This document explains how to configure the SentinelOne Singularity XDR v1.0.0 plugin in the Netskope Cloud Exchange platform. This plugin is used to fetch Devices (Endpoints) from the Inventory > Endpoints page, Users (Identity) from the Inventory > Identity page, and Applications from the Vulnerabilities page from the SentinelOne Singularity XDR platform. The plugin supports performing Manage Device Tags, Move Device to Group, Isolate/Undo Isolate, Update Asset Criticality, Run Scan and Reboot Device actions on Devices. The plugin supports performing Update Asset Criticality action on Users.
Conditions préalables
Pour réaliser cette intégration, vous avez besoin de :
- Un locataire Netskope (ou plusieurs, par exemple des instances de production et de développement/test).
- Un locataire Netskope Cloud Exchange avec le plugin Tenant et le plugin Risk Exchange déjà configurés.
- Access to the Singularity Operations Center.
- The following licences for using SentinelOne Singularity XDR plugin:
- Identity Detection & Response (IDR)
- Endpoint Security – Complete
- Make sure you have the Vulnerability Management Add-on Module license enabled for your Endpoint Security – Complete license
- Connectivity to the following hosts: https://<your-tenant>.sentinelone.net
- Your SentinelOne Site Name.
SentinelOne Singularity XDR Plugin Support
This plugin is used to fetch Devices (Endpoints) from the Inventory > Endpoints page, Users (Identity) from the Inventory > Identity page, and Applications from the Vulnerabilities page from the SentinelOne Singularity XDR platform. The plugin supports performing Manage Device Tags, Move Device to Group, Isolate/Undo Isolate, Update Asset Criticality, Run Scan and Reboot Device actions on Devices. The plugin supports performing Update Asset Criticality action on Users.
| Type de données extraites | Actions |
|---|---|
| Devices (Endpoints) Users (Identity) Applications | Manage périphérique Tag(s) Déplacer périphérique vers Groupe Mise à jour : Critique des actifs Isoler/Annuler Isoler Lancer Scan Reboot périphérique Aucune action |
Mises en correspondance
Mapping will be used to view the pulled Devices (Endpoints), Users (Identity), Applications and their respective details. Mapped fields during plugin configuration will be visible on the Records page once the data is pulled. Below is the suggested mapping that should be used while configuring the plugin.
Pull Mapping pour périphérique
| Champ du plugin | Type de données attendu | Nom de champ suggéré | Stratégie globale suggérée | Valeur de l'échantillon |
|---|---|---|---|---|
| Agent ID | String | Agent ID | Unique | 2448495699704074860 |
| ID de l'actif | String | ID de l'actif | Unique | 6umdeth4ni5brpl2e2wjfei3im |
| Nom de l'actif | String | Nom de l'hôte | Overwrite | win11-50-10-99 |
| Numéro de série | String | Numéro de série | Overwrite | VMware-42 03 0d 0e 92 ed 5c 36-d9 a0 9b c4 b6 be 64 72 |
| Network Status | String | Network Status | Overwrite | connected |
| IP Address (Public) | String | Adresse IP | Overwrite | 106.213.69.80 |
| Internal IPv4 Addresses | List | Adresses IPv4 | Overwrite | [“10.50.10.99”] |
| Internal IPv6 Addresses | List | Adresses IPv6 | Overwrite | [“fe80::7a84:24a4:7a93:9e4b”] |
| Adresses MAC | List | Adresses MAC | Overwrite | [“00:50:56:83:5e:ba”] |
| domaine | String | domaine | Overwrite | EC |
| Device Review Status | String | Device Review Status | Overwrite | Not Trusted |
| Criticité des actifs | String | Criticité des actifs | Overwrite | high |
| Infection Status | String | Infection Status | Overwrite | Healthy |
| Risk Factors | List | Risk Factors | Overwrite | [“unresolved alerts”] |
| Asset Status | String | Asset Status | Overwrite | Actif |
| Tags | List | Tags | Overwrite | [“Agent:Tag1”] |
| Last Logged In User | String | Last Logged In User | Overwrite | netskopeuser |
| OS Username | String | OS Username | Overwrite | root |
| AD User DN | Reference | AD User DN | Overwrite | CN=netskopeuser,CN=Users,DC=ec,DC=local Note: need to use reference entity as Users with Distinguished Name field. |
| Asset Contact Email | String | Asset Contact Email | Overwrite | netskope@netskope.com |
| Système d'exploitation | String | Système d'exploitation | Overwrite | Windows 11 Pro |
| Famille OS | String | Famille OS | Overwrite | Fenêtres |
| Site Name | String | Site Name | Overwrite | CRE Singularity |
| Membre de | String | Membre de | Overwrite | CloudExchangeGroup |
Note
To merge device records between Netskope Tenant and SentinelOne Singularity XDR, you can use Serial Number as a unique and common field between them.
Cartographie en mode "pull" pour les utilisateurs
| Champ du plugin | Type de données attendu | Nom de champ suggéré | Stratégie globale suggérée | Valeur de l'échantillon |
|---|---|---|---|---|
| ID de l'actif | String | ID de l'actif | Unique | dpdcguxhdecy3nnhq4aquqzxsa |
| Distinguished Name | String | Distinguished Name | Unique | CN=netskopeuser,CN=Users,DC=ec,DC=local |
| Nom de l'utilisateur principal | String | Nom de l'utilisateur principal | Overwrite | netskope@ec.local |
| domaine | String | domaine | Overwrite | ec.local |
| Risk Factors | List | Risk Factors | Overwrite | [“unresolved alerts”] |
| Infection Status | String | Infection Status | Overwrite | Healthy |
| Asset Status | String | Asset Status | Overwrite | Actif |
| Privileged Account | Boolean | Privileged Account | Overwrite | false |
| Account Enabled | Boolean | Account Enabled | Overwrite | true |
| Compte de service | Boolean | Compte de service | Overwrite | false |
| Criticité des actifs | String | Criticité des actifs | Overwrite | high |
| Member Of Groups | List | Member Of Groups | Overwrite | [“Remote Desktop Users”] |
| Bad Password Count | Number | Bad Password Count | Overwrite | 0 |
| Deleted | Boolean | Deleted | Overwrite | false |
| Tags | List | Tags | Overwrite | [“User:Tag1”] |
| Asset Contact Email | String | Asset Contact Email | Overwrite | netskope@netskope.com |
| String | Overwrite | netskopeuser@netskope.com | ||
| Site Name | String | Site Name | Overwrite | CRE Singularity |
| Display Name | String | Display Name | Overwrite | netskope user |
| Sam Account Name | String | Sam Account Name | Overwrite | netskopeuser |
| Dernière heure de connexion | DateTime | Dernière heure de connexion | Overwrite | 2026-03-16T11:07:33Z |
Note
To merge user records between Netskope Tenant and SentinelOne Singularity XDR, you can use Email as a unique and common field between them. Make sure you have common emails available on both the platforms and the API response from SentinelOne also provides the email address.
Pull Mapping for Applications
| Champ du plugin | Type de données attendu | Nom de champ suggéré | Stratégie globale suggérée | Valeur de l'échantillon |
|---|---|---|---|---|
| ID de l'application | String | ID de l'application | Unique | 2066008415608298271 |
| Application Vulnerability ID | String | Application Vulnerability ID | Unique | 2454276368152639000 |
| Nom de l'application | String | Nom de l'application | Overwrite | 7-Zip |
| Application Vendor | String | Application Vendor | Overwrite | Igor Pavlov |
| ID CVE | String | ID CVE | Overwrite | CVE-2025-11001 |
| Endpoint ID | Reference | Endpoint ID | Overwrite | 2441356020949988360 Note : il faut utiliser l’entité de référence comme périphérique avec le champ ID d’agent. |
| Endpoint Name | String | Endpoint Name | Overwrite | clw699 |
| Version de l'application | String | Version de l'application | Overwrite | 19.00 |
| NVD Base Score | Number | NVD Base Score | Overwrite | 7.80 |
| Sévérité | String | Sévérité | Overwrite | MEDIUM |
| Score de risque | Number | Score de risque | Overwrite | 5.70 |
| Exploit Maturity | String | Exploit Maturity | Overwrite | Proof of Concept |
| Remediation Availability | String | Remediation Availability | Overwrite | Official Fix |
| Confidence Level | String | Confidence Level | Overwrite | Confirmed |
| État de la vulnérabilité | String | État de la vulnérabilité | Overwrite | Detected |
| Mitigation Status | String | Mitigation Status | Overwrite | Not mitigated |
| Detection Date | DateTime | Detection Date | Overwrite | 2026-04-10T06:09:01.882869Z |
| Published Date | DateTime | Published Date | Overwrite | 2025-10-08T04:39:35Z |
| Type de système d'exploitation | String | Type de système d'exploitation | Overwrite | windows |
Note
To merge application records between Netskope Tenant and SentinelOne Singularity XDR, you can use Application Name as a unique and common field between them.
Permissions
- User should have a role with following permissions:
- Endpoints
- Affichage
- Reconnect To Network
- Reboot
- Manage Endpoint Tags
- Initiate Scan
- Disconnect From Network
- Accounts
- Affichage
- Applications
- Affichage
- View Risks
- Scan Vulnerabilities
- Groupes
- Affichage
- Move to Group
- Create
- Roles
- Roles
- Sites
- Affichage
- Task Management
- Affichage
- Unified Asset Inventory
- Affichage
- View Identity Assets
- View Endpoint Assets
- Éditer
- Supprimer
- Create
- Assign Tags
- Unified Tags(Previously Endpoint Tags)
- Affichage
- Create
- Endpoints
Note
Above permissions are for API endpoints, to view the records or performed actions on SentinelOne Singularity XDR UI, you need an admin account.
Détails de l'API
Liste des API utilisées
| Point final de l'API | Méthode | Cas d'utilisation |
|---|---|---|
| /web/api/v2.1/sites | OBTENIR | Check platform connectivity and validate site name. |
| /web/api/v2.1/xdr/assets/surface/endpoint | OBTENIR | Pull device from the platform. |
| /web/api/v2.1/xdr/assets/surface/identity | OBTENIR | Pull users from the platform. |
| /web/api/v2.1/application-management/risks/applications | OBTENIR | Retrieve applications with vulnerabilities and risks. |
| /web/api/v2.1/application-management/risks | OBTENIR | Get risks and application vulnerabilities. |
| /web/api/v2.1/groups | OBTENIR | List all static and pinned groups. |
| /web/api/v2.1/groups | PUBLIER | Create a static or pinned group. |
| /web/api/v2.1/groups/<group_id>/move-agents | PUT | Move endpoint devices to a group. |
| /web/api/v2.1/agents/tags | OBTENIR | Fetch all tags. |
| /web/api/v2.1/tag-manager | PUBLIER | Create a new tag for devices. |
| /web/api/v2.1/agents/actions/manage-tags | PUBLIER | Add a tag to a device. |
| /web/api/v2.1/agents/actions/manage-tags | PUBLIER | Remove a tag from a device. |
| /web/api/v2.1/agents/actions/disconnect | PUBLIER | Disconnect a device from the network. (Isolate) |
| /web/api/v2.1/agents/actions/connect | PUBLIER | Reconnect a device to the network. (Undo-Isolate) |
| /web/api/v2.1/xdr/assets/action | PUBLIER | Update the criticality of an asset. |
| /web/api/v2.1/agents/actions/initiate-scan | PUBLIER | Initiate full disk scan on device. |
| /web/api/v2.1/application-management/scan | PUBLIER | Initiate application vulnerability scan on device. |
| /web/api/v2.1/agents/actions/restart-machine | PUBLIER | Restart device. |
Connectivity Check
API Endpoint: GET /web/api/v2.1/sites
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Query Parameters
| Clé | Value | Description |
|---|---|---|
| sortBy | name | Sort By field |
| sortOrder | asc | Sort by order |
| limit | 1000 | Max value 1000 |
| cursor | <next_page_cursor> | Cursor position returned by the last request. Use to iterate over more than 1000 items. |
Sample Response
{
"data": {
"allSites": {
"activeLicenses": 0,
"totalLicenses": 0
},
"sites": [
{
"accountId": "1268419425097944269",
"accountName": "Netskope",
"activeLicenses": 6,
"createdAt": "2026-03-18T09:43:40.831461Z",
"creator": "netskope",
"creatorId": "2413779193746265055",
"description": null,
"expiration": null,
"externalId": null,
"healthStatus": true,
"id": "2437714560078484067",
"inheritAccountExpiration": false,
"irFields": null,
"isDefault": false,
"licenses": {
"bundles": [
{
"displayName": "Endpoint Security - Complete",
"majorVersion": 1,
"minorVersion": 33,
"name": "complete",
"surfaces": [
{
"count": -1,
"name": "Total Agents"
}
],
"totalSurfaces": -1
},
{
"displayName": "CNS Pro",
"majorVersion": 1,
"minorVersion": 19,
"name": "cloud_native_security_pro",
"surfaces": [
{
"count": -1,
"name": "Workloads"
}
],
"totalSurfaces": -1
},
{
"displayName": "Data Ingest",
"majorVersion": 1,
"minorVersion": 9,
"name": "singularity_data_lake",
"surfaces": [
{
"count": 1,
"name": "Average GB/Day"
},
{
"count": 0,
"name": "Long-Range Query Credits"
}
],
"totalSurfaces": 1
},
{
"displayName": "Hyperautomation",
"majorVersion": 1,
"minorVersion": 4,
"name": "hyperautomation",
"surfaces": [
{
"count": -1,
"name": "Action Packs"
}
],
"totalSurfaces": -1
},
{
"displayName": "Identity Detection & Response (IDR)",
"majorVersion": 2,
"minorVersion": 4,
"name": "singularity_identity",
"surfaces": [
{
"count": -1,
"name": "Total Endpoints"
}
],
"totalSurfaces": -1
}
],
"modules": [
{
"displayName": "Remote Script Orchestration",
"majorVersion": 1,
"name": "rso"
},
{
"displayName": "RemoteOps Forensics",
"majorVersion": 1,
"name": "remote_ops_forensics"
},
{
"displayName": "Binary Vault - Benign Files",
"majorVersion": 1,
"name": "binary_vault_benign"
},
{
"displayName": "Cloud Funnel",
"majorVersion": 1,
"name": "cloud_funnel"
},
{
"displayName": "Vulnerability Management",
"majorVersion": 1,
"name": "vulnerability_management"
},
{
"displayName": "Purple AI SOC Analyst",
"majorVersion": 1,
"name": "purple_ai_soc_analyst"
}
],
"settings": [
{
"displayName": "Enabled",
"groupName": "remote_shell_availability",
"setting": "Enabled",
"settingGroup": "remote_shell_availability",
"settingGroupDisplayName": "Remote Shell"
},
{
"displayName": "365 Days",
"groupName": "malicious_data_retention",
"setting": "365 Days",
"settingGroup": "malicious_data_retention",
"settingGroupDisplayName": "Malicious Data Retention"
},
{
"displayName": "Available",
"groupName": "marketplace_access_status",
"setting": "Available",
"settingGroup": "marketplace_access_status",
"settingGroupDisplayName": "Marketplace Access"
},
{
"displayName": "14 Days",
"groupName": "dv_retention",
"setting": "14 Days",
"settingGroup": "dv_retention",
"settingGroupDisplayName": "Deep Visibility Data Retention"
}
]
},
"name": "CRE Singularity",
"registrationToken": "eyJ1cmwiOiAiaHR0cHM6Ly911wYXJ0bmVycy5zZW50aW5lbG9uZS5uZXQiLCAic2IzZTRlNTRjZDAwYTkyYjljNGQ4NDdjMmMxODU0N2Q1YzRiNTUwZGM4YTRhODY1MDhjMiJ9",
"siteType": "Trial",
"sku": "Complete",
"state": "active",
"suite": "Complete",
"totalLicenses": 0,
"unlimitedExpiration": true,
"unlimitedLicenses": true,
"updatedAt": "2026-03-23T09:54:29.950520Z",
"usageType": null
}
]
},
"pagination": {
"nextCursor": null,
"totalItems": 7
}
}
Pull Devices (Endpoints)
API Endpoint: GET /web/api/v2.1/xdr/assets/surface/endpoint
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Query parameters:
| Paramètres | Value | Description |
|---|---|---|
| siteIds | <site_id> | Site ID resolved from configured Site Name |
| limit | 1000 | Max records per page |
| cursor | <next_page_cursor> | Pagination cursor |
| skipCount | true | Skip total count for speed |
Sample Response
{
"data": [
{
"activeCoverage": [
"EPP",
"IDR"
],
"adsEnabled": false,
"agent": {
"agentVersion": "25.2.5.437",
"antiTamperingStatus": "Enabled",
"configurableNetworkQuarantine": false,
"consoleConnectivity": false,
"consoleMigrationStatus": "N/A",
"customerIdentifier": "",
"decommissioned": false,
"detectionState": "install_to_dynamic",
"diskEncryption": true,
"dvConnectivity": "",
"dvConnectivityLastUpdatedDt": "2026-03-23T19:21:24.46841Z",
"firewallStatus": true,
"hasLocalConfig": false,
"id": "2441356020949988360",
"installerType": ".msi",
"lastLoggedInUser": "Crest",
"lastReportedIp": "192.168.17.205",
"location": [],
"missingPermissions": [],
"networkStatus": "connected",
"operationalState": "na",
"pendingActions": [],
"pendingUninstall": false,
"pendingUpgrade": false,
"rangerStatus": "Enabled",
"rangerVersion": "21.11.0.171",
"remoteProfilingState": "disabled",
"scanStartedTimeDt": "2026-03-23T10:18:50.535573Z",
"scanStatus": "started",
"subscribeOnDt": "2026-03-23T10:18:36.790704Z",
"uninstalled": false,
"upToDate": true,
"uuid": "df0db53f4bc14b9d89c023494c0c7f4d",
"vssProtectionStatus": "",
"vssRollbackStatus": "",
"vssServiceStatus": ""
},
"id": "qrrw3vjwit2vrtjc6sqtle3jra"
}
]
}
Pull Users (Identity)
API Endpoint: GET /web/api/v2.1/xdr/assets/surface/identity
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Query parameters
| Clé | Value | Description |
|---|---|---|
| siteIds | site_id | SentinelOne site ID. Obtained from Site Name configuration Parameter. |
| limit | 1000 | Max Value 1000 |
| cursor | <next_page_cursor> | Cursor position returned by the last request. Used to iterate over more than 1000 items. |
| skipCount | true | If true, the total number of items will not be calculated, which speeds up execution time. |
| resourceType | AD User |
Sample Response
{
"data": [
{
"accountExpires": "1970-01-01T00:00:00Z",
"activeCoverage": [
"ISPM"
],
"adminCount": 0,
"assetContactEmail": "",
"assetCriticality": "",
"assetEnvironment": "Active Directory",
"assetStatus": "Active",
"badPasswordCount": 0,
"badPasswordTime": "1970-01-01T00:00:00Z",
"category": "Identity",
"cn": "netskopeuser",
"createdTime": "2026-02-04T09:13:05Z",
"deleted": false,
"displayName": "netskopeuser",
"distinguishedName": "CN=netskopeuser,CN=Users,DC=ec,DC=local",
"domain": "ec.local",
"enabled": true,
"forest": "ec.local",
"id": "dpdcguxhdecy3nnhq4aquqzxsa",
"idSecondary": [
"RANGER_AD:19488:S1TNT=ba0iSIleFakuSPme:8f4efa15-c7db-4946-ae1a-ea1cdbf7402a",
"RANGER_AD:19488:8f4efa15-c7db-4946-ae1a-ea1cdbf7402a"
],
"infectionStatus": "Healthy",
"lastLogonTime": "2026-03-16T11:07:33Z",
"lastModifiedTime": "2026-04-02T06:45:23Z",
"lockOutTime": "1970-01-01T00:00:00Z",
"logonCount": 15,
"memberOf": [
"Remote Desktop Users"
],
"missingCoverage": [],
"name": "netskopeuser",
"notes": [
{
"createdAt": "2026-04-05T07:45:32.089694Z",
"id": "fc7d1e8a-434e-4584-9977-ba9780882e78",
"note": "<div data-rich-text-editor-signature><p class=\"rich-text-editor_paragraph__Xhp0C\">This user is for client status data generation on Netskope tenant.</p></div>",
"updatedAt": "2026-04-05T07:45:32.089704Z",
"userId": "2413779193746265055",
"userName": "ashukla@netskope.com"
}
],
"objectCategory": "Person",
"objectClass": [
"top",
"person",
"organizationalPerson",
"user"
],
"objectGuid": "8f4efa15-c7db-4946-ae1a-ea1cdbf7402a",
"objectSid": "S-1-5-21-1076376550-343107771-3680882144-1104",
"parentDistName": "CN=Users,DC=ec,DC=local",
"passwordLastSetTime": "2026-02-04T09:13:05Z",
"passwordNeverExpire": true,
"primaryGroupId": 513,
"principalName": "EC\\netskopeuser",
"privileged": false,
"recycled": false,
"resourceType": "AD User",
"riskFactors": [],
"s1AccountId": "1268419425097944269",
"s1AccountName": "Netskope",
"s1ManagementId": 19488,
"s1ScopeId": "2437714560078484067",
"s1ScopeLevel": "site",
"s1ScopePath": "Netskope/CRE Singularity",
"s1ScopeType": 1,
"s1SiteId": "2437714560078484067",
"s1SiteName": "CRE Singularity",
"s1UpdatedAt": "2026-04-05T07:48:30Z",
"samAccountName": "netskopeuser",
"samAccountType": 805306368,
"serviceAccount": false,
"subCategory": "Users and Groups",
"surfaces": [
"Identity"
],
"tags": [
{
"applied_at": "2026-04-05T07:47:18.740705Z",
"applied_by_user_id": "2413779193746265055",
"id": "2450701933736065398",
"key": "User",
"key_value": "User:Tag1",
"read_only": false,
"reserved": false,
"source": "User",
"value": "Tag1"
}
],
"userAccountControl": 66048,
"userPrincipalName": "netskopeuser@ec.local",
"usnChanged": 32916,
"usnCreated": 12841
}
],
"pagination": {
"nextCursor": "eyJpZF9jb2x1bW4iOiAiTm9uZSIsICJpZF92YWx1ZSI6IG51bGwsICJpZF9zb3J0X29yZGVyIjogImFzYyIsICJzb3J0X2J5X2NvbHVtbiI6ICJOb25lIiwgInNvcnRfYnlfdmFsdWUiOiBbImNsb25lYWJsZSBkb21haW4gY29udHJvbGxlcnMiLCAiZGV1anhxNTJhcW9ybGR2cWxqMm96Y3ZjeWEiXSwgInNvcnRfb3JkZXIiOiAiYXNjIn0%3D",
"totalItems": 56
}
}
Pull Applications
Get Basic Application Details
API Endpoint: GET /web/api/v2.1/application-management/risks/applications
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Query Parameters
| Clé | Value | Description |
|---|---|---|
| siteIds | site_id | SentinelOne site ID. Obtained from Site Name configuration Parameter. |
| limit | 1000 | Max Value 1000 |
| cursor | <next_page_cursor> | Cursor position returned by the last request. Used to iterate over more than 1000 items. |
| skipCount | true | If true, the total number of items will not be calculated, which speeds up execution time. |
| sortBy | name | sort by field |
| sortOrder | asc | Ascending sorting order |
| applicationType | Application |
Sample Response
{
"data": [
{
"applicationId": "2066008415608298271",
"applicationType": "Application",
"cveCount": 1,
"daysDetected": 16,
"detectionDate": "2026-03-20T09:55:13.780194Z",
"endpointCount": 1,
"endpointsWithoutTicket": 0,
"estimate": false,
"exploitCodeMaturity": null,
"exploitedInTheWild": "Unknown",
"highestNvdBaseScore": "4.70",
"highestRiskScore": "2.60",
"highestSeverity": "LOW",
"name": "amd64-microcode 3.20191218.1ubuntu1.3",
"remediationLevel": null,
"statuses": [
{
"count": 1,
"key": "NOT_MITIGATED",
"label": "Not mitigated",
"ticketCategory": null
}
],
"vendor": "Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>"
}
]
}
Pull Application Vulnerabilities
API Endpoint: GET /web/api/v2.1/application-management/risks
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Query Parameters
| Clé | Value | Description |
|---|---|---|
| siteIds | site_id | SentinelOne site ID. Obtained from Site Name configuration Parameter. |
| limit | 1000 | Max Value 1000 |
| cursor | <next_page_cursor> | Cursor position returned by the last request. Used to iterate over more than 1000 items. |
| skipCount | true | If true, the total number of items will not be calculated, which speeds up execution time. |
| sortBy | application | sort by field |
| sortOrder | asc | Ascending sorting order |
Sample Response
{
"data": [
{
"application": "7-Zip 19.00",
"applicationName": "7-Zip",
"applicationVendor": "Igor Pavlov",
"applicationVersion": "19.00",
"cveId": "CVE-2025-11001",
"cvssVersion": "3.1",
"daysDetected": 20,
"detectionDate": "2026-04-10T06:09:01.882869Z",
"endpointId": "2441356020949988360",
"endpointName": "clw699",
"endpointType": "laptop",
"exploitCodeMaturity": "Proof of Concept",
"id": "2454276368152639000",
"lastScanDate": "2026-04-15T10:24:22Z",
"lastScanResult": "Succeeded",
"markType": "",
"markedBy": null,
"markedDate": null,
"mitigationStatus": "Not mitigated",
"mitigationStatusChangeTime": null,
"mitigationStatusChangedBy": null,
"mitigationStatusReason": null,
"nvdBaseScore": "7.80",
"nvdCvssVersion": "3.1",
"osType": "windows",
"publishedDate": "2025-10-08T04:39:35Z",
"reason": null,
"remediationLevel": "Official Fix",
"reportConfidence": "Confirmed",
"riskScore": "5.70",
"severity": "MEDIUM",
"status": "Detected"
}
],
"pagination": {
"nextCursor": "eyJpZF9jb2x1bW4iOiAiUmlza1ZpZXcuaWQiLCAiaWRfdmFsdWUiOiAyNDU0Mjc2MzY4MTUyNjM5MDAwLCAiaWRfc29ydF9vcmRlciI6ICJhc2MiLCAic29ydF9ieV9jb2x1bW4iOiAiUmlza1ZpZXcuZW5kcG9pbnRfbmFtZSIsICJzb3J0X2J5X3ZhbHVlIjogImNsdzY5OSIsICJzb3J0X29yZGVyIjogImFzYyJ9",
"totalItems": 1570
}
}
Move Device to Group
Get Groups
API Endpoint: GET /web/api/v2.1/groups
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Query Parameters
| Clé | Value | Description |
|---|---|---|
| siteIds | site_id | SentinelOne site ID. Obtained from Site Name configuration Parameter. |
| limit | 300 | Max Value 300 |
| cursor | <next_page_cursor> | Cursor position returned by the last request. Used to iterate over more than 1000 items. |
| skipCount | true | If true, the total number of items will not be calculated, which speeds up execution time. |
| sortBy | name | sort by field |
| sortOrder | asc | Ascending sorting order |
| types | static,pinned | Types of groups to list in the action configuration parameter. |
Exemple de réponse
{
"data": [
{
"createdAt": "2026-04-02T13:54:36.500484Z",
"creator": "Netskope",
"creatorId": "2413779193746265055",
"description": "Manual group created via API.",
"filterId": null,
"filterName": null,
"id": "2448712492137993273",
"inherits": true,
"isDefault": false,
"name": "API Group",
"rank": null,
"registrationToken": "eyJ1cmwiOiAiaHR0cHM6Ly91c2VhMS1wYXJ0bmVycy5zZW50aW5lbG9uZS5uZXQiLCAic2l0ZV9rZXkiOiAiZ18xZjAyYmQwYTlhYmM3YTZjNThmMmQyYjJiMWE3MzUwMDhiMTdkYTRjOTEzNzg5YzVjYzU2MGE1MzlhZTY4NmQ1In0=",
"siteId": "2437714560078484067",
"totalAgents": 0,
"type": "static",
"updatedAt": "2026-04-02T13:54:37.150255Z"
}
],
"pagination": {
"nextCursor": "eyJpZF9jb2x1bW4iOiAiR3JvdXAuaWQiLCAiaWRfdmFsdWUiOiAyNDQ4NzEyNDkyMTM3OTkzMjczLCAiaWRfc29ydF9vcmRlciI6ICJhc2MiLCAic29ydF9ieV9jb2x1bW4iOiAiR3JvdXAubmFtZSIsICJzb3J0X2J5X3ZhbHVlIjogIkFQSSBHcm91cCIsICJzb3J0X29yZGVyIjogImFzYyJ9",
"totalItems": 4
}
}
Create Group
API Endpoint: POST /web/api/v2.1/groups
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Request Body
{
"data": {
"name": "Group name",
"description": "Group Created via Cloud Exchange",
"inherits": "True",
"siteId": "225494730938493804",
"type": "static or pinned"
}
}
Sample Response
{
"data": {
"createdAt": "2026-04-02T13:55:03.282857Z",
"creator": "netskope",
"creatorId": "2413779193746265055",
"description": "Pinned group created via API.",
"filterId": null,
"id": "2448712716877190565",
"isDefault": false,
"name": "API Pinned Group",
"rank": null,
"registrationToken": "eyJ1cmwiOiAiaHR0cHM6Ly91c2VhMS1wYXJ0bmVycy5zZW50aW5lbG9uZS5uZXQiLCAic2l0ZV9rZXkiOiAiZ19iNDMyZmM4M2I1YjRmM2U0MTY1ZDM5ODQ0ZDVlMGY0YjZlNzdjNDlkZDM3MzI1NDA3ZmUxOWQ0ODg5Y2MyYmM5In0=",
"siteId": "2437714560078484067",
"type": "pinned",
"updatedAt": "2026-04-02T13:55:05.443663Z"
}
}
Move device to Group
API Endpoint: PUT /web/api/v2.1/groups/<group_id>/move-agents
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Path Parameters
| Clé | Value | Description |
|---|---|---|
| group_id | <group_id> | ID of group to add Endpoint to. |
Request Body
{
"filter": {
"agentIds": [
"agent_id",
"agent_id"
],
"siteIds": [
"2437714560078484067"
]
}
}
Manage Device Tags
Fetch All Tags
API Endpoint: GET /web/api/v2.1/agents/tags
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Query parameters
| Clé | Value | Description |
|---|---|---|
| siteIds | site_id | SentinelOne site ID. Obtained from Site Name configuration Parameter. |
| limit | 1000 | Max Value 1000 |
| cursor | <next_page_cursor> | Cursor position returned by the last request. Used to iterate over more than 1000 items. |
| skipCount | true | If true, the total number of items will not be calculated, which speeds up execution time. |
