| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription
Precision AI bundle subscription
Device Security X subscription
One of the following Cortex XSOAR setups:
A free, cohosted, limited-featured
Cortex XSOAR instance
AND
A free Cortex XSOAR Engine (on-premises integration)
A full-featured Cortex XSOAR server
|
It's assumed you already have SentinelOne Singularity
Endpoint set up. When integrating SentinelOne with Device Security
and Cortex XSOAR, you need to provide
Cortex XSOAR with an API token from
SentinelOne. Cortex XSOAR uses the API
token to poll SentinelOne for information about endpoints and
vulnerabilities.
To generate the API token from SentinelOne, create a SentinelOne
role for Cortex XSOAR to use. Then assign the
role to a service user in SentinelOne to generate the API token.