Skip to content

[sentinel_one] Add configuration option to filter results by Site IDs, fix error handling for CEL, improve UI layout, and readme document - #15446

Merged
brijesh-elastic merged 4 commits into
elastic:mainfrom
brijesh-elastic:sentinel_one-1.40.0
Oct 8, 2025
Merged

[sentinel_one] Add configuration option to filter results by Site IDs, fix error handling for CEL, improve UI layout, and readme document#15446
brijesh-elastic merged 4 commits into
elastic:mainfrom
brijesh-elastic:sentinel_one-1.40.0

Conversation

@brijesh-elastic

@brijesh-elastic brijesh-elastic commented Sep 24, 2025

Copy link
Copy Markdown
Contributor

Proposed commit message

sentinel_one: Add configuration option to filter results by Site IDs, fix error handling for CEL,
improve UI layout, and readme document

Add a configuration option to filter results by Site IDs for the application data stream.
Fix error handling for CEL code in the application risk data stream. Update the
configuration parameter descriptions and the README document.

Note

To Reviewers:

  • The URL configuration parameter type was text previously; with this enhancement, it has been updated to the url type. I have tested the upgrade process, and the parameter's value is preserved correctly.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  • Clone integrations repo.
  • Install elastic package locally.
  • Start elastic stack using elastic-package.
  • Move to integrations/packages/sentinel_one directory.
  • Run the following command to run tests.

elastic-package test -v

Related Issue

…tion data stream, improve UI layout, and readme document
@brijesh-elastic brijesh-elastic self-assigned this Sep 24, 2025
@brijesh-elastic
brijesh-elastic requested a review from a team as a code owner September 24, 2025 06:23
@brijesh-elastic brijesh-elastic added documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:sentinel_one SentinelOne bugfix Pull request that fixes a bug issue Category: Integration quality Category: Quality used for SI planning Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] labels Sep 24, 2025
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@brijesh-elastic
brijesh-elastic marked this pull request as draft September 24, 2025 06:24
@brijesh-elastic
brijesh-elastic marked this pull request as ready for review September 25, 2025 07:31

@chemamartinez chemamartinez left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @brijesh-elastic

@brijesh-elastic
brijesh-elastic merged commit c1f8d2e into elastic:main Oct 8, 2025
8 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package sentinel_one - 1.41.0 containing this change is available at https://epr.elastic.co/package/sentinel_one/1.41.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Category: Integration quality Category: Quality used for SI planning documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:sentinel_one SentinelOne Team:SDE-Crest Crest developers on the Security Integrations team [elastic/sit-crest-contractors] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants