NetBird EDR SentinelOne Integrations API
Manage SentinelOne EDR integrations.
Manage SentinelOne EDR integrations.
openapi: 3.1.0
info:
title: NetBird REST Accounts EDR SentinelOne Integrations API
description: API to manipulate groups, rules, policies and retrieve information about peers and users
version: 0.0.1
servers:
- url: https://api.netbird.io
description: Default server
security:
- BearerAuth: []
- TokenAuth: []
tags:
- name: EDR SentinelOne Integrations
description: Manage SentinelOne EDR integrations.
x-cloud-only: true
paths:
/api/integrations/edr/sentinelone:
post:
tags:
- EDR SentinelOne Integrations
summary: Create EDR SentinelOne Integration
description: Creates a new EDR SentinelOne integration
operationId: createSentinelOneEDRIntegration
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/EDRSentinelOneRequest'
responses:
'200':
description: Integration created successfully. Returns the created integration.
content:
application/json:
schema:
$ref: '#/components/schemas/EDRSentinelOneResponse'
'400':
description: Bad Request (e.g., invalid JSON, missing required fields, validation error).
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'401':
description: Unauthorized (e.g., missing or invalid authentication token).
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'500':
description: Internal Server Error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
get:
tags:
- EDR SentinelOne Integrations
summary: Get EDR SentinelOne Integration
description: Retrieves a specific EDR SentinelOne integration by its ID.
responses:
'200':
description: Successfully retrieved the integration details.
content:
application/json:
schema:
$ref: '#/components/schemas/EDRSentinelOneResponse'
'400':
description: Bad Request (e.g., invalid integration ID format).
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'401':
description: Unauthorized.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'404':
description: Not Found (e.g., integration with the given ID does not exist).
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'500':
description: Internal Server Error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
put:
tags:
- EDR SentinelOne Integrations
summary: Update EDR SentinelOne Integration
description: Updates an existing EDR SentinelOne Integration.
operationId: updateSentinelOneEDRIntegration
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/EDRSentinelOneRequest'
responses:
'200':
description: Integration updated successfully. Returns the updated integration.
content:
application/json:
schema:
$ref: '#/components/schemas/EDRSentinelOneResponse'
'400':
description: Bad Request (e.g., invalid JSON, validation error, invalid ID).
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'401':
description: Unauthorized.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'404':
description: Not Found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'500':
description: Internal Server Error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
delete:
tags:
- EDR SentinelOne Integrations
summary: Delete EDR SentinelOne Integration
description: Deletes an EDR SentinelOne Integration by its ID.
responses:
'200':
description: Integration deleted successfully. Returns an empty object.
content:
application/json:
schema:
type: object
example: {}
'400':
description: Bad Request (e.g., invalid integration ID format).
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'401':
description: Unauthorized.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'404':
description: Not Found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
'500':
description: Internal Server Error.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse'
components:
schemas:
Group:
allOf:
- $ref: '#/components/schemas/GroupMinimum'
- type: object
properties:
peers:
description: List of peers object
type: array
items:
$ref: '#/components/schemas/PeerMinimum'
resources:
type: array
items:
$ref: '#/components/schemas/Resource'
required:
- peers
- resources
NetworkResourceType:
description: Network resource type based of the address
type: string
enum:
- host
- subnet
- domain
example: host
Resource:
type: object
properties:
id:
description: ID of the resource
type: string
example: chacdk86lnnboviihd7g
type:
description: Type of the resource
$ref: '#/components/schemas/ResourceType'
required:
- id
- type
EDRSentinelOneRequest:
type: object
description: Request payload for creating or updating a EDR SentinelOne integration
properties:
api_token:
type: string
description: SentinelOne API token
api_url:
type: string
description: The Base URL of SentinelOne API
groups:
type: array
description: The Groups this integrations applies to
items:
type: string
last_synced_interval:
type: integer
description: The devices last sync requirement interval in hours. Minimum value is 24 hours.
minimum: 24
enabled:
type: boolean
description: Indicates whether the integration is enabled
default: true
match_attributes:
$ref: '#/components/schemas/SentinelOneMatchAttributes'
required:
- api_token
- api_url
- groups
- last_synced_interval
- match_attributes
ResourceType:
allOf:
- $ref: '#/components/schemas/NetworkResourceType'
- type: string
enum:
- peer
example: peer
PeerMinimum:
type: object
properties:
id:
description: Peer ID
type: string
example: chacbco6lnnbn6cg5s90
name:
description: Peer's hostname
type: string
example: stage-host-1
required:
- id
- name
GroupMinimum:
type: object
properties:
id:
description: Group ID
type: string
example: ch8i4ug6lnn4g9hqv7m0
name:
description: Group Name identifier
type: string
example: devs
peers_count:
description: Count of peers associated to the group
type: integer
example: 2
resources_count:
description: Count of resources associated to the group
type: integer
example: 5
issued:
description: How the group was issued (api, integration, jwt)
type: string
enum:
- api
- integration
- jwt
example: api
required:
- id
- name
- peers_count
- resources_count
ErrorResponse:
type: object
description: 'Standard error response. Note: The exact structure of this error response is inferred from `util.WriteErrorResponse` and `util.WriteError` usage in the provided Go code, as a specific Go struct for errors was not provided.'
properties:
message:
type: string
description: A human-readable error message.
example: couldn't parse JSON request
SentinelOneMatchAttributes:
type: object
description: Attribute conditions to match when approving agents
additionalProperties: false
properties:
active_threats:
description: The maximum allowed number of active threats on the agent
type: integer
example: 0
encrypted_applications:
description: Whether disk encryption is enabled on the agent
type: boolean
firewall_enabled:
description: Whether the agent firewall is enabled
type: boolean
infected:
description: Whether the agent is currently flagged as infected
type: boolean
is_active:
description: Whether the agent has been recently active and reporting
type: boolean
is_up_to_date:
description: Whether the agent is running the latest available version
type: boolean
network_status:
description: The current network connectivity status of the device
type: string
enum:
- connected
- disconnected
- quarantined
operational_state:
description: The current operational state of the agent
type: string
EDRSentinelOneResponse:
type: object
description: Represents a SentinelOne EDR integration configuration
required:
- id
- account_id
- created_by
- last_synced_at
- created_at
- updated_at
- api_url
- groups
- last_synced_interval
- match_attributes
- enabled
properties:
id:
type: integer
format: int64
description: The unique numeric identifier for the integration.
example: 123
account_id:
type: string
description: The identifier of the account this integration belongs to.
example: ch8i4ug6lnn4g9hqv7l0
last_synced_at:
type: string
format: date-time
description: Timestamp of when the integration was last synced.
example: '2023-05-15T10:30:00Z'
created_by:
type: string
description: The user id that created the integration
created_at:
type: string
format: date-time
description: Timestamp of when the integration was created.
example: '2023-05-15T10:30:00Z'
updated_at:
type: string
format: date-time
description: Timestamp of when the integration was last updated.
example: '2023-05-16T11:45:00Z'
api_url:
type: string
description: The Base URL of SentinelOne API
groups:
type: array
description: List of groups
items:
$ref: '#/components/schemas/Group'
last_synced_interval:
type: integer
description: The devices last sync requirement interval in hours.
match_attributes:
$ref: '#/components/schemas/SentinelOneMatchAttributes'
enabled:
type: boolean
description: Indicates whether the integration is enabled
securitySchemes:
BearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
TokenAuth:
type: apiKey
in: header
name: Authorization
description: Enter the token with the `Token` prefix, e.g. "Token nbp_F3f0d.....".