SentinelOne › Service Graph Connectors › Integrating third-party data into CMDB › Configuration Management › Extend ServiceNow AI Platform capabilities
CMDB classes targeted in the Service Graph Connector for SentinelOne
When you complete setting up the connection, you can configure the integration to periodically pull data. The data is saved in tables that extend from the Configuration item [cmdb_ci] table.
AWS Datacenter [cmdb_ci_aws_datacenter]
The following attributes in the AWS Datacenter [cmdb_ci_aws_datacenter] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Object Id | object_id |
| Region | region |
| Name | name |
| Parent Class | Relationship Type | Child Class |
|---|
| AWS Datacenter [cmdb_ci_aws_datacenter] | Hosted On: Hosts | Cloud Service Account [cmdb_ci_cloud_service_account] |
Azure Datacenter [cmdb_ci_azure_datacenter]
The following attributes in the Azure Datacenter [cmdb_ci_azure_datacenter] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Object Id | region |
| Name | name |
| Region | region |
| Parent Class | Relationship Type | Child Class |
|---|
| Azure Datacenter [cmdb_ci_azure_datacenter] | Hosted On: Hosts | Cloud Service Account [cmdb_ci_cloud_service_account] |
Availability Zone [cmdb_ci_availability_zone]
The following attributes in the Availability Zone [cmdb_ci_availability_zone] table are populated by collected data.
| Parent Class | Relationship Type | Child Class |
|---|
| Azure Datacenter [cmdb_ci_azure_datacenter] | Contains:Contained by | Availability Zone [cmdb_ci_availability_zone] |
| Attribute label | Attribute name |
|---|
| Name | name |
| Object Id | object_id |
| Region | region |
GCP Datacenter [cmdb_ci_google_datacenter]
The following attributes in the GCP Datacenter [cmdb_ci_google_datacenter] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Name | name |
| Object Id | object_id |
| Account Id | account_id |
| Datacenter Type | datacenter_type |
| Parent Class | Relationship Type | Child Class |
|---|
| GCP Datacenter [cmdb_ci_google_datacenter] | Hosted On: Hosts | Cloud Service Account [cmdb_ci_cloud_service_account] |
Cloud Service Account [cmdb_ci_cloud_service_account]
The following attributes in the Cloud Service Account [cmdb_ci_cloud_service_account] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Name | name |
| Object Id | object_Id |
| Account Id | account_Id |
| Datacenter Type | datacenter_type |
| Parent Class | Relationship Type | Child Class |
|---|
| Network [cmdb_ci_network] | Hosted On: Hosts | Cloud Service Account [cmdb_ci_cloud_service_account] |
Cloud Subnets [cmdb_ci_cloud_subnet]
The following attributes in the Cloud Subnets [cmdb_ci_cloud_subnet] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Object Id | object_id |
| Name | name |
| Parent Class | Relationship Type | Child Class |
|---|
| Network [cmdb_ci_network] | Contains:Contained by | Cloud Subnets [cmdb_ci_cloud_subnet] |
Hardware Type [cmdb_ci_compute_template]
The following attributes in the Hardware Type [cmdb_ci_compute_template] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Name | name |
| Object Id | object_id |
| Parent Class | Relationship Type | Child Class |
|---|
| Compute Template [cmdb_ci_compute_template] | Hosted On: Hosts | Cloud Service Account [cmdb_ci_cloud_service_account] |
| VM Instance [cmdb_ci_vm_instance] | Provisioned From::Provisioned | Compute Template [cmdb_ci_compute_template] |
Cloud Network [cmdb_ci_network]
The following attributes in the Cloud Network [cmdb_ci_network] table are populated by collected data.
