Learn more about the SentinelOne DeepVisibility Collector and content pack integrations in Cortex XSIAM.
You can configure collecting SentinelOne DeepVisibility raw EDR event data using a Standard Collector or with a content pack integration:
SentinelOne DeepVisibility vendor | Description |
|---|---|
Standard Collector overview | Forward raw EDR event data from SentinelOne DeepVisibility to Cortex XSIAM, streamed via Cloud Funnel to Amazon S3 using the SentinelOne - Deep Visibility data source. |
Link to Standard Collector instructions | |
Links to content pack/integration instructions | The SentinelOne content pack provides capabilities for endpoint protection, allowing users to receive alerts, manage protection policies, search processes, and execute remediation actions on endpoints. The SentinelOne pack contains classifiers, issue fields, issue types, layouts, modeling rules, and playbooks. It also includes the following integrations:
|