All integrations

SentinelOne

SentinelOne · Identity & security

Available

Connect your SentinelOne console with a service user's API token. Every 15 minutes each new threat raises an alert on the matching Gochi device, so your ticket rules and notifications apply. When the threat is resolved in SentinelOne the Gochi alert resolves, and resolving it in Gochi marks it resolved in SentinelOne too (you can switch that off). Clients are matched to your Gochi companies by name; a client or machine Gochi can't match is listed in the run log, never guessed. A coverage check lists protected machines with no Gochi agent, and Gochi devices that aren't protected.

What moves between Gochi and SentinelOne

  • Threats Into Gochi
  • Threats resolved Both ways
  • Which machines are protected Into Gochi