Configuring SentinelOne Log Ingestion
To configure your SentinelOne endpoint protection system to send logs to Stellar Cyber:
Use our example as a guideline, as you might be using a different software version.
During installation, the timezone for sensors are automatically set to UTC+0. Since the logs for some security products might only include the local time without a timezone, Stellar Cyber recommends that you set the sensor timezone to the same timezone as your security product.
- 
                                                    Log in to SentinelOne. 
- 
                                                    Select INTEGRATIONS. 
- 
                                                    Select SYSLOG. 
- 
                                                    Enable SYSLOG. 
- 
                                                    For the Host, enter the IP address of the Modular Sensor. 
- 
                                                    For the port, enter 5175. 
- 
                                                    Optionally enable TLS. If you do so, then under Certificate, select Upload. This sends the CA certificate for the Select to SentinelOne. 
- 
                                                    For Formatting, choose CEF2. 
- 
                                                    Select Save. 

