When you complete setting up the connection, you can configure the integration to periodically pull data. The data is saved in tables that extend from the Configuration item [cmdb_ci] table.
AWS Datacenter [cmdb_ci_aws_datacenter]
The following attributes in the AWS Datacenter [cmdb_ci_aws_datacenter] table are populated by collected data.
| Attribute label |
Attribute name |
| Object Id |
object_id |
| Region |
region |
| Name |
name |
表 : 1. Relationships for AWS Datacenter
| Parent Class |
Relationship Type |
Child Class |
| AWS Datacenter [cmdb_ci_aws_datacenter] |
Hosted On: Hosts |
Cloud Service Account [cmdb_ci_cloud_service_account] |
Azure Datacenter [cmdb_ci_azure_datacenter]
The following attributes in the Azure Datacenter [cmdb_ci_azure_datacenter] table are populated by collected data.
| Attribute label |
Attribute name |
| Object Id |
region |
| Name |
name |
| Region |
region |
表 : 2. Relationships for Azure Data Center
| Parent Class |
Relationship Type |
Child Class |
| Azure Datacenter [cmdb_ci_azure_datacenter] |
Hosted On: Hosts |
Cloud Service Account [cmdb_ci_cloud_service_account] |
Availability Zone [cmdb_ci_availability_zone]
The following attributes in the Availability Zone [cmdb_ci_availability_zone] table are populated by collected data.
表 : 3. Relationships for Availability Zone
| Parent Class |
Relationship Type |
Child Class |
| Azure Datacenter [cmdb_ci_azure_datacenter] |
Contains:Contained by |
Availability Zone [cmdb_ci_availability_zone] |
| Attribute label |
Attribute name |
| Name |
name |
| Object Id |
object_id |
| Region |
region |
GCP Datacenter [cmdb_ci_google_datacenter]
The following attributes in the GCP Datacenter [cmdb_ci_google_datacenter] table are populated by collected data.
| Attribute label |
Attribute name |
| Name |
name |
| Object Id |
object_id |
| Account Id |
account_id |
| Datacenter Type |
datacenter_type |
表 : 4. Relationships for GCP Datacenter
| Parent Class |
Relationship Type |
Child Class |
| GCP Datacenter [cmdb_ci_google_datacenter] |
Hosted On: Hosts |
Cloud Service Account [cmdb_ci_cloud_service_account] |
Cloud Service Account [cmdb_ci_cloud_service_account]
The following attributes in the Cloud Service Account [cmdb_ci_cloud_service_account] table are populated by collected data.
| Attribute label |
Attribute name |
| Name |
name |
| Object Id |
object_Id |
| Account Id |
account_Id |
| Datacenter Type |
datacenter_type |
表 : 5. Relationships for Cloud Service Account
| Parent Class |
Relationship Type |
Child Class |
| Network [cmdb_ci_network] |
Hosted On: Hosts |
Cloud Service Account [cmdb_ci_cloud_service_account] |
Cloud Subnets [cmdb_ci_cloud_subnet]
The following attributes in the Cloud Subnets [cmdb_ci_cloud_subnet] table are populated by collected data.
| Attribute label |
Attribute name |
| Object Id |
object_id |
| Name |
name |
表 : 6. Relationships for Cloud Subnets
| Parent Class |
Relationship Type |
Child Class |
| Network [cmdb_ci_network] |
Contains:Contained by |
Cloud Subnets [cmdb_ci_cloud_subnet] |
Hardware Type [cmdb_ci_compute_template]
The following attributes in the Hardware Type [cmdb_ci_compute_template] table are populated by collected data.
| Attribute label |
Attribute name |
| Name |
name |
| Object Id |
object_id |
表 : 7. Relationships for Hardware Type
| Parent Class |
Relationship Type |
Child Class |
| Compute Template [cmdb_ci_compute_template] |
Hosted On: Hosts |
Cloud Service Account [cmdb_ci_cloud_service_account] |
| VM Instance [cmdb_ci_vm_instance] |
Provisioned From::Provisioned |
Compute Template [cmdb_ci_compute_template] |
Cloud Network [cmdb_ci_network]
The following attributes in the Cloud Network [cmdb_ci_network] table are populated by collected data.
| Attribute label |
Atribute name |
| Object Id |
object_id |
| Name |
name |
表 : 8. Relationships for Cloud network
| Parent Class |
Relationship Type |
Child Class |
| Network [cmdb_ci_network] |
Hosted on::Hosts |
Cloud Service Account [cmdb_ci_cloud_service_account] |
Virtual Machine Instance [cmdb_ci_vm_instance]
The following attributes in the Virtual Machine Instance [cmdb_ci_vm_instance] table are populated by collected data.
| Attribute label |
Attribute name |
| Object Id |
object_id |
| Name |
name |
| VM Instance ID |
vm_inst_id |
表 : 9. Relationships for VM Instance
| Parent Class |
Relationship Type |
Child Class |
| VM Instance [cmdb_ci_vm_instance] |
Hosted On: Hosts |
AWS Datacenter [cmdb_ci_aws_datacenter] |
| VM Instance [cmdb_ci_vm_instance] |
Virtualized by::Virtualizes |
Server [cmdb_ci_server] |
| VM Instance [cmdb_ci_vm_instance] |
Hosted On: Hosts |
AWS Datacenter [cmdb_ci_aws_datacenter] |
Key Value [cmdb_key_value]
The following attributes in the Key Value [cmdb_key_value] table are populated by collected data.
| Attribute label |
Attribute name |
| Key |
key |
| Value |
value |
| Tag |
tag |
Image [cmdb_ci_os_template]
The following attributes in the Image [cmdb_ci_os_template] table are populated by collected data.
| Attribute label |
Attribute name |
| Object Id |
object_id |
| Name |
name |
表 : 10. Relationships for Image
| Parent Class |
Relationship Type |
Child Class |
| Image [cmdb_ci_os_template] |
Hosted on::Hosts |
Cloud Service Account [cmdb_ci_cloud_service_account] |
Server [cmdb_ci_server]
The following attributes in the Server [cmdb_ci_server] table are populated by collected data.
| Attribute label |
Attribute name |
| Name |
name |
| Serial number |
serial_number |
| CPU speed (MHz) |
cpu_speed |
| CPU count |
cpu_count |
| RAM (MB) |
ram |
| OS Address Width (bits) |
os_address_width |
| Operating System |
os |
| CPU core count |
cpu_core_count |
| Fully qualified domain name |
fqdn |
| CPU name |
cpu_name |
| First Discovered |
first_discovered |
Computer [cmdb_ci_computer]
The following attributes in the Computer [cmdb_ci_computer] table are populated by collected data.
| Attribute label |
Attribute name |
| Name |
name |
| Serial number |
serial_number |
| CPU speed (MHz) |
cpu_speed |
| CPU count |
cpu_count |
| RAM (MB) |
ram |
| OS Address Width (bits) |
os_address_width |
| Operating System |
os |
| CPU core count |
cpu_core_count |
| Fully qualified domain name |
fqdn |
| CPU name |
cpu_name |
| First Discovered |
first_discovered |
SentinelOne Asset Tags [sn_sec_sgc_sntlone_asset_tags]
The following attributes in the SentinelOne Asset Tags [sn_sec_sgc_sntlone_asset_tags] table are populated by collected data.
| Attribute label |
Attribute name |
| ID |
tags_id |
| Key |
tags_key |
| Value |
tags_value |
| Assigned At |
tags_assignedat |
| Assigned By |
tags_assignedby |
| Assigned By ID |
assigned_by_id |
IP Address [cmdb_ci_ip_address]
The following attributes in the IP Address [cmdb_ci_ip_address] table are populated by collected data.
| Attribute label |
Attribute name |
| IP Address |
ip_address |
| Name |
name |
| Nic |
nic |
| IP version |
ip_version |
表 : 11. Relationships for IP Address
| Parent Class |
Relationship Type |
Child Class |
| Server [cmdb_ci_server] |
Owns:Owned by |
IP Address [cmdb_ci_ip_address] |
Network Adapter [cmdb_ci_network_adapter]
The following attributes in the Network Adapter [cmdb_ci_network_adapter] table are populated by collected data.
