Initialize the SentinelOne Beat

Prerequisites

Direction

Port

Protocol

Source

Outbound

443

HTTPS

SentinelOne Beat

Initialize the Beat via the Web Console (Recommended)

  1. Ensure that the Open Collector Connection to the SIEM (WebUI) setup has been completed.

  2. Ensure that the System Monitor Agent to which you intend to send these logs has been Configured for JSON Parsing.

Use either the Enable JSON Parsing on System Monitor Agents or the Enable JSON Parsing for an Existing System Monitor Agent sections at the above link to configure the System Monitor Agent for JSON Parsing.

  1. Follow the steps outlined in Add a Beat in the Web Console to create the Beat via the Web UI.

Initialize the Beat via Command Line (Legacy)

  1. In the Open Collector, run the following command:

    ./lrctl sentinelonebeat start
    
  2. Use the Up and Down Arrow keys to select New sentinelonebeat instance from the list, and then press Enter.

  3. Enter the unique identifier for this sentinelonebeat instance, and then press Enter.

  4. Enter the SentinelOne API URL, and then press Enter.

The following URLs are supported for this Beat:

https://<your sentinelone domain>/web/api/v2.1/activities

https://<your sentinelone domain>/web/api/v2.1/cloud-detection/alerts

https://<your sentinelone domain>/web/api/v2.1/device-control/events

https://<your sentinelone domain>/web/api/v2.1/exclusions

https://<your sentinelone domain>/web/api/v2.1/threats

  1. Enter the Service Token (Bearer Token), and then press Enter.

  2. (Optional.) Enter any unique Site IDs from which you would like to collect, and then press Enter.

Site IDs are optional, and can be left blank by pressing 'c' on the keyboard, and then press Enter.

  1. Enter the hostname or IP address of the System Monitor Agent that has been Configured for JSON Parsing, and then press Enter.

Use either the Enable JSON Parsing on System Monitor Agents or the Enable JSON Parsing for an Existing System Monitor Agent sections at the above link to configure the System Monitor Agent for JSON Parsing.

  1. Enter the port on which the System Monitor Agent is configured to listen for JSON data (the default is 5044), and then press Enter.
    The sentinelonebeat service started message appears.

  2. Check the status of the service to confirm that it’s running:

    ./lrctl sentinelonebeat status
    
  3. (Optional) Edit the sentinelonebeat configuration to update the values set above if needed. Ensure that you have all the needed information for each step available as you will need to re-enter it:

    ./lrctl sentinelonebeat config edit