Elastic medium stable kql
SentinelOne Threat External Alerts
Generates a detection alert for each SentinelOne threat written to the configured indices. Enabling this rule allows you to immediately begin investigating SentinelOne threat alerts in the app.
Detection Logic
event.kind: alert and data_stream.dataset: sentinel_one.threat Field Validations
Loading…
Comments (0)
Loading comments...