How to Generate a Capture Client (SentinelOne) API Key Using a Service User

Description

Overview

This article explains how to SSO to SentinelOne console via SonicWall Unified Management; and create a Service User in the SentinelOne Management Console to generate an API token for that user. A Service User provides an API token that is not tied to an individual's email address, which is the recommended approach for integrations.

Prerequisites

  • Administrator-level access to the Capture Client Management console
  • Knowledge of the required scope (Account or Site) for the integration
  • Knowledge of required access permissions from third-party vendor which needs to be integrated.

Accessing the SentinelOne Console via SonicWall Unified Management

Use the following steps to reach the SentinelOne console before performing the steps in this article.

  1. Log in to SonicWall Unified Management at platform.sonicwall.com using CMC Admin Account
  2. From the top navigation bar, confirm the correct tenant is selected (for example, the account or MSP name shown in the scope selector).
  3. In the left navigation menu, click Capture Client.
  4. In the Capture Client left navigation menu, click SentinelOne.
  5. This opens the SentinelOne Management Console using SSO, where the Service User and API token can be created.

Figure 1: Capture Client Dashboard in SonicWall Unified Management, with SentinelOne visible in the left navigation.

Creating Service user

  1. Once you are into SentinelOne Management Console, check and confirm the Scope from the top.
  2. Navigate to Settings.
  3. Select Users, then click Service Users.
  4. Click the Actions menu and select Create New Service User.

    Figure 2: SentinelOne console – Settings > Users > Service Users, with the Actions menu open showing Create New Service User.
  5. In the Create New Service User dialog, complete the following fields:
    • Name: A descriptive identifier for the integration. Note: the name cannot be edited after creation.
    • Description: Optional context regarding the token's purpose
    • Expiration Date: Select a duration as required (for example, 1 Year).

      Figure 3: Create New Service User dialog – Name, Description, and Expiration Date fields.
  6. Click Next.
  7. In the Select Scope of Access dialog, configure the following:
    • Access Level: Select Global, Account, or Site, depending on the required scope
    • Account/Site: Search for and select the applicable account or site based on your access.
    • Role: Select the minimum role required for the integration (for example, Admin or Viewer).
      Note: Please check with your third-party vendor about requirements of Access.

      Figure 4: Select Scope of Access dialog – Access Level, Site, and Role selection.
  8. Click Create User.
  9. The API Token dialog opens automatically once the Service User is created. Copy the token immediately, as it is displayed only once and cannot be retrieved later; if lost, a new token must be generated.

    Figure 5: API Token dialog. The token value is masked here for security; it is displayed only once in the live console.
  10. Click Close once the token has been copied and stored securely.
  11. Record the Management Console URL, as this is required alongside the API token for integration configuration. Here are the console details:

                Important Notes

                • Tokens inherit the role and scope of the Service User that generated them.
                • Revoking or deleting a Service User invalidates its associated token.
                • Store the token in a secure credential management system.
                • SentinelOne displays a security warning if an expiration duration exceeding 1 month is selected.
                • If your API key expires, you can’t extend the validity and need to create another Service user with new validity as required.

                Related Articles

                • Integrating with 3rd Party Syslog and Threat Detection Platforms
                  Read More
                • Integrating SonicWall Capture Client with SonicWall Firewalls
                  Read More
                • How to use Resource Monitor to see if a Capture Client Interoperability Exclusion is Being Applied
                  Read More
                not finding your answers?