Appearance
SentinelOne CEF
Realm Security integrates seamlessly with SentinelOne, enabling intelligent routing and analysis of security event logs via CEF over syslog.
Setup SentinelOne CEF Source in Realm
Sending SentinelOne CEF logs to Realm requires use of the Cloud Syslog input feed. How to setup Cloud Syslog Input Feed
Configure SentinelOne Syslog Forwarding
- Log in to your SentinelOne management console.
- Navigate to Settings > Integrations > Syslog.
- Enable syslog and fill out the server details:
Host: IP address or hostname of the Realm Collector VM
Port: Port number assigned to the SentinelOne CEF stream found in the Realm console
Formatting:CEF
Transport:TLS - Under TLS Certificate, upload the certificate provided by Realm Security.
- Click Save.