Skip to main content
Skip table of contents

Initialize the SentinelOne Beat

Prerequisites

Direction

Port

Protocol

Source

Outbound

443

HTTPS

SentinelOne Beat

Initialize the Beat

  1. To confirm the Open Collector is running, run the following command:

    CODE
    ./lrctl status

    You should see the open_collector and metrics as shown in the following graphic:

    image-20250217-053832.png

    If the Open Collector is not running correctly, see Troubleshoot the Open Collector in the Open Collector Installation and User Guide.

  2. In the Open Collector, run the following command:

    CODE
    ./lrctl sentinelonebeat start
  3. Enter a unique identifier for the beat instance.

    image-20250217-055927.png
  4. Enter the SentinelOne API URL.

    image-20250217-060807.png

The following URLs are supported for this Beat:

https://<your sentinelone domain>/web/api/v2.1/activities

https://<your sentinelone domain>/web/api/v2.1/cloud-detection/alerts

https://<your sentinelone domain>/web/api/v2.1/device-control/events

https://<your sentinelone domain>/web/api/v2.1/exclusions

https://<your sentinelone domain>/web/api/v2.1/threats

  1. Enter the API Token (Bearer Token) obtained during the steps outlined in Configure the SentinelOne Portal.

  2. (Optional.) Enter any unique Site IDs from which you would like to collect.

Site IDs are optional, and can be left blank by pressing 'c' on the keyboard.

image-20250217-061853.png
  1. Enter the hostname or IP of the Open Collector.

ipsmudge.PNG
  1. Enter the port number of the Open Collector.

image-20250217-062345.png
  1. Press Enter.
    The beat starts successfully, and displays the following output:

image-20250217-062455.png

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.