| sortBy | clé | sort by field |
| sortOrder | asc | Ascending sorting order |
| includeEndpointCounters | false | |
| includeChildren | true | This will fetch tags that belong to child objects inside the site (i.e. tags belonging to specific groups) |
Exemple de réponse
{
"data": [
{
"allowEdit": true,
"createdAt": "2026-04-03T06:55:54.754516Z",
"createdBy": "netskope (netskope@netskope.com)",
"description": "API test",
"endpointsInCurrentScope": 0,
"id": "2449226531386302599",
"key": "Agent",
"scopeId": "2437714560078484067",
"scopeLevel": "site",
"scopePath": "Global\\Netskope\\CRE Singularity",
"totalEndpoints": 0,
"type": "agents",
"updatedAt": "2026-04-03T06:55:54.754526Z",
"updatedBy": "netskope (netskope@netskope.com)",
"value": "Tag1"
}
],
"pagination": {
"nextCursor": "eyJpZF9jb2x1bW4iOiAiVGFnTWFuYWdlclZpZXcuaWQiLCAiaWRfdmFsdWUiOiAyNDQ5MjI2NTMxMzg2MzAyNTk5LCAiaWRfc29ydF9vcmRlciI6ICJhc2MiLCAic29ydF9ieV9jb2x1bW4iOiAiVGFnTWFuYWdlclZpZXcua2V5IiwgInNvcnRfYnlfdmFsdWUiOiAiQWdlbnQiLCAic29ydF9vcmRlciI6ICJhc2MifQ%3D%3D",
"totalItems": 0
}
}
Create Tag
API Endpoint: POST /web/api/v2.1/tag-manager
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"data": {
"key": "<tag_key>",
"type": "agents",
"value": "<tag_value>",
"description": "Tag created from Cloud Exchange"
},
"filter": {
"siteIds": [
"<site_id>"
]
}
}
Exemple de réponse
{
"data": {
"createdAt": "2026-04-03T07:08:24.221290Z",
"createdById": "2413779193746265055",
"description": "API test",
"id": "2449232818371190824",
"key": "Agent1",
"scopeId": "2437714560078484067",
"scopeLevel": "site",
"type": "agents",
"updatedAt": "2026-04-03T07:08:24.221299Z",
"updatedById": "2413779193746265055",
"value": "Tag1"
}
}
Add Tag to Device
API Endpoint: POST /web/api/v2.1/agents/actions/manage-tags
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"data": [
{
"operation": "add",
"tagId": "tag_id"
}
],
"filter": {
"siteIds": [
"site_id"
],
"ids": [
"agent_id1",
"agent_id2"
]
}
}
Exemple de réponse
{
"data": {
"affected": 1
}
}
Remove Tag from Device
API Endpoint: POST /web/api/v2.1/agents/actions/manage-tags
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"data": [
{
"operation": "remove",
"tagId": "tag_id"
}
],
"filter": {
"siteIds": [
"site_id"
],
"ids": [
"agent_id1",
"agent_id2"
]
}
}
Exemple de réponse
{
"data": {
"affected": 1
}
}
Isolate/Undo-Isolate
Isolate device(Disconnect from Network)
API Endpoint: POST /web/api/v2.1/agents/actions/disconnect
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"filter": {
"ids": [
"agent_id1",
"agent_id2"
],
"siteIds": [
"site_id"
]
}
}
Exemple de réponse
{
"data": {
"affected": 1
}
}745
Undo-Isolate device(Reconnect to Network)
API Endpoint: POST /web/api/v2.1/agents/actions/connect
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"filter": {
"ids": [
"agent_id1",
"agent_id2"
],
"siteIds": [
"site_id"
]
}
}
Exemple de réponse
{
"data": {
"affected": 1
}
}
Update Asset Criticality
API Endpoint: POST /web/api/v2.1/xdr/assets/action
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"actionName": "<action_value>",
"id__in": [
"<asset_id1>",
"<asset_id2>"
]
}
| Valeur d'action autorisée (<action_value>) |
|---|
| mark_asset_criticality_low |
| mark_asset_criticality_medium |
| mark_asset_criticality_high |
| mark_asset_criticality_critical |
| clear_asset_criticality |
Exemple de réponse
{
"data": [
{
"message": "Mark Critical Value Criticality Started"
}
]
}
Run Scan
Initiate Full Disk Scan
API Endpoint: POST /web/api/v2.1/agents/actions/initiate-scan
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"filter": {
"ids": [
"<agent_id>1",
"<agent_id2>"
],
"siteIds": [
"site_id"
]
}
}
Sample Response
{
"data": {
"affected": 1
}
}
Initiate Application Vulnerability Scan
API Endpoint: POST /web/api/v2.1/agents/actions/initiate-scan
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"filter": {
"siteIds": [
"2437714560078484067"
],
"agentIds": [
"2448495699704074860"
]
}
}
Exemple de réponse
{
"data": {
"success": true
}
}
Redémarrage périphérique
API Endpoint: POST /web/api/v2.1/agents/actions/restart-machine
Headers
| Clé | Value |
|---|---|
| Authorization | ApiToken <token> |
| User-Agent | netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0 |
Corps de la demande
{
"filter": {
"siteIds": [
"site_id"
],
"ids": [
"agent_id1",
"agent_id2"
]
}
}
Exemple de réponse
{
"data": {
"affected": 1
}
}
Matrice de performance
The performance readings were conducted on a Large CE Stack with these VM specifications by pulling 500k Devices/Users/Application records each from the SentinelOne Singularity XDR plugin.
| Description | Spécifications |
|---|---|
| Détails de la pile | Taille : Grande RAM : 32 GB CPU : 16 cœurs |
| Time taken to pull Device records | ~ 30 minutes |
| Time taken to pull User records | ~ 30 minutes |
| Time taken to pull Application records | ~ 30 minutes |
Agent utilisateur
netskope-ce-6.1.0-cre-sentinelone-singularity-xdr-v1.0.0
Workflow
- Get your API Token .
- Configure the SentinelOne Singularity XDR plugin.
- Ajouter une règle de gestion.
- Ajouter des actions.
- Validez le plugin.
Regardez une vidéo
Cliquez sur "play" pour regarder une vidéo :
Get API Token from SentinelOne Singularity XDR
-
Utilisez le Singularity Operation Center pour le plugin. Pour l'activer, cliquez sur Profile puis sur My User.

