Connect SentinelOne
Use this guide to import SentinelOne endpoint alerts and host data into Cracken.
Prerequisites
- Permission to create a SentinelOne service user
- The management-console URL for your SentinelOne deployment
- A Cracken realm where you can configure data integrations
Prepare the credential
Create a dedicated service user and assign:
- Viewer role
- Scope covering every account, site, and group that Cracken should read
Generate an API token for that service user and store it securely. SentinelOne service-user tokens expire according to your deployment's policy and must be replaced in Cracken when rotated.
Use the management-console URL, in the form https://<host>.sentinelone.net, as Base URL.
Connect SentinelOne
- Open Integration Center → Data Integrations.
- On the SentinelOne card, click Install.
- Enter the Base URL and API Token.
- Click Test Connection, then Save & Connect.
Cracken can list endpoint alerts and request an on-demand synchronization of the latest results within the service user's scope.
Sources
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported endpoint data.