SentinelOne β Alert Ingestion Guide
This guide covers two approaches for ingesting SentinelOne alerts into Swimlane Turbine, normalized to TEDS format:
- Connector β Use the SentinelOne connector's built-in ingestion actions directly in a playbook for full control over your workflow.
- Component β Use the SOC - Unified Alert Ingestion - SentinelOne Component for a turnkey pipeline with deduplication, observable enrichment, TI record management, and automated case creation.
Both approaches deliver alerts in Swimlane's Turbine Extendable Data Schema (TEDS) format, the same format used across CrowdStrike, Microsoft Graph, and other connectors. One downstream playbook handles alerts from any source.
Key Capabilities
- Unified alert format β Every SentinelOne alert is normalized to TEDS, enabling cross-vendor playbooks and dashboards.
- Built-in enrichment β Timeline events, analyst notes, mitigation action results, Purple AI investigation verdicts, and raw indicators from the SentinelOne Data Lake.
- Incremental polling β Only new or updated alerts are fetched on each run, with automatic checkpoint management. No duplicates, efficient API usage.
- Production-ready β Handles pagination, scope filtering, error recovery, and high-volume environments out of the box.
Using the Connector
The SentinelOne connector includes two purpose-built actions for alert ingestion: Ingest Unified Alerts and Get Unified Alerts. Use this approach when you want full control over your playbook logic.
How It Works
- Authenticate β Connects to the SentinelOne API using the configured asset credentials (API Key).
- Query Alerts β Calls the SentinelOne Unified Alerts GraphQL API (/unifiedalerts/graphql) with scope, time range, and optional filters.
- Incremental Polling β Uses a checkpoint timestamp (lastUpdatedAt) to fetch only new or updated alerts since the last run. On the first run, it looks back a configurable number of hours.
- Paginate β Automatically handles pagination (configurable page size up to 1000, with a max pages safety limit).
- Normalize to TEDS β Each alert is transformed into a teds_object containing standardized fields (severity, timestamps, impacted hosts, observables, MITRE ATT&CK mappings, originating files).
- Enrich β When enrichment is enabled (default), the action automatically fetches and attaches additional context for each alert: timeline, history, analyst notes, mitigation actions, Purple AI investigations, and raw indicators.
- Return β Returns the normalized alerts along with a last_updated_at timestamp for the next polling run.
The Get Unified Alerts action is a lower-level alternative that retrieves raw alert data from the GraphQL API with granular field-level control (50+ skip flags). Use this when you need custom processing rather than the built-in TEDS normalization.
Connector Setup
Prerequisites
- SentinelOne API Token with access to the target scope (Account, Site, or Group)
- The SentinelOne connector installed from the Turbine marketplace
- Your SentinelOne Account ID, Site ID, or Group ID
Steps
- Create an Asset β In Turbine, create a new SentinelOne asset with your API Token and Management Console URL.
- Create a Playbook β Create a new playbook with a scheduled trigger (e.g., every 5 minutes).
- Add the Ingest Unified Alerts Action β Add the SentinelOne connector's Ingest Unified Alerts action to your playbook.
- Configure Scope β Set the scopeType (ACCOUNT, SITE, or GROUP) and provide the corresponding scopeIds.
- Configure First Run β Set backfillHours (e.g., 24) or backfillTimeString (e.g., "24 hours ago") for the initial ingestion window.
- Enable Incremental Polling β Store data.last_updated_at from each run and pass it back as lastUpdatedAt on the next run.
- Process Alerts β Use the teds_object output with the "Process as TEDS alert" action to create Turbine records automatically.
Authentication
- API Token β SentinelOne API Token generated from the Management Console
- Management Console URL β Your SentinelOne tenant URL
Using the Component
The SOC - Unified Alert Ingestion - SentinelOne Component provides a complete SOC ingestion pipeline on top of the connector actions. Use this approach when you want out-of-the-box alert ingestion with deduplication, observable enrichment, TI record management, and automated case creation.
What the Component Adds
- Alert Deduplication β Checks if an alert has already been ingested by matching alert_uid against existing CIM records, preventing duplicate cases.
- Case Creation β Creates structured Case and Incident Management (CIM) records from TEDS alerts with all normalized fields.
- Observable Extraction β Parses observables from alert content and file evidence, calculates file hashes, and structures them as TEDS observables.
- Multi-Provider Enrichment β Enriches extracted observables using up to five Threat Intelligence providers:
- VirusTotal β file hash and URL reputation
- AbuseIPDB β IP address reputation
- IPQualityScore β IP and email risk scoring
- URLhaus β malicious URL detection
- Recorded Future β threat intelligence context
- Threat Intelligence Records β Creates or updates TI records for each observable. New observables trigger enrichment automatically; existing observables get updated Last Seen timestamps.
- Alert Correlation β Correlates incoming alerts against existing CIM records based on shared observables, alert rules, or custom logic.
- Knowledge Base Linking β Links relevant Knowledge Base Articles (KBAs) to cases based on signal source and alert rules.
How It Works
- Ingest Alerts β Uses the SentinelOne connector's Ingest Unified Alerts action to retrieve new alerts with incremental polling.
- Deduplicate β Each alert's alert_uid is checked against existing CIM records. Duplicates are skipped.
