SentinelOne Singularity
| Pack name | SentinelOne Singularity |
| Version | 1.0.0 |
| Vendor | SentinelOne |
| Capabilities | Connector · Parser · Streaming Rules · Correlation Rules · Dashboard · Report |
| Categories | Endpoint · EDR · XDR · Malware · SentinelOne |
Overview
Pack cung cấp giám sát endpoint toàn diện từ nền tảng SentinelOne Singularity trên SecOps platform, bao gồm:
- Pull connector — tự động lấy log từ SentinelOne Management API v2.1 (3 luồng: Threats, STAR Alerts, Activities), không cần cài agent shipper
- Parser — chuẩn hóa cả 3 luồng JSON sang ECS trong một parser duy nhất. Parser được đóng gói kèm luôn trong connector (
connectors/sentinelone/parser.yaml) nên tự động được gán làm parser mặc định khi tạo source - 4 streaming rules — phát hiện malicious threat, threat chưa được mitigate, STAR alert mức High/Critical, agent bị gỡ hoặc vô hiệu hóa
- 2 correlation rules — phát hiện malware outbreak diện rộng và endpoint bị tấn công lặp lại
- 1 dashboard — 12 chart giám sát SOC endpoint security
- 1 report template — 16 chart báo cáo định kỳ, có mapping PCI DSS và ISO 27001
Yêu cầu trước khi cài đặt
| Yêu cầu | Chi tiết |
|---|---|
| SentinelOne Singularity | Management Console đang hoạt động, Management API v2.1 |
| API Token | Service User token (khuyến nghị) hoặc console-user token |
| Console permissions | Threats: view, STAR Rule Alerts: view, Activity: view |
| Kết nối mạng | SecOps platform gọi được HTTPS tới console URL của tenant |
| Quyền platform | Role Content Pack Manager |
Tạo API Token trên SentinelOne
Cách khuyến nghị — Service User (token không hết hạn sau 30 ngày):
- Đăng nhập Management Console → Settings → Users → Service Users
- Actions → Create New Service User
- Đặt tên (ví dụ
secops-siem-collector), chọn scope (Account hoặc Site cụ thể) - Gán 3 quyền:
Threats: view,STAR Rule Alerts: view,Activity: view - Create → copy token hiển thị (chỉ hiện một lần duy nhất)
Cách thay thế — Console user token:
My User → Actions → API Token Operations → Generate API Token
⚠️ Token của console user hết hạn sau 30 ngày → connector sẽ dừng thu thập. Chỉ dùng để test nhanh.
Xác định Management URL
URL là phần domain của console, không kèm dấu / cuối và không kèm đường dẫn /web/api/v2.1:
https://usea1-partners.sentinelone.net
https://apne1-1101.sentinelone.net
Xác thực
Connector gửi header:
Authorization: ApiToken <your-token>
Kiểm tra nhanh bằng curl trước khi cấu hình:
curl -H "Authorization: ApiToken <token>" \
"https://<tenant>.sentinelone.net/web/api/v2.1/system/status"
Cài đặt
- Vào Marketplace → tìm "SentinelOne Singularity" → Install
- Vào Data Collection → Data Connectors → Add Connection → chọn connector type
sentinelone - Điền cấu hình (bảng bên dưới) → Test Connection → Save
- Kiểm tra Parsers →
sentinelone-parserđang active (parser đi kèm connector nên source mới sẽ tự dùng parser này) - Kiểm tra Detection Rules → filter tag SentinelOne → 6 rules đang enabled
- Mở Dashboards → SentinelOne Endpoint Security Overview
- Mở Reports → Report Library → SentinelOne Endpoint Security Report để tạo báo cáo định kỳ
Cấu hình Connector
| Field | Bắt buộc | Mặc định | Mô tả |
|---|---|---|---|
| Management Console URL | ✅ | — | URL console, ví dụ https://usea1-partners.sentinelone.net |
| API Token | ✅ | — | Token dạng secret, gửi qua header Authorization: ApiToken |
| Site IDs | — | (trống) | Danh sách Site ID phân tách bằng dấu phẩy. Để trống = thu thập toàn bộ scope token đọc được |
| Collect Threats | — | true | Lấy threat từ /web/api/v2.1/threats. Kiểu string, nhận true/false (hoặc 1/0, yes/no); để trống = true |
| Collect STAR Alerts | — | true | Lấy STAR alert từ /web/api/v2.1/cloud-detection/alerts. Kiểu string, cùng quy ước trên |
| Collect Activities | — | true | Lấy console audit activity từ /web/api/v2.1/activities. Kiểu string, cùng quy ước trên |
| Page Size | — | 100 | Số record mỗi lần gọi API (SentinelOne cho phép 1–1000). Kiểu int |
| Initial Lookback Hours | — | 1 | Số giờ lấy ngược lại ở lần chạy đầu tiên (khi chưa có watermark). Kiểu int |
| Poll Interval (minutes) | ✅ | 5 | Chu kỳ poll API. Kiểu int |
Lưu ý khi cấu hình qua API: payload phải đúng kiểu JSON — 3 field
collect_*là chuỗi ("true"), cònpage_size/lookback_hours/time_intervallà số (100, không phải"100"). Sai kiểu sẽ nhận lỗifailed to validate log source structure: invalid type for field: ...
Cơ chế hoạt động:
- Mỗi luồng (threat / alert / activity) giữ watermark riêng theo
createdAt→ không trùng, không sót khi một luồng bị lỗi - Phân trang theo
pagination.nextCursorcủa SentinelOne, tự động lặp đến hết - Mỗi record được gắn
_log_type(threat|alert|activity) để parser phân nhánh idem_keydạng<instance_id>:<stream>:<record_id>chống ghi trùng
Định dạng log
Connector đẩy nguyên bản JSON của SentinelOne API, chỉ thêm field _log_type. Parser phân nhánh theo thứ tự: _log_type → _source → cấu trúc (threatInfo / alertInfo / activityType).
Ví dụ log hợp lệ
Threat — malicious, chưa mitigate (rút gọn):
{"_log_type":"threat","id":"1608042494261759854","threatInfo":{"threatId":"1608042494261759854","threatName":"mimikatz.exe","classification":"Malware","classificationSource":"Static","confidenceLevel":"malicious","detectionType":"static","incidentStatus":"unresolved","mitigationStatus":"not_mitigated","analystVerdict":"undefined","initiatedBy":"agent_policy","storyline":"7A44C3E5A1B2C3D4","filePath":"C:\\Users\\admin\\Downloads\\mimikatz.exe","fileExtension":"EXE","fileSize":1263616,"md5":"29f4a4bd8dad8b3c7c04ed4a1e2b6d1f","sha1":"b7c1b1b48f2c1f2b2d1e0a0c9d8e7f6a5b4c3d2e","sha256":"9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08","originatorProcess":"explorer.exe","maliciousProcessArguments":"-m 64 -k","processUser":"CORP\\jsmith","createdAt":"2025-01-20T07:04:04.925421Z"},"agentDetectionInfo":{"accountId":"901234567890123456","accountName":"Contoso Ltd","agentIpV4":"10.20.30.40","agentVersion":"23.4.2.350","osName":"Windows 10 Pro","machineType":"laptop","siteId":"1122334455667788990","siteName":"HQ","uuid":"3b1c2d4e5f60718293a4b5c6d7e8f901"},"agentRealtimeInfo":{"agentComputerName":"WKS-JSMITH-01","agentId":"1607999999999999999","agentOsType":"windows","groupId":"1234567890123456789","groupName":"Workstations"}}
STAR Alert — High severity (rút gọn):
{"_log_type":"alert","alertInfo":{"alertId":"1610000000000000123","dvEventId":"1610000000000000999","eventType":"PROCESSCREATION","indicatorName":"PsExecLateralMovement","indicatorCategory":"lateral_movement","indicatorDescription":"Suspicious remote service creation consistent with PsExec lateral movement","hitType":"Events","source":"STAR","analystVerdict":"UNDEFINED","incidentStatus":"UNRESOLVED","netEventDirection":"INCOMING","dstIp":"10.20.40.12","dstPort":445,"srcIp":"10.20.30.40","createdAt":"2025-01-20T10:12:03.120000Z"},"ruleInfo":{"id":"1609000000000000777","name":"Lateral Movement - PsExec Service Creation","severity":"High","scopeLevel":"Site"},"sourceProcessInfo":{"name":"psexesvc.exe","filePath":"C:\\Windows\\PSEXESVC.exe","commandline":"C:\\Windows\\PSEXESVC.exe","pid":4812,"user":"CORP\\svc_backup","storyline":"5E4D3C2B1A099887"},"sourceParentProcessInfo":{"pid":728,"name":"services.exe"},"agentDetectionInfo":{"name":"SRV-FILE-02","uuid":"aabbccddeeff00112233445566778899","osName":"Windows Server 2019","version":"23.4.2.350"}}
Activity — agent bị gỡ (rút gọn):
{"_log_type":"activity","id":"1611000000000000001","activityType":23,"description":"Agent Uninstalled","primaryDescription":"The agent WKS-JSMITH-01 was uninstalled.","secondaryDescription":"Agent removed from console by administrator","agentId":"1607999999999999999","groupId":"1234567890123456789","groupName":"Workstations","siteId":"1122334455667788990","siteName":"HQ","accountId":"901234567890123456","accountName":"Contoso Ltd","osFamily":"windows","userId":"901234567890123999","data":{"computerName":"WKS-JSMITH-01","username":"admin@corp.example.com"},"createdAt":"2025-01-20T12:30:11.000000Z"}
Timestamp hỗ trợ cả độ chính xác microsecond (
...04.925421Z) và giây (...04Z).