Enable the Singularity Operation Center toggle to access the Singularity Operation Center.

-
Connectez-vous à votre instance SentinelOne Singularity XDR avec un compte disposant de ces autorisations.

-
Go to the My profile section and click Actions.


-
Click Generate API token. Copy the generated token to use while configuring the SentinelOne Singularity XDR plugin.

Configure the SentinelOne Singularity XDR Plugin
-
Dans Cloud Exchange, allez sur Settings > Plugins. Recherchez et sélectionnez le plugin SentinelOne Singularity XDR v1.0.0 (CRE).

-
Ajoutez un nom de configuration du plugin et modifiez l'intervalle de synchronisation si nécessaire.

-
Cliquez sur Next et ajoutez les paramètres de configuration :
- Base URL: URL de base de l'instance SentinelOne (comme https://<your-tenant>.sentinelone.net.
- API Token: API token to authenticate SentinelOne. Use the API Token generated previously.
- Site Name: Nom du site SentinelOne à partir duquel récupérer les ressources. Allez à Policies and settings > Scopes > Sites dans SentinelOne pour obtenir le nom du site. Une seule valeur de nom de site est autorisée.

-
Cliquez sur Next et sélectionnez l'entité requise dans la liste déroulante Entité , puis indiquez le mappage des champs selon vos besoins. Vous pouvez créer une New entité en cliquant sur Add New Entity.
Pour créer un champ New, cliquez sur Add Field.

Fournissez l’étiquette de champ, le type de données et la stratégie d’agrégation selon vos besoins, puis cliquez Save.

Map the created fields:



Similarly, map fields for the User entity:




Note
Veuillez vous référer à la section « Mappages » avant de configurer le plugin.
-
Faites défiler vers le haut et cliquez sur Save.

Add a Risk Exchange Business Rule for the SentinelOne Singularity XDR Plugin
-
Allez à Risk Exchange > Business Rules et cliquez sur Create New Rule.
-
Enter a Rule Name and select the Entity for the Fields that were configured for the SentinelOne Singularity XDR plugin, and then configure the query based on your requirements.

-
Cliquez sur Save.
Add an Risk Exchange Action for the SentinelOne Singularity XDR Plugin
The SentinelOne Singularity XDR supports the following action types:
- Manage Device Tag(s)
- Manage Device Tag(s) action can be used to attach/unattach tags from Devices on SentinelOne Singularity XDR.
- Move Device to Group
- Move Device to Group action can be used to move a Device to a Group.
Note: One device can be a member of only 1 group at a time on SentinelOne Singularity XDR platform.
- Move Device to Group action can be used to move a Device to a Group.
- Isolate/Undo Isolate
- Isolate/Undo Isolate can be used to Isolate/Undo Isolate device on SentinelOne Singularity XDR.
- Update Asset Criticality
- Update Asset Criticality action can be used to update the Asset Criticality on SentinelOne Singularity XDR.
Note: This action can be used for Devices and Users entity.
- Update Asset Criticality action can be used to update the Asset Criticality on SentinelOne Singularity XDR.
- Run Scan
- Run Scan action can be used to perform 2 types of scan on the devices present on SentinelOne Singularity XDR.
- Full Disk Scan
- Application Vulnerability Scan
- Run Scan action can be used to perform 2 types of scan on the devices present on SentinelOne Singularity XDR.
- Redémarrage périphérique
- Reboot Device action can be used to reboot devices present on SentinelOne Singularity XDR.
- No Action
- No action will be performed for this action. Users can generate UBA alerts in CTO by using this action and enabling the generate alerts toggle button.
Note
You can perform multiple actions on the pulled records from SentinelOne Singularity XDR on the Netskope Tenant, for performing the related actions on Netskope refer to the Netskope Risk Exchange plugin guide.
Manage Device Tag(s)
-
Dans Risk Exchange, allez à Actions et cliquez sur Add Action Configuration.
-
Select la règle métier, la configuration du plugin cible et l'action requises dans leurs listes déroulantes respectives.
-
Enable the “Require Approval” radio button if Approval is needed before performing action on the pulled records. Note that, if “Require Approval” toggle is enabled then users need to manually approve the execution of each action from the Home > Risk Exchange > Action Logs page on Cloud Exchange.
-
Définissez les paramètres d'action suivants :
- Action Type: Select action to perform on device(s). Select Add Tag(s) to attach tags to the device and select Remove Tag(s) to detach tag from the device.
- Tag Key: Key of the tag to add or remove. Only 1 static value is allowed in this field with a character limit of 500.
- Tag Value: Value of the tag to add or remove. Multiple comma separated values are allowed with a character limit of 500 for each tag.
- Agent ID: Agent ID of the device to perform the tag action on.


-
Cliquez sur Save.
Move Device to Group
-
Dans Risk Exchange, allez à Actions et cliquez sur Add Action Configuration.
-
Select the required Business Rule, Target Plugin Configuration, and Action from their respective dropdown.
-
Enable the “Require Approval” radio button if Approval is needed before performing action on the pulled records. Note that, if “Require Approval” toggle is enabled then users need to manually approve the execution of each action from the Home > Risk Exchange > Action Logs page on Cloud Exchange.
-
Définissez les paramètres d'action suivants :
- Group Name: Name of group to move the device to. Select ‘Create New Group’ to create a new group. Need to map it as a static value. To create a new group select Create New Group from the static drop down and provide the Group name in the Create Group field as well as Group type below it.
- Create Group: Name of group to be created. Applicable only when ‘Create New Group’ is selected in the ‘Group Name’ action parameter.
- Group Type: Type of group to create. Applicable only when ‘Create New Group’ is selected in the ‘Group Name’ action parameter. Note: Need to map this as static value to select value from the drop down
- Agent ID: Agent ID of the device to perform the tag action on.

-
Cliquez sur Save.
Update Asset Criticality
-
Dans Risk Exchange, allez à Actions et cliquez sur Add Action Configuration.
-
Select the required Business Rule, Target Plugin Configuration, and Action from their respective dropdown.
-
Enable the “Require Approval” radio button if Approval is needed before performing action on the pulled records. Note that, if “Require Approval” toggle is enabled then users need to manually approve the execution of each action from the Home > Risk Exchange > Action Logs page on Cloud Exchange.
-
Définissez les paramètres d'action suivants :
- Criticality Value: Criticality level to assign to the asset. Note: Need to map this as a static value to select values from the dropdown list.
- Asset ID: The ID of an asset whose criticality is to be changed.

-
Cliquez sur Save.
Isolate/Undo Isolate
-
Dans Risk Exchange, allez à Actions et cliquez sur Add Action Configuration.
-
Select the required Business Rule, Target Plugin Configuration, and Action from their respective dropdown.
-
Enable the “Require Approval” radio button if Approval is needed before performing action on the pulled records. Note that, if “Require Approval” toggle is enabled then users need to manually approve the execution of each action from the Home > Risk Exchange > Action Logs page on Cloud Exchange.
-
Définissez les paramètres d'action suivants :
- Action Type: The action type to perform. Need to map it as a static value from the drop down list.
- Agent ID: The ID of device to perform the action on.


-
Cliquez sur Save.
Run Scan
-
Dans Risk Exchange, allez à Actions et cliquez sur Add Action Configuration.
-
Select the required Business Rule, Target Plugin Configuration, and Action from their respective dropdown.
-
Enable the “Require Approval” radio button if Approval is needed before performing action on the pulled records. Note that, if “Require Approval” toggle is enabled then users need to manually approve the execution of each action from the Home > Risk Exchange > Action Logs page on Cloud Exchange.
-
Définissez les paramètres d'action suivants :
- Scan Type: Type of scan to run. Need to map it as a static value from the drop down list.
- Agent ID: The ID of device to perform the action on.


-
Cliquez sur Save.
Redémarrage périphérique
-
Dans Risk Exchange, allez à Actions et cliquez sur Add Action Configuration.
-
Select the required Business Rule, Target Plugin Configuration, and Action from their respective dropdown.
-
Enable the “Require Approval” radio button if Approval is needed before performing action on the pulled records. Note that, if “Require Approval” toggle is enabled then users need to manually approve the execution of each action from the Home > Risk Exchange > Action Logs page on Cloud Exchange.
-
Définissez les paramètres d'action suivants :
- Agent ID: The ID of device to perform the action on.

-
Cliquez sur Save.
No Action
-
Dans Risk Exchange, allez à Actions et cliquez sur Add Action Configuration.
-
Select la règle de gestion, la configuration et l'action requises dans leurs listes déroulantes respectives.
-
Enable the “Require Approval” radio button if Approval is needed before performing action on the pulled records.

-
Cliquez sur Save.
Validate the SentinelOne Singularity XDR Plugin
Valider sur Cloud Exchange
Pour valider le tirage :
Go to Risk Exchange and click Records. Select the Entity that is selected while configuring the field mapping to view the pulled records.






To verify the logs related to pulled records, go to the Settings > Logging and apply the filter with plugin name or plugin configuration name.



Journaux des actions effectuées :
-
Manage Device Tag(s)


-
Move Device to Group

-
Isolate/Undo Isolate


-
Update Asset Criticality

-
Run Scan

-
Reboot Device

Lorsqu’un enregistrement extrait correspond à l’une des règles métier configurées, l’action configurée sera effectuée sur l’enregistrement. Cela se voit dans Risk Exchange à Action Logs.

Validate on SentinelOne Singularity XDR
Note
To view the records and verify performed action on SentinelOne Singularity XDR UI, you need an admin account.
- SentinelOne Singularity XDR plugin fetches Devices (Endpoints) from the Inventory > Endpoints page, Users (Identity) from the Inventory > Identity page, and Applications from the Vulnerabilities page from the SentinelOne Singularity XDR platform.
- Log in to your SentinelOne Singularity XDR instance and navigate to the Inventory page.
-
Click Endpoint to view the available devices.

-
Click Identity to view the available users.

Note
Only AD Users will be pulled by SentinelOne Singularity XDR plugin.
-
Go to Vulnerabilities to view the Vulnerabilities.

Note
Only vulnerabilities that have Software type = APP will be pulled by the SentinelOne Singularity XDR plugin.
Validate the Manage Device Tag(s) Action
-
Log in to your SentinelOne Singularity XDR instance and go to the Inventory page.

-
Click on a particular device to open its details and go to the Tags page.

Validate the Move Device to Group Action
-
Log in to your SentinelOne Singularity XDR instance and navigate to the Inventory page.

-
Scroll right and look for the Group Name column to see the Group Name for a particular device.

Validate the Isolate/Undo Isolate Action
-
Log in to your SentinelOne Singularity XDR instance and go to the Inventory page.

-
Scroll right and look for the Network Status Column to see the Network Status for particular Device.

Validate the Update Asset Criticality Action
-
Log in to your SentinelOne Singularity XDR instance and go to the Inventory page.

-
Scroll right and look for the Asset Criticality column to see the Asset Criticality for a particular device.

Validate the Run Scan Action
-
Log in to your SentinelOne Singularity XDR instance and go to the Inventory page.

-
Scroll right and look for the Full Disk Scan column to see the Full Disk Scan status for a particular device.
Note
There is no column for Application Vulnerability Scan. For more information about Application Vulnerability Scan, you can contact the SentinelOne Singularity XDR support team.

Validate Reboot Action
-
Log in to your SentinelOne Singularity XDR instance and go to the Activities page.

-
Apply filter with Activity Type as Machine Restarted.

Dépannage
Unable to configure the SentinelOne Singularity XDR plugin
If you are unable to configure the SentinelOne Singularity XDR plugin, it could be due to one of these reasons:
- Provided Incorrect API TokenL or Base URL
- Les informations d'identification fournies n'ont pas les permissions suffisantes.
What to do:
- Pour obtenir le jeton API, suivez les étapes décrites dans la section Configuration sur SentinelOne Singularity XDR .
- Fournir les permissions appropriées au paramètre de configuration.
Unable to pull Devices or Users or Applications
If you are unable to pull Devices or Users or Applications from the SentinelOne Singularity XDR plugin, it could be due to one of these reasons:
- No Devices or Users or Applications present on the SentinelOne Singularity XDR platform.
- Une erreur s'est produite lors de l'extraction des enregistrements de la plate-forme.
- Le mappage n'est pas ajouté lors de la configuration du plugin dans la page source de l'entité.
What to do:
- Check on the SentinelOne Singularity XDR platform if Devices or Users or Applications exist or not.
- Réception d'une erreur 500 : Le serveur est peut-être en panne, attendez un peu et vérifiez plus tard.
- Réception d'une erreur 401 : Les informations d'identification fournies lors de la configuration du plugin n'existent plus. Vérifiez les informations d'identification et modifiez la configuration du plugin avec des informations d'identification valides si nécessaire.
- Make sure that the mapping is added under Devices/Users/Applications Entity and the mandatory field is mapped while configuring the plugin.
Unable to View Devices or Users or Applications details on the Records page
If you are unable to view Devices or Users or Applications details on the record table, it could be due to the Mapping for all the SentinelOne Singularity XDR fields was not provided while configuring the plugin.
What to do:
- Veillez à fournir le mappage nécessaire lors de la configuration du plugin.
- Assurez-vous que les champs créés dans une entité sont conformes aux mappages suggérés.
Comportements connus
- Newly created tags are sometimes not added to the device. To overcome this you need to execute the same action again to get the tags reflected on SentinelOne Singularity XDR platform.
- If one of the tags from the list of tags fails while performing actions related to tags then that action will be marked as Failed on the Action logs page irrespective of other tags being attached.
- For Manage Device Tag(s), Move Device to Group, Isolate/Undo Isolate and Reboot Device actions, SentinelOne APIs only give count for Success. For example: If a user performs Manage Device Tag(s) action on 100 devices to Add tags and out of which tags are only added to 90 devices then the API will only return count as 90, so we will not be able to figure out the list of devices on which tags were not added.
- For Update Asset Criticality action, SentinelOne API does not even give count for Success. So, in case of partial failure, action logs in CE will show status as Success.