| Attribute label | Atribute name |
|---|
| Object Id | object_id |
| Name | name |
| Parent Class | Relationship Type | Child Class |
|---|
| Network [cmdb_ci_network] | Hosted on::Hosts | Cloud Service Account [cmdb_ci_cloud_service_account] |
Virtual Machine Instance [cmdb_ci_vm_instance]
The following attributes in the Virtual Machine Instance [cmdb_ci_vm_instance] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Object Id | object_id |
| Name | name |
| VM Instance ID | vm_inst_id |
| Parent Class | Relationship Type | Child Class |
|---|
| VM Instance [cmdb_ci_vm_instance] | Hosted On: Hosts | AWS Datacenter [cmdb_ci_aws_datacenter] |
| VM Instance [cmdb_ci_vm_instance] | Virtualized by::Virtualizes | Server [cmdb_ci_server] |
| VM Instance [cmdb_ci_vm_instance] | Hosted On: Hosts | AWS Datacenter [cmdb_ci_aws_datacenter] |
Key Value [cmdb_key_value]
The following attributes in the Key Value [cmdb_key_value] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Key | key |
| Value | value |
| Tag | tag |
Image [cmdb_ci_os_template]
The following attributes in the Image [cmdb_ci_os_template] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Object Id | object_id |
| Name | name |
| Parent Class | Relationship Type | Child Class |
|---|
| Image [cmdb_ci_os_template] | Hosted on::Hosts | Cloud Service Account [cmdb_ci_cloud_service_account] |
Server [cmdb_ci_server]
The following attributes in the Server [cmdb_ci_server] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Name | name |
| Serial number | serial_number |
| CPU speed (MHz) | cpu_speed |
| CPU count | cpu_count |
| RAM (MB) | ram |
| OS Address Width (bits) | os_address_width |
| Operating System | os |
| CPU core count | cpu_core_count |
| Fully qualified domain name | fqdn |
| CPU name | cpu_name |
| First Discovered | first_discovered |
Computer [cmdb_ci_computer]
The following attributes in the Computer [cmdb_ci_computer] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Name | name |
| Serial number | serial_number |
| CPU speed (MHz) | cpu_speed |
| CPU count | cpu_count |
| RAM (MB) | ram |
| OS Address Width (bits) | os_address_width |
| Operating System | os |
| CPU core count | cpu_core_count |
| Fully qualified domain name | fqdn |
| CPU name | cpu_name |
| First Discovered | first_discovered |
The following attributes in the SentinelOne Asset Tags [sn_sec_sgc_sntlone_asset_tags] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| ID | tags_id |
| Key | tags_key |
| Value | tags_value |
| Assigned At | tags_assignedat |
| Assigned By | tags_assignedby |
| Assigned By ID | assigned_by_id |
IP Address [cmdb_ci_ip_address]
The following attributes in the IP Address [cmdb_ci_ip_address] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| IP Address | ip_address |
| Name | name |
| Nic | nic |
| IP version | ip_version |
| Parent Class | Relationship Type | Child Class |
|---|
| Server [cmdb_ci_server] | Owns:Owned by | IP Address [cmdb_ci_ip_address] |
Network Adapter [cmdb_ci_network_adapter]
The following attributes in the Network Adapter [cmdb_ci_network_adapter] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| Mac Address | mac_address |
| Name | name |
| Ip Default Gateway | ip_default_gateway |
| Discovery Source | discovery_source |
| Parent Class | Relationship Type | Child Class |
|---|
| Server [cmdb_ci_server] | Owns:Owned by | Network Adapter [cmdb_ci_network_adapter] |
SentinelOne Additional Attributes [sn_sec_sgc_sntlone_additonal_attributes]
The following attributes in the SentinelOne Additional Attributes [sn_sec_sgc_sntlone_additonal_attributes] table are populated by collected data.
| Attribute label | Attribute name |
|---|
| NetworkInterfaces Name | networkinterfaces\_name |
| NetworkInterfaces GatewayMacAddress | networkinterfaces\_gatewaymacaddress |
| UUID | uuid |
| Configuration item | configuration\_item |
| Network Quarantine Enabled | network\_quarantine\_enabled |
| Last Successful Scan Date | last\_successful\_scan\_date |
| License\_Key | license\_key |
| First Discovered | first\_discovered |
| Location Enabled | location\_enabled |
| Ad ComputerDistinguishedName | ad\_computerdistinguishedname |
| Agent Version | agent\_version |
| Scan Status | scan\_status |
| Scan Started At | scan\_started\_at |
| ID | id |
| IP Address Subnet | ip\_address\_subnet |
| Mitigation Mode Suspicious | mitigation\_mode\_suspicious |
| Last Scan Finished At | last\_scan\_finished\_at |
| Firewall Enabled | firewall\_enabled |
| Console Migration Status | console\_migration\_status |
| Group ID | group\_id |
| Operational State Expiration | operational\_state\_expiration |
| Last IP To Mgmt | last\_ip\_to\_mgmt |
| Threat Reboot Required | