Integrate SentinelOne Singularity
You can integrate SentinelOne Singularity with Sophos XDR so that it sends data to Sophos for analysis.
Key steps
The key steps in a SentinelOne Singularity integration are as follows:
- Create a service user and API token in SentinelOne Singularity Endpoint.
- Get the API details from SentinelOne.
- If you want to ingest EDR data, configure a SentinelOne Deep Visibility policy.
- Configure the integration in Sophos XDR and turn on the data sources you want to ingest.
Requirements
The following is required for SentinelOne Singularity configuration:
- An administrator account in SentinelOne Singularity.
To ingest SentinelOne Alerts, you'll also require the following:
- The STAR custom rules feature turned on in your SentinelOne tenant.
To ingest SentinelOne EDR, you'll also require the following:
- The SentinelOne Cloud Funnel add-on. Contact your SentinelOne account representative for Cloud Funnel pricing.
- A service user with Cloud Funnel permissions.
- An account ID.
-
A supported SentinelOne region (
apne1,apse1,cace1,carvir,euce1,usce1, orusea1).If your region is not listed, contact Sophos to request support for it.
Add a SentinelOne Singularity integration
To integrate SentinelOne Singularity, you must first create a service user and API token in SentinelOne Singularity, then provide them in Sophos XDR.
Create a service user and API token
To get the SentinelOne Singularity API details you need for integration, do as follows:
- Sign in to your SentinelOne Singularity Operations Center.
- Go to Policies and settings > Service users.
- In the Actions list, click Create User.
- In Create New Service User, enter a name and description for the user.
- For Expiration Date, select a lifespan for the user from the drop-down menu, or click Custom to set a different expiration date and time.
- Under Permissions, select Account or Site, depending on the desired scope for the integration, then choose the account or site you wish to integrate with Sophos XDR.
- If you want to ingest EDR data, the service user's role must also include Cloud Funnel permissions. Duplicate the built-in Viewer role, grant Cloud Funnel permissions by choosing Select All, and assign that role to the service user.
- Click Create Service User.
- Securely copy the API Token for the service user. You'll need it when you add the integration in Sophos XDR.
- Click Close.
Next, you configure an integration in Sophos XDR.
Find the account ID
Note
A SentinelOne Singularity account ID is required to ingest EDR data. It is optional for other data sources.
You may wish to scope the integration to a specific account. Find the account ID in the SentinelOne Singularity Operations Center as follows:
- Sign in to your SentinelOne Singularity Operations Center.
- Go to Policies and settings > Accounts.
- Click on the desired account.
- Copy the Account ID.
Find the site ID (optional)
You may wish to scope the integration to a specific site. Find the site ID in the SentinelOne Singularity Operations Center as follows:
- Sign in to your SentinelOne Singularity Operations Center.
- Go to Policies and settings > Sites.
- Click on the desired site.
- Copy the Site ID.
Configure a SentinelOne Deep Visibility policy (EDR only)
EDR data is collected through SentinelOne Cloud Funnel 2.0. To ingest EDR data, configure a Deep Visibility policy in SentinelOne so that agents collect and forward the required events to Cloud Funnel. When you turn on the EDR data source in Sophos XDR, Sophos XDR automatically provisions the Cloud Funnel destination (a dedicated Sophos-managed storage location). You don't create or manage that storage yourself. Don't change the Cloud Funnel configuration created by the integration while the integration is in use.
Note
The following steps were written for the Unity version of the SentinelOne Management Console with Singularity Operations Center disabled. If your console uses a different version, menu names and locations may vary.
- Go to Sentinels > Policy and locate the Deep Visibility section.
- Click Enable Deep Visibility.
-
Select the event categories to collect: Process, DNS, Registry Keys, Command Scripts, File, IP, Scheduled Tasks, Cross Process, URL, Login, Behavioral Indicators, and Module.
Note
For the integration to ingest an event category, you must also select all event types in that category under Event Type Configuration. Events that are not turned on in the policy are not collected or forwarded to Sophos XDR.
-
Under XDR Collections, select Windows Event Log. Optionally, also select Windows Event Log Extended.
Note
Selecting the Windows Event Log Extended option includes the Windows event log XML, which the integration uses to add more information to the events. Windows Event Log Extended consumes significantly more data than Windows Event Log in SentinelOne and therefore is more costly.
Refer to the SentinelOne documentation (Windows Event Logs in the SentinelOne Singularity AI SIEM) before turning on these options to understand the cost involved with enabling Windows Event Log Extended and how to configure which Windows event logs you want collected.
-
Click Save Changes.
Configure the integration in Sophos XDR
To integrate SentinelOne Singularity with Sophos XDR, do as follows:
- In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
-
Click SentinelOne.
The SentinelOne page opens. You can configure integrations here and see a list of any you've already configured.
-
In Configured integrations, click Add new.
-
In Add an integration, do as follows:
- Enter a name for the integration.
-
Under Endpoint Data Sources, select the SentinelOne data sources you want Sophos XDR to ingest. Available data sources are:
- SentinelOne Assets
- SentinelOne Alerts
- SentinelOne EDR
- SentinelOne Threats (required)
-
Enter the Management URL. For example,
https://usea1-999-example.sentinelone.net/. - Enter the API Token you copied in SentinelOne Singularity.
- Enter the Account ID you copied in SentinelOne Singularity.
- (Optional) Enter the Site ID you copied in SentinelOne Singularity.
- (EDR only, optional) If you're including SentinelOne EDR in your data sources and you want Sophos XDR to replace an existing Cloud Funnel configuration, select Replace Cloud Funnel.
-
Click Done.
The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.
Tip
When EDR is turned on, the Account ID, Site ID, and Management URL can't be changed, because they determine the identity and location of the Cloud Funnel feed. To change any of these values, first turn off EDR, then turn it back on with the new value.
Additional resources
For more information on configuring SentinelOne Singularity, see the following documents: