---
title: SentinelOne Integration
description: AgileBlue can leverage the SentinelOne Rest APIs to collect and parse data from the platform.
---

[Skip to content](https://help.agileblue.com/sentinelone-integration#main-content)

English

Show submenu for translations

[Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new?hsLang=en) [Customer portal](https://help.agileblue.com/support-ticket-status?hsLang=en)

![FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png\]](https://help.agileblue.com/hs-fs/hubfs/FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png?height=32&name=FullColor-800px-Aug-04-2025-07-56-16-5066-PM.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact AgileBlue Support](https://help.agileblue.com/kb-tickets/new)
- [Customer portal](https://help.agileblue.com/support-ticket-status)
- AgileBlue Portal

 AgileBlue Portal

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://help.agileblue.com/?hsLang=en)
2. [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en)
3. [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)

# SentinelOne Integration

## AgileBlue can support monitoring, response, and bi-directional case communication with the SentinelOne platform through our API integration.

### Overview 

AgileBlue's integration with SentinelOne allows for streamlined alert management and expanded containment options. By leveraging this integration, any SentinelOne incident which generates an alert within the AgileBlue platform will be closed in both systems simultaneously. Additionally, the integration allows customers to designate which system is used for host isolation.

---

### Supported Platform Version

- SentinelOne Management Console API version 2.1

---

### Setup Steps - Alert Monitoring

This section describes the steps to configure API access for the AgileBlue SOC to ingest alerts from SentinelOne.

1. Log in to the **SentinelOne Management Console** as an Admin.
   
   ![](https://help.agileblue.com/hs-fs/hubfs/sentinel-one-dashboard-png.png?width=670&height=321&name=sentinel-one-dashboard-png.png)
2. Navigate to **Logged User Account** in the top right panel on the navigation bar.
3. Click **My User**.
4. In the **API Token** section, click **Generate**. 
     1. NOTE: The API token generated by user is time-limited. To rotate a new token login with the dedicated admin account.
5. Provide the following values to **AgileBlue Support** via a **secure** communication method. 
     1. **API Token**
     2. **SentinelOne console URL**

---

### Setup Steps - Bi-Directional Integration

This section covers the steps to enable bi-directional communication between the AgileBlue SecOps platform and SentinelOne. This includes the ability to allow AgileBlue's platform to leverage the SentinelOne agent for host isolation capabilities as well as bi-directional case communication between the two platforms.

1. Within the **SentinelOne Console**, navigate to **Dashboard \> Settings \> Users \> Service Users \> Actions \> Create New Service User**
2. Name the service user **AgileBlue API** and set expiration to **1 month**, then click **Next
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Jan-20-2026-09-13-36-0287-PM.png?width=889&height=687&name=undefined-Jan-20-2026-09-13-36-0287-PM.png)**
3. Select the **Site** for the user to be created under the set the **role** to **Admin**
4. Click **Create User**
5. After creating the user, you'll be given one opportunity to collect the **API Token**, copy this value and store securely – you'll need this value later
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Jan-20-2026-09-22-11-2771-PM.png?width=909&height=219&name=undefined-Jan-20-2026-09-22-11-2771-PM.png)
6. Log in to the [**AgileBlue Portal**](https://portal.agileblue.com/login)and navigate to **Settings \> Alert Playbook**
7. Scroll to the **Host Isolation System** section and paste the API token gathered in step 5 under **API Token**
8. Next, paste the URL from your **SentinelOne Console** as seen below – the URL should end with sentinelone.net/
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Jan-20-2026-09-26-43-0458-PM.png?width=936&height=252&name=undefined-Jan-20-2026-09-26-43-0458-PM.png)
9. Click on **Validate Credentials **to ensure the connection has been established, if successful the following message will appear:
   
   ![](https://help.agileblue.com/hs-fs/hubfs/undefined-Jan-20-2026-09-26-38-9679-PM.png?width=706&height=162&name=undefined-Jan-20-2026-09-26-38-9679-PM.png)
10. After validating your credentials, scroll to the bottom of the page and click **Save**

---

### **Need Help?**

AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to [**AgileBlue Support**](https://help.agileblue.com/kb-tickets/new?hsLang=en).

*Email: support@agileblue.com   
Phone: (216) 606-9400🚨*

- [Agent Installation](https://help.agileblue.com/agent-installation?hsLang=en#main-content)

    - [Windows](https://help.agileblue.com/agent-installation?hsLang=en#windows)
    - [Mac](https://help.agileblue.com/agent-installation?hsLang=en#mac)
    - [Linux](https://help.agileblue.com/agent-installation?hsLang=en#linux)
    - [Syslog Collection](https://help.agileblue.com/agent-installation?hsLang=en#syslog-collection)
    - [Agent Management](https://help.agileblue.com/agent-installation?hsLang=en#agent-management)
- [Application Integrations](https://help.agileblue.com/application-integrations?hsLang=en#main-content)

    - [Microsoft Tools](https://help.agileblue.com/application-integrations?hsLang=en#microsoft-tools)
    - [Third-Party EDR](https://help.agileblue.com/application-integrations?hsLang=en#third-party-edr)
    - [Other Security Tools](https://help.agileblue.com/application-integrations?hsLang=en#other-security-tools)
- [Cloud Integrations](https://help.agileblue.com/cloud-integrations?hsLang=en)
- [AgileBlue Features](https://help.agileblue.com/agileblue-features?hsLang=en#main-content)

    - [Portal Management](https://help.agileblue.com/agileblue-features?hsLang=en#portal-management)
    - [Support Systems](https://help.agileblue.com/agileblue-features?hsLang=en#support-systems)
- [Vulnerability Scanning](https://help.agileblue.com/vulnerability-scanning?hsLang=en)
- [Release Notes](https://help.agileblue.com/release-notes?hsLang=en)

[![AgileBlue](https://help.agileblue.com/hs-fs/hubfs/Current-Website-Logo-Replacement.png?width=1321&height=648&name=Current-Website-Logo-Replacement.png "AgileBlue")](http://www.agileblue.com)

AgileBlue Support Phone: 216.606.9400

Copyright © 2026, AgileBlue