⚠️ API
/activitieskhông trảdescription— chỉ cóprimaryDescriptionvàsecondaryDescription. Parser đọcdescriptiontrước rồi fallback sangprimaryDescription. Tương tự, hostname của activity nằm ởdata.computerName(không phảiagentRealtimeInfonhư threat/alert), và operator nằm ởdata.username/data.userName.
Parser — Các trường ECS chính
| ECS Field | Nguồn | Mô tả |
|---|---|---|
event.dataset | Derived từ _log_type | sentinelone.threat / sentinelone.alert / sentinelone.activity |
event.action | mitigationStatus (threat) / eventType (alert) / primaryDescription (activity) | threat_mitigated, threat_not_mitigated, processcreation, agent_uninstalled… — xem bảng chuẩn hóa activity bên dưới |
event.outcome | mitigationStatus / primaryDescription | success / failure / unknown |
event.severity_label | confidenceLevel (threat) hoặc ruleInfo.severity (alert) | critical / high / medium / low |
observer.type | Cố định | edr |
threat.name | threatInfo.threatName / alertInfo.indicatorName | Tên threat hoặc indicator |
threat.score | threatInfo.confidenceLevel | malicious / suspicious |
threat.action | threatInfo.mitigationStatus (threat) / alertInfo.analystVerdict (alert) | mitigated / not_mitigated / marked_as_benign. Với alert, giá trị được chuẩn hóa về snake_case (False positive → false_positive) để đồng nhất với threat |
threat.type | threatInfo.classification | Malware, Ransomware, PUA… |
file.path · file.name · file.size | threatInfo.filePath / threatName / fileSize | Artifact độc hại |
file.hash.md5 · file.hash.sha256 | threatInfo.md5 / sha256 | Hash IOC dùng để hunt |
related.hash | threatInfo.sha1 | SHA1 (Field Standard không có file.hash.sha1) |
process.name · process.command_line · process.pid | originatorProcess / sourceProcessInfo.* | Process khởi tạo |
process.parent.pid | sourceParentProcessInfo.pid | Process cha |
host.name · host.hostname | agentRealtimeInfo.agentComputerName (threat) / agentDetectionInfo.name (alert) / data.computerName (activity) | Endpoint bị ảnh hưởng |
host.ip | agentDetectionInfo.agentIpV4 | Đã lọc bỏ IP hạ tầng ảo — xem mục bên dưới |
host.os.family · host.os.full | agentOsType / osName | Ngữ cảnh endpoint |
agent.id · agent.version | agentDetectionInfo.uuid / version | Agent SentinelOne |
rule.id · rule.name | ruleInfo.id / name | STAR rule sinh alert |
user.name | processUser (threat) / sourceProcessInfo.user (alert) / data.username → data.userName (activity) | User liên quan |
user.email | Derived từ user.name | Tự động điền khi user.name chứa @ (SentinelOne thường dùng email làm định danh operator) |
user.domain | agentDetectionInfo.agentDomain | Domain của endpoint |
container.name | containerInfo.name | Tên container khi threat được phát hiện trong workload container |
source.ip | agentDetectionInfo.externalIp (threat) / alertInfo.srcIp (alert) / data.ipAddress (activity) | IP nguồn |
destination.ip · destination.port | alertInfo.dstIp / dstPort | Đích kết nối trong STAR alert |
dns.question.name · dns.answers.data | alertInfo.dnsRequest / dnsResponse | DNS context |
registry.path · registry.key · registry.value | alertInfo.registry* | Registry context |
labels.* | Nhiều nguồn | log_type, site_name, storyline, detection_type, analyst_verdict, mitigation_status, activity_type, container_image, agent_ips, file_sha1… |
labels.storylinelà ID chuỗi tấn công của SentinelOne — dùng để pivot toàn bộ sự kiện liên quan trong Deep Visibility.
Lọc IP hạ tầng ảo trong host.ip
SentinelOne báo cáo mọi NIC mà agent nhìn thấy, bao gồm cả bridge của Docker và libvirt. Ví dụ: 172.17.0.1,192.168.122.1,10.20.30.40.
Parser loại các dải sau khỏi host.ip để chart và rule không bị nhiễu bởi IP giả:
| Dải bị loại | Nguồn |
|---|---|
127.x.x.x | Loopback |
169.254.x.x | Link-local / APIPA |
172.17.x.x | Docker bridge mặc định |
192.168.122.x | libvirt / KVM bridge |
host.ip→ chỉ còn IP định tuyến được (10.20.30.40)labels.agent_ips→ giữ nguyên vẹn danh sách gốc, dùng khi cần điều tra đầy đủ interface- Nếu sau khi lọc không còn IP nào, parser giữ lại danh sách gốc để tránh mất dữ liệu
Chuẩn hóa event.action cho luồng Activity
API /activities trả mô tả dạng câu tự do (kèm hostname, tên file, email trong nội dung). Parser không slugify cả câu — làm vậy sẽ nhét hostname vào event.action và phá vỡ khả năng gom nhóm trên dashboard. Thay vào đó parser dò từ khóa theo thứ tự ưu tiên và gán nhãn low-cardinality:
event.action | Từ khóa trong mô tả | Ghi chú |
|---|---|---|
agent_uninstalled | uninstall | Khớp streaming rule #4 |
agent_decommissioned | decommission | Khớp streaming rule #4. Không nhầm với recommissioned |
agent_disabled | disable | Khớp streaming rule #4 |
user_login_failed | failed to log in | event.outcome = failure, severity nâng lên medium |
user_login | logged in / login / log in | event.outcome = success |
remote_shell_session | remote shell | Thao tác đặc quyền, severity medium |
token_revoked | revoked | Thu hồi API token |
verdict_changed | analyst verdict | Analyst đổi verdict của threat |
incident_status_changed | incident status | Analyst đổi trạng thái incident |
content_update | live updates / were merged | Cập nhật content engine — nhiễu nền, chiếm ~74% activity |
agent_moved | moved agent / to site | Chuyển agent giữa site/group |
threat_activity | threat | Activity phát sinh từ threat |
policy_changed | policy | Thay đổi policy |
object_added / object_deleted | added/created · deleted/removed | Thêm/xóa đối tượng trên console |
activity_<mã> | (không khớp từ khóa nào) | Fallback theo activityType. Đo trên 1600 activity thật: chỉ còn 4.8% rơi vào nhánh này |
Vì
content_updatechiếm phần lớn lưu lượng activity, cả dashboard chart 12 lẫn report chart "Console Administrative Actions" đều lọc bỏ nhãn này (NOT_EQUALS content_update).