- Extract Observables β The IOC Parser and file extraction components identify observables (domains, IPs, file hashes, emails, URLs) from alert content and attached files.
- Enrich Observables β Each observable is sent through configured TI enrichment providers. Results (verdicts, risk scores, context) are appended to the observable.
- Create TI Records β Each enriched observable is saved to a Threat Intelligence record.
- Correlate β The alert is checked for correlation with existing cases based on shared observables and alert rules.
- Create Case β A CIM record is created with the full TEDS alert, enriched observables, TI tracking IDs, KBA references, and correlation data.
Component Setup
Prerequisites
- SentinelOne API Token with access to the target scope
- The SentinelOne connector installed from the Turbine marketplace
- The SOC - Unified Alert Ingestion - SentinelOne Component imported from the marketplace
- A Turbine application with Case and Incident Management (CIM) and Threat Intelligence (TI) record types configured
- (Optional) Assets for enrichment providers: VirusTotal, AbuseIPDB, IPQualityScore, URLhaus, Recorded Future
Steps
- Create an Asset β In Turbine, create a new SentinelOne asset with your API Token and Management Console URL.
- Install the Component β Import the SOC - Unified Alert Ingestion - SentinelOne Component from the marketplace.
- Configure Enrichment β Set up assets for the TI enrichment providers you want to use. The Component will use whichever providers have valid assets configured.
- Configure the Component β Set the scope, polling interval, and enrichment preferences within the Component configuration.
- Schedule the Playbook β The Component handles checkpointing, deduplication, enrichment, and record creation automatically on each scheduled run.
Recommended Configuration
Scenario | pageSize | maxPages | backfillHours | enableEnrichment |
|---|---|---|---|---|
Initial deployment | 500 | 100 | 24 | true |
Production polling (every 5 min) | 100 | 10 | β | true |
High-volume environments | 1000 | 1000 | β | false |
Testing | 100 | 1 | 1 | true |
TEDS Output Schema
Both the connector and Component produce alerts in this standardized format:
TEDS Field | Type | Description |
|---|---|---|
alert_uid | string | Unique alert identifier |
alert_title | string | Alert display name |
alert_description | string | Description of what was detected |
alert_severity | string | CRITICAL, HIGH, MEDIUM, LOW |
alert_provider | string | "SentinelOne" |
alert_categories | array | E.g., ["MALWARE"] |
alert_created_timestamp | string | ISO 8601 creation time |
alert_start_timestamp | string | When the threat was first observed |
alert_end_timestamp | string | Last update time |
alert_ingested_timestamp | string | When the alert was ingested |
alert_impacted_hostnames | array | Affected endpoint hostnames |
alert_impacted_ip_addresses | array | Affected endpoint IPs |
alert_impacted_usernames | array | Affected user accounts |
alert_originating_files | array | File paths that triggered the alert |
observables | array | Objects with observable_type and observable_value (SHA256, file names, IPs, domains) |
alert_rules | array | Objects with rule_name, rule_type, rule_description |
signal_source | string | Source signal type |
raw_alert | object | Complete original SentinelOne alert |
Enrichment Data (alert_metadata)
When enrichment is enabled, each alert also includes:
Field | Type | Description |
|---|---|---|
alert_notes | array | Analyst notes (ID, text, timestamp) |
alert_timeline | array | Detection and status change events |
alert_history | array | Alert state change history |
alert_mitigation_actions | array | Remediation actions taken (quarantine, kill, etc.) |
ai_investigations | array | Purple AI analysis verdict and summary |
raw_indicators | array | Raw indicators from the SentinelOne Data Lake |
Sample Output
{
"teds_object": {
"alert_uid": "019866b7-d9e1-7c8b-a7c2-3cd553dd3d24",
"alert_title": "property_spray.js detected as Malware",
"alert_description": "Windows file events analysis detected suspicious activity",
"alert_severity": "MEDIUM",
"alert_provider": "SentinelOne",
"alert_categories": ["MALWARE"],
"alert_created_timestamp": "2025-08-01T17:38:58.343Z",
"alert_start_timestamp": "2025-08-01T17:38:58.331Z",
"alert_end_timestamp": "2025-12-27T09:52:26.907Z",
"alert_impacted_hostnames": ["S1DEMOJS"],
"alert_impacted_ip_addresses": ["192.168.1.100"],
"alert_impacted_usernames": ["admin"],
"alert_originating_files": ["C:\\Users\\admin\\Downloads\\property_spray.js"],
"observables": [
{"observable_type": "sha256", "observable_value": "7069f825..."},
{"observable_type": "file_name", "observable_value": "property_spray.js"}
],
"alert_rules": [
{"rule_name": "Agent Policy", "rule_type": "Reputation", "rule_description": "Windows file events analysis detected..."}
],
"signal_source": "Alert"
},
"alert_metadata": {
"alert_notes": [{"text": "Investigated and confirmed as false positive"}],
"alert_timeline": [{"eventType": "DETECTION", "eventText": "Alert created"}],
"alert_mitigation_actions": [{"actionType": "QUARANTINE", "status": "SUCCESS"}],
"ai_investigations": [{"verdict": "SUSPICIOUS", "summary": "AI analysis suggests suspicious behavior"}]
}
}Connector Reference
For the full list of actions, input/output schemas, and authentication setup, see the SentinelOne connector documentation.