Currently when users configure Sentinel One integration, 2 options are presented to the users:
- Collect SentinelOne logs via API (CEL)
- 2 data streams supported by CEL input:
application and application_risk (More to be added here).
- Collect SentinelOne logs via API (HTTP JSON)
- 5 data streams supported by HTTPJSON input:
activity, agent, alert, group, and threat.
While the options are intuitive to some users who are aware of CEL and HTTPJSON inputs, users who do not know about them or the reason why both exist, will face significant challenge to choose the right option. Also the current options do not mention CEL and HTTPJSON as input which makes it harder even for users who are familiar with beats ecosystem to understand.
Hence this layout could be modified to improve the user experience.
Some ideas for improvement:
-
Update title to use the word input. This makes it slightly clear for users familiar with beats. However uncertainty could still exist.
-
Change the input title to add data stream names and removed the words CEL and HTTPJSON.
Currently when users configure Sentinel One integration, 2 options are presented to the users:
applicationandapplication_risk(More to be added here).activity,agent,alert,group, andthreat.While the options are intuitive to some users who are aware of CEL and HTTPJSON inputs, users who do not know about them or the reason why both exist, will face significant challenge to choose the right option. Also the current options do not mention CEL and HTTPJSON as
inputwhich makes it harder even for users who are familiar with beats ecosystem to understand.Hence this layout could be modified to improve the user experience.
Some ideas for improvement:
Update title to use the word
input. This makes it slightly clear for users familiar with beats. However uncertainty could still exist.Change the input title to add data stream names and removed the words
CELandHTTPJSON.