Detection Rules
Streaming Rules (4 rules — real-time)
| # | Rule | Severity | MITRE ATT&CK | Mô tả |
|---|---|---|---|---|
| 1 | SentinelOne Malicious Threat Detected | High | TA0002 Execution · T1204 User Execution | Threat được agent phân loại confidence level malicious — xác nhận malware/ransomware/offensive tool đang chạy trên endpoint |
| 2 | SentinelOne Threat Not Mitigated | High | TA0005 Defense Evasion · T1562 Impair Defenses | Threat đã phát hiện nhưng agent không xử lý được — endpoint vẫn đang bị nhiễm |
| 3 | SentinelOne High Severity STAR Alert | High | TA0008 Lateral Movement · T1021 Remote Services | STAR custom detection rule bắn alert mức High hoặc Critical |
| 4 | SentinelOne Agent Uninstalled or Disabled | High | TA0005 Defense Evasion · T1562 Impair Defenses | Thao tác console gỡ agent, decommission endpoint hoặc tắt bảo vệ — defense evasion |
Correlation Rules (2 rules — pattern)
| # | Rule | Severity | MITRE ATT&CK | Mô tả | Ngưỡng | Lookback |
|---|---|---|---|---|---|---|
| 5 | SentinelOne Malware Outbreak Across Endpoints | Critical | TA0002 Execution · T1204 User Execution | Cùng một threat name xuất hiện trên nhiều endpoint khác nhau — worm, lây qua shared drive, hoặc giai đoạn triển khai trước khi ransomware kích hoạt | ≥ 3 event và ≥ 3 host khác nhau | 15 phút |
| 6 | SentinelOne Repeated Threats on Single Host | High | TA0005 Defense Evasion · T1562 Impair Defenses | Một endpoint liên tục sinh threat — máy đã bị chiếm quyền hoặc user tải malware lặp lại | ≥ 5 threat / 1 host | 15 phút |
Dashboard — SentinelOne Endpoint Security Overview
| # | Chart | Loại | Mô tả |
|---|---|---|---|
| 1 | Threat Detections Trend | LINE | Trend threat/alert theo thời gian, tách theo outcome |
| 2 | Total Threats | METRIC | Tổng số threat trong khoảng thời gian |
| 3 | Malicious Threats | METRIC | Số threat có verdict malicious |
| 4 | Unmitigated Threats | METRIC | Số threat chưa được xử lý — cần can thiệp ngay |
| 5 | STAR Alerts | METRIC | Số alert từ custom detection rules |
| 6 | Threat Classification Distribution | PIE | Tỷ trọng Malware / Ransomware / PUA… |
| 7 | Mitigation Status Distribution | PIE | Mitigated vs Not mitigated vs Marked as benign |
| 8 | Top Infected Endpoints | BAR | Endpoint có nhiều threat nhất |
| 9 | Top Threat Names | BAR | Threat/malware phổ biến nhất trong môi trường |
| 10 | Top STAR Rules Triggered | BAR | STAR rule bắn nhiều nhất — dùng để tuning |
| 11 | Recent Unmitigated Threats | TABLE | 20 threat chưa xử lý gần nhất (host, threat, file path, SHA256) |
| 12 | Recent Console Activities | TABLE | 20 thao tác console gần nhất (ai làm gì) — đã lọc bỏ content_update để không bị nhiễu cập nhật content engine lấn át |
SOC Triage nhanh:
- Metric 4 (Unmitigated Threats) > 0 → ưu tiên cao nhất, mở Table 11 lấy host + SHA256
- Chart 8 — một endpoint chiếm đa số → máy đã bị chiếm quyền, cân nhắc isolate
- Chart 9 — một threat name lan trên nhiều host → đối chiếu correlation rule #5 (outbreak)
- Chart 10 — STAR rule bắn quá nhiều → tuning rule, tránh alert fatigue
- Table 12 — kiểm tra có thao tác gỡ agent bất thường không (khớp streaming rule #4)
Report — SentinelOne Endpoint Security Report
Báo cáo định kỳ (16 chart) dùng cho review endpoint protection hàng tháng, theo dõi độ phủ mitigation và phục vụ compliance.
| Nhóm | Chart |
|---|---|
| Tổng quan threat | Threat Detections Trend (Hourly) · Total Threat Detections · Malicious Threats · Unmitigated Threats · Infected Endpoints |
| Phân bố | Threat Classification Distribution · Mitigation Status Distribution · Detection Confidence Distribution |
| Xếp hạng | Top Infected Endpoints · Top Threat Names · Top STAR Rules Triggered |
| STAR | STAR Alert Severity Distribution |
| Audit console | Console Administrative Actions · Failed Console Logins · Remote Shell Sessions |
| Chi tiết | Unmitigated Threat Details (bảng 100 dòng: host, threat, classification, confidence, file path, SHA256) |
Mapping compliance
Mỗi chart có trường compliance để trích xuất theo khung kiểm soát:
| Khung | Điểm kiểm soát chính | Chart phục vụ |
|---|---|---|
| PCI DSS | 5.2.1 · 5.3.4 (anti-malware) | Total / Malicious / Unmitigated Threats, Classification, Top Endpoints |
| 10.2.x · 10.4.1 (audit log) | Console Administrative Actions, STAR Rules, Failed Logins | |
| 8.3.4 (failed auth) | Failed Console Logins | |
| 12.10.5 (incident response) | Unmitigated Threats, Unmitigated Threat Details | |
| ISO 27001 | A.8.7 (chống mã độc) | Toàn bộ nhóm threat |
| A.8.15 · A.12.4.x (logging) | Console Administrative Actions | |
| A.8.16 (monitoring) | STAR Rules, STAR Severity | |
| A.8.18 (privileged utility) | Remote Shell Sessions | |
| A.5.26 (ứng phó sự cố) | Unmitigated Threats |
3 chỉ số cần theo dõi qua từng kỳ
- Tỷ lệ Unmitigated / Total — phản ánh độ phủ tự động containment. Tăng → kiểm tra policy có site nào đang ở chế độ Detect-only
- Detection Confidence Distribution — tỷ trọng
suspicioustăng đột biến → nhiều detection hành vi cần analyst triage - Failed Console Logins + Remote Shell Sessions — tấn công nhắm vào chính nền tảng bảo mật; mọi remote shell phải truy nguyên được về một change đã duyệt
Troubleshooting
| Triệu chứng | Nguyên nhân | Cách xử lý |
|---|---|---|
| Test Connection fail 401 | Token sai hoặc đã hết hạn | Tạo lại token. Console-user token hết hạn sau 30 ngày → chuyển sang Service User |
| Test Connection fail 403 | Thiếu quyền | Cấp Threats: view, STAR Rule Alerts: view, Activity: view cho service user |
| Test Connection timeout | Sai Management URL hoặc firewall chặn | URL phải là domain console, không kèm /web/api/v2.1 và không có / cuối |
| Không có event nào | Không có dữ liệu mới trong lookback | Tăng Initial Lookback Hours, hoặc kiểm tra console có threat/activity trong khoảng đó không |
Test Connection fail, lỗi invalid type for field: collect_threats | Pack ≤ 1.0.3 khai báo 3 field này là boolean — kiểu không được platform hỗ trợ (chỉ có string, password, int) | Nâng lên 1.0.4. Khi đẩy config qua API, gửi "collect_threats": "true" (chuỗi) và "page_size": 100 (số) |
| Không có event nào, Test Connection vẫn OK | Để trống các field tùy chọn trên form (pack < 1.0.3) | Điền rõ true cho cả 3 field Collect, 100 cho Page Size, 24 cho Lookback Hours. Từ 1.0.3 trở đi field rỗng tự rơi về default |
| Chỉ có threat, thiếu alert | Toggle tắt hoặc chưa có STAR rule | Bật Collect STAR Alerts; STAR alert chỉ sinh khi đã tạo Custom Detection Rule trên console |
| Chỉ thu được 1 site | Site IDs bị giới hạn | Xóa trắng field Site IDs hoặc bổ sung đủ ID, phân tách bằng dấu phẩy |
| Event vào nhưng field trống | Parser không nhận diện được luồng | Kiểm tra record có field _log_type; nếu không, parser fallback theo threatInfo/alertInfo/activityType |
file.hash.sha1 không tìm thấy | Field Standard không có field này | Dùng related.hash hoặc labels.file_sha1 |
| Rate limit / 429 | Poll quá dày hoặc page size quá lớn | Tăng Poll Interval, giảm Page Size về 100 |
| Rule "High Severity STAR Alert" không bao giờ bắn | Tenant chỉ cấu hình STAR rule ở mức Low/Medium | Rule lọc event.severity_label in (high, critical). Kiểm tra severity thực tế trên console; nếu muốn bắt cả Medium thì sửa rule (đánh đổi: nhiều alert hơn đáng kể) |
Chart Activity toàn content_update | Nhiễu cập nhật content engine chiếm ~74% luồng activity | Dashboard và report đã lọc sẵn. Chart tự tạo cần thêm điều kiện event.action NOT_EQUALS content_update |
| Cột Operator trong bảng Activity trống | SentinelOne chỉ điền user cho thao tác do người dùng console thực hiện | Bình thường — activity do hệ thống/agent sinh ra không có operator. Khoảng 15% activity có user.name |
host.ip thiếu IP so với console | Parser đã lọc IP hạ tầng ảo | Xem labels.agent_ips để có danh sách NIC đầy đủ |
Checklist connector:
- Management URL đúng dạng
https://<tenant>.sentinelone.net(không có/cuối, không có/web/api/v2.1) - Token là Service User token, còn hiệu lực
- Đủ 3 quyền
Threats: view·STAR Rule Alerts: view·Activity: view - Ít nhất một trong 3 toggle Collect đang bật
- Test Connection trả về thành công
-
sentinelone-parser.yamlđang active trong Parsers
Changelog
1.0.6
- Fix (connector) — watermark trước đây được ghi bằng
dict(một timestamp cho mỗi streamthreat/alert/activity). Platform chỉ persist watermark dưới dạng string, nên map bị ép kiểu sai và connector không đọc lại được vị trí cũ → mỗi chu kỳ đều pull lại từlookback_hours. Cursor map nay được lưu JSON-encoded string (json.dumps(..., sort_keys=True)); khi đọc vẫn chấp nhậndictcũ để instance tạo trước 1.0.6 giữ nguyên vị trí, và fallback vềlookback_hoursnếu giá trị không parse được
1.0.5
- Fix (parser) — trong
#conditionalcó 2 dòng comment# .... Platform parser loader coi mọi dòng bắt đầu bằng#là ranh giới block, nên toàn bộ code phía sau comment (chuẩn hóahost.ip,labels.agent_ips, và parsetimestamptừcreatedAt) bị cắt bỏ khi nạp trên server. Hệ quả nghiêm trọng nhất:timestampcủa mọi event rơi về giá trị khởi tạonow()(thời điểm ingest) thay vì thời điểm SentinelOne ghi nhận. Local Vector CLI vàccsp-client validate/testđều PASS nên lỗi không lộ ra. Đã xóa 2 dòng comment; tuyệt đối không đặt comment trong thân parser
1.0.4
- Fix (connector) —
connector.jsonkhai báocollect_threats/collect_alerts/collect_activitiesvới"type": "boolean", nhưng platform chỉ hỗ trợstring,password,int. Hệ quả: mọi lần lưu cấu hình đều bị chặn vớifailed to validate log source structure: invalid type for field: collect_threats. Đã chuyển 3 field sangstring(default"true");_cfg_bool()đã sẵn sàng chấp nhậntrue/false/1/0/yes/no
1.0.3
- Fix (connector) — khi để trống các field tùy chọn trên UI, console gửi lên chuỗi rỗng chứ không phải bỏ trống key →
defaulttrongconnector.jsonkhông được áp dụng. Hệ quả: cả 3 togglecollect_*bị hiểu làfalse→ connector không gọi API lần nào và không báo lỗi. Đã thêm_cfg_bool()/_cfg_int()để giá trị rỗng rơi về default, đồng thời chấp nhận boolean dạng chuỗi (true/1/yes/on) - Fix (connector) —
page_sizevàlookback_hoursrỗng trước đây gâyValueErrorởint("") - Test — bổ sung 9 test cho trường hợp config rỗng / boolean dạng chuỗi (tổng 23 test)
1.0.2
- Fix (parser) —
user.namecủa activity đọcdata.byUser(field này không tồn tại trong API); đã chuyển sangdata.username→data.userName - Improve (parser) — mở rộng chuẩn hóa
event.actioncho activity thêm 8 nhãn (user_login_failed,remote_shell_session,token_revoked,verdict_changed,incident_status_changed,content_update,agent_moved…): fallbackactivity_<mã>giảm từ 88.8% xuống 4.8% trên 1600 activity thực tế - Add (pack) — report template 16 chart kèm mapping PCI DSS / ISO 27001
- Add (pack) — parser đóng gói kèm connector tại
connectors/sentinelone/parser.yaml - Change (dashboard) — chart "Recent Console Activities" lọc bỏ
content_update
1.0.1
- Fix (parser) —
event.actioncủa luồng activity trước đây luôn làactivityvì parser đọc fielddescription(API không trả field này). Đã fallback sangprimaryDescription→ streaming rule #4 mới hoạt động được - Fix (parser) —
host.namecủa activity trống; đã đọc đúngdata.computerName - Improve (parser) —
threat.actioncủa alert chuẩn hóa về snake_case, đồng nhất với luồng threat - Improve (parser) —
host.iplọc bỏ IP loopback/link-local/Docker/libvirt; danh sách gốc giữ tạilabels.agent_ips - Add (parser) — bổ sung
observer.type,user.email,container.nametheo Field Standard
1.0.0
- Phiên bản đầu tiên: connector, parser, 4 streaming rules, 2 correlation rules, dashboard 12 chart
Hỗ trợ
- Lỗi platform/Góp ý pack: Dùng tính năng feedback trên trang Marketplace
Last updated: 2026-07-29 · Vendor: SentinelOne · Author: secops-team