Let Oomnitza be your single source of truth!
You'll get complete visibility of your SentinelOne assets as data from SentinelOne is automatically transformed into consumable information and actionable insights.
Connect Oomnitza and SentinelOne in minutes
Get the information and insights that you need to reduce costs and the time that you spend on administration tasks such as:
- Configurable dashboards and list views of key asset and software information
- Configurable reports to share information about assets and software with your colleagues and management such as corporate-wide reports that detail the distribution and status of the assets and software in your environment
- Configurable workflows that you can create such as
- Getting asset details, passphases, and site information
- Deleting asset tags
Navigation
Creating the asset integration
SentinelOne Get Asset Passphase
SentinelOne Get Asset Site Information
Before you start
Best practice
For the integration with Oomnitza, create a dedicated user account.
SentinelOne uses API key authentication, which requires an API secret key and API ID.
For more information, see SentinelOne FAQ.
Updating the credentials
To authorize connections between Oomnitza and SentinelOne, complete these steps:
- In Oomnitza, click Configuration > Credentials.
- Click Add new credential (+).
- Add the information details.
- Click the AUTHORIZATION tab.
- Ensure that API Key is selected as the authorization type.
- Enter Authorization as the name of the token.
- Enter ApiToken {{SentinelOne API token}} as the API key.
- Ensure that Add to Header is selected.
- Save your changes.
You use the credentials that you added to create and customize your SentinelOne integrations with Oomnitza.
Creating the asset integration
To configure the integration for SentinelOne assets, complete the following steps:
- In Oomnitza, click Configuration > Integrations.
- Click Integrations List View
.
- On the Integrations page, scroll down to the Extended section for Assets.
- Click NEW INTEGRATION.
- In the New Asset Integration sidebar, click SentinelOne.
- To integrate Oomnitza with the SentinelOne Asset Load, click APPLY and then click NEXT twice.
On the connect page, complete the following steps to connect the integration:
- Enter a descriptive name for the integration such as SentinelOne Assets. This name will be displayed on the Integrations page once the setup is complete.
- Check the Software check box if you would like to receive software information for your assets.
- Select Cloud as the installation type.
- From the Credentials list, select the credentials from the Oomnitza vault that you added for the connection.
- From the Integration Preferences list, select Create & Update.
- Enter the name of the user of the integration.
- Enter the SentinelOne Customer Domain URL. The URL has the following format
https://<subdomain>.sentinelone.net
orhttps://<subdomain>.sentinelone.com
- Click Next.
Creating custom mappings
Map the SentinelOne fields to Oomnitza fields and create custom mappings to get the user information that you need.
Complete these actions:
- You must create a custom mapping for the SentinelOne Device Id field. To do this, complete these steps:
- Click the down arrow on the Id field.
- Select Add new Oomnitza assets field.
- Change the name of the Id field to SentinelOne Device Id.
- Click CREATE.
- Create custom mappings to map any other field that you want to add to Oomnitza:
- Click the down arrow on the field that you want to map.
- Select Add new Oomnitza assets field.
- Change the name of the field.
- Click CREATE.
- Assign a sync key to the Email field.
- Click NEXT.
Tracking information for asset loads
When the integration is run, you can track the name of the credentials that were used and the source of the data. To do this, you map the following fields to Oomnitza:
- Connect: Credentials
- Connect: Customer Domain URL
Custom mappings
Account Id
Account Name
Active Directory Computer Distinguished Name
Active Directory Last User Distinguished Name
Active Threats
Agent Version
Apps Vulnerability Status
Computer Name
Connector Sync Time
Console Migration Status
Core Count
Cpu Count
Cpu Id
Created At
Customer Domain URL
Detection State
Domain
External Id
External Ip
First Full Mode Time
Group Id
Group Ip
Group Name
Id
Installer Type
Is Active
Is Allow Remote Shell
Is Decommissioned
Is Encrypted Applications
Is Firewall Enabled
Is In Remote Shell Session
Is Infected
Is Location Enabled
Is Network Quarantine Enabled
Is Pending Uninstall
Is Threat Reboot Required
Is Uninstalled
Is Up To Date
Last Active Date
Last Ip To Mgmt
Last Logged In User Name
License Key
Location Type
Machine Type
Mitigation Mode
Mitigation Mode Suspicious
Model Name
Network Status
Operational State
Operational State Expiration
Os Arch
Os Name
Os Revision
Os Start Time
Os Type
Os Username
Ranger Status
Ranger Version
Registered At
Remote Profiling State
Remote Profiling State Expiration
Scan Aborted At
Scan Finished At
Scan Started At
Scan Status
Site Id
Site Name
Storage Name
Storage Type
Total Memory
Updated At
Uuid
When you've completed mapping SentinelOne fields to Oomnitza fields, click NEXT.
Schedule
By default, data is streamed to Oomnitza once every day.
You can configure the schedule to meet your needs such as changing the interval or changing the time so that the data is streamed when your system isn't busy.
- Configure your schedule.
- Click FINISH.
Result
A new tile is created for the integration on the Integrations page.
What to do next
If you want to see what information is collected now, click the tile on the Integrations page and click RUN NOW.
If you want to change the integration settings, you can click a navigation link on the page, such as 4 Mappings, and edit the settings.
Tip
To view the information that is collected about your mobile assets, click Assets.
Creating workflows
To reduce your workload and automate complex and repetitive tasks, you can create asset workflows with the API block by following the steps in Creating user workflows with the API block. When creating the asset workflows with the API block for SentinelOne, the following specific configuration is required:
- To locate the available presets, enter SentinelOne in the Select Preset search field. The SentinelOne API block workflow comes with the following presets:
SentinelOne Delete Tag by ID
SentinelOne Get Asset Details
SentinelOne Get Asset Passphase
SentinelOne Get Asset Site Information - In the Configure section, enter the following details:
- The SentinelOne URL, if it was not already added as a global variable. For further information, refer to Setting the SentinelOne URL as a global variable.
- Your SentinelOne Credentials that you created in Updating the credentials.
Unleash the power of Oomnitza
To get valuable actionable insights that help you manage your assets, learn how to:
- Configure dashboards for your users and software
- Configure custom reports about your users and software
- Create workflows to automate tasks
See Getting started
See Creating workflows to find out more about how to create workflows with SentinelOne.
Did you know
You can also create extended connector integrations for SentinelOne Users. Extended Integration for SentinelOne Users
Comments
0 comments
Please sign in to leave a comment.