Skip to content

Commit

Permalink
sentinel_one: document alert data stream environment limitation
Browse files Browse the repository at this point in the history
  • Loading branch information
efd6 committed Sep 11, 2024
1 parent ca0cfc0 commit 1b066ee
Show file tree
Hide file tree
Showing 4 changed files with 10 additions and 1 deletion.
2 changes: 2 additions & 0 deletions packages/sentinel_one/_dev/build/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ To collect data from SentinelOne APIs, you must have an API token. To create an

The API token generated by the user is time-limited. To rotate a new token, log in with the dedicated admin account.

The **alert** data stream depends on STAR Custom Rules. STAR Custom Rules are supported in Cloud environments, but are not supported in on-premises environments. Because of this, the **alert** data stream is not supported in on-premises environments.

## Logs

### activity
Expand Down
5 changes: 5 additions & 0 deletions packages/sentinel_one/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.25.1"
changes:
- description: Document limitation for using the alert data stream in on-premises environments.
type: bugfix
link: https://github.com/elastic/integrations/pull/11036
- version: "1.25.0"
changes:
- description: Add agent.* to alerts data.
Expand Down
2 changes: 2 additions & 0 deletions packages/sentinel_one/docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ To collect data from SentinelOne APIs, you must have an API token. To create an

The API token generated by the user is time-limited. To rotate a new token, log in with the dedicated admin account.

The **alert** data stream depends on STAR Custom Rules. STAR Custom Rules are supported in Cloud environments, but are not supported in on-premises environments. Because of this, the **alert** data stream is not supported in on-premises environments.

## Logs

### activity
Expand Down
2 changes: 1 addition & 1 deletion packages/sentinel_one/manifest.yml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
format_version: "3.0.2"
name: sentinel_one
title: SentinelOne
version: "1.25.0"
version: "1.25.1"
description: Collect logs from SentinelOne with Elastic Agent.
type: integration
categories:
Expand Down

0 comments on commit 1b066ee

Please sign in to comment.