Skip to content

Sentinel One: layout improvements to inputs section #15724

@kcreddy

Description

@kcreddy

Currently when users configure Sentinel One integration, 2 options are presented to the users:

  • Collect SentinelOne logs via API (CEL)
    • 2 data streams supported by CEL input: application and application_risk (More to be added here).
  • Collect SentinelOne logs via API (HTTP JSON)
    • 5 data streams supported by HTTPJSON input: activity, agent, alert, group, and threat.
Image

While the options are intuitive to some users who are aware of CEL and HTTPJSON inputs, users who do not know about them or the reason why both exist, will face significant challenge to choose the right option. Also the current options do not mention CEL and HTTPJSON as input which makes it harder even for users who are familiar with beats ecosystem to understand.
Hence this layout could be modified to improve the user experience.

Some ideas for improvement:

  1. Update title to use the word input. This makes it slightly clear for users familiar with beats. However uncertainty could still exist.

    Image
  2. Change the input title to add data stream names and removed the words CEL and HTTPJSON.

    Image

Metadata

Metadata

Labels

Category: Integration qualityCategory: Quality used for SI planningIntegration:sentinel_oneSentinelOneTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions