Skip to content

SentinelOne CEF

Realm Security integrates seamlessly with SentinelOne, enabling intelligent routing and analysis of security event logs via CEF over syslog.

Setup SentinelOne CEF Source in Realm

Sending SentinelOne CEF logs to Realm requires use of the Cloud Syslog input feed. How to setup Cloud Syslog Input Feed

Configure SentinelOne Syslog Forwarding

  1. Log in to your SentinelOne management console.
  2. Navigate to Settings > Integrations > Syslog.
  3. Enable syslog and fill out the server details:

    Host: IP address or hostname of the Realm Collector VM
    Port: Port number assigned to the SentinelOne CEF stream found in the Realm console
    Formatting: CEF
    Transport: TLS

  4. Under TLS Certificate, upload the certificate provided by Realm Security.
  5. Click Save.