| Attribute label |
Attribute name |
| Mac Address |
mac_address |
| Name |
name |
| Ip Default Gateway |
ip_default_gateway |
| Discovery Source |
discovery_source |
表 : 12. Relationships for Network Adapter
| Parent Class |
Relationship Type |
Child Class |
| Server [cmdb_ci_server] |
Owns:Owned by |
Network Adapter [cmdb_ci_network_adapter] |
SentinelOne Additional Attributes [sn_sec_sgc_sntlone_additonal_attributes]
The following attributes in the SentinelOne Additional Attributes [sn_sec_sgc_sntlone_additonal_attributes] table are populated by collected data.
| Attribute label |
Attribute name |
| NetworkInterfaces Name |
networkinterfaces_name |
| NetworkInterfaces GatewayMacAddress |
networkinterfaces_gatewaymacaddress |
| UUID |
uuid |
| Configuration item |
configuration_item |
| Network Quarantine Enabled |
network_quarantine_enabled |
| Last Successful Scan Date |
last_successful_scan_date |
| License_Key |
license_key |
| First Discovered |
first_discovered |
| Location Enabled |
location_enabled |
| Ad ComputerDistinguishedName |
ad_computerdistinguishedname |
| Agent Version |
agent_version |
| Scan Status |
scan_status |
| Scan Started At |
scan_started_at |
| ID |
id |
| IP Address Subnet |
ip_address_subnet |
| Mitigation Mode Suspicious |
mitigation_mode_suspicious |
| Last Scan Finished At |
last_scan_finished_at |
| Firewall Enabled |
firewall_enabled |
| Console Migration Status |
console_migration_status |
| Group ID |
group_id |
| Operational State Expiration |
operational_state_expiration |
| Last IP To Mgmt |
last_ip_to_mgmt |
| Threat Reboot Required |
threat_reboot_required |
| Machine Type |
machine_type |
|
Is Pending Uninstall
Ranger Status
|
Is_pending_uninstall
ranger_status
|
| Ad LastUserDistinguishedName |
ad_lastuserdistinguishedname |
| Agent Up To Date |
agent_up_to_date |
| Ranger Version |
ranger_version |
| Last Boot Time |
last_boot_time |
| Disk Encryption Status |
disk_encryption_status |
| Mitigation Mode |
mitigation_mode |
| Last Full Scan |
last_full_scan |
| Agent Uninstalled |
agent_uninstalled |
| Extenal Id |
extenal_id |
| Updated At |
updated_at |
| Last Scan Aborted At |
last_scan_aborted_at |
| Network Status |
network_status |
| Show Alert Icon |
show_alert_icon |
| Subscribed On |
subscribed_on |
| Account ID |
account_id |
| Recently Active |
recently_active |
| Active Threats |
active_threats |
| Allow Remote Shell |
allow_remote_shell |
| Site Name |
site_name |
| First Full Mode Time |
first_full_mode_time |
| Infected |
infected |
| App Vulnerability Status |
app_vulnerability_status |
| Site ID |
site_id |
| Agent Installer Type |
agent_installer_type |
| Account Name |
acount_name |
| NetworkInterfaces Name |
networkinterfaces_name |
| NetworkInterfaces GatewayMacAddress |
networkinterfaces_gatewaymacaddress |
| NetworkInterfaces ID |
networkinterfaces_id |
| user_actions_needed |
user_actions_needed |
| aws_security_group |
aws_security_group |
| proxyState_console |
proxyState_console |
| proxyState_deepVisibility |
proxyState_deepVisibility |
| Ad UserPrincipalName |
ad_userPrincipalName |
| Ad ComputerMemberOf |
ad_computerMemberOf |
| Ad ComputerDistinguishedName |
ad_computerDistinguishedName |
| Ad LastUserMemberOf |
ad_lastUserMemberOf |
| Ad LastUserDistinguishedName |
ad_lastUserDistinguishedName |
| Ad Mail |
ad_mail |
| Agent Decommissioned |
agent_decommissioned |
| Agent Operational State |
agent_operational_state |
| Last Active Date |
last_active_date |
| Group Updated At |
group_updated_at |
| Missing Permissions |
missing_permissions |
Service Graph Connector for SentinelOne Properties
| Property |
Description |
| sn_sec_sgc_sntlone.api_page_size |
Enter the number of records per page to retrieve.
- Type: string
- Default value: 1000
- Location: System Property [sys_properties] table
|
注: To open the System Properties [sys_properties] table, enter sys_properties.LIST in the navigation filter.