Showing results for 
Show  only  | Search instead for 
Did you mean: 
Level 7
Report Inappropriate Content
Message 1 of 2

SentinelOne parser for ESM


Is there anyone has expiriance with adding SentinelOne XDR to the ESM like Data source.

If you have i would be grateful to share your experience with me.

And excample parser for this device 🙂

1 Reply
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: SentinelOne parser for ESM

Dear, SentinelOne is not a supported data source as per the supported data source guide available at below link:


Since, it is not supported, there will not be any parsers related to it on SIEM. If you can create parsers on your own, you might be able to integrate it by selecting Data Source Vendor as 'Generic' and Data Source Model as 'Advanced Syslog Parser'. If you are unable to create parsers on your own, can reach out to McAfee Professional Services.

More information at


Also, you can submit an Enhancement Request for this:

How to submit a new Product Idea (Product Enhancement Request):

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community