-
Notifications
You must be signed in to change notification settings - Fork 511
Open
Labels
Category: Integration qualityCategory: Quality used for SI planningCategory: Quality used for SI planningIntegration:sentinel_oneSentinelOneSentinelOneTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]
Description
Currently when users configure Sentinel One integration, 2 options are presented to the users:
- Collect SentinelOne logs via API (CEL)
- 2 data streams supported by CEL input:
applicationandapplication_risk(More to be added here).
- 2 data streams supported by CEL input:
- Collect SentinelOne logs via API (HTTP JSON)
- 5 data streams supported by HTTPJSON input:
activity,agent,alert,group, andthreat.
- 5 data streams supported by HTTPJSON input:
While the options are intuitive to some users who are aware of CEL and HTTPJSON inputs, users who do not know about them or the reason why both exist, will face significant challenge to choose the right option. Also the current options do not mention CEL and HTTPJSON as input which makes it harder even for users who are familiar with beats ecosystem to understand.
Hence this layout could be modified to improve the user experience.
Some ideas for improvement:
Metadata
Metadata
Assignees
Labels
Category: Integration qualityCategory: Quality used for SI planningCategory: Quality used for SI planningIntegration:sentinel_oneSentinelOneSentinelOneTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Team:Sit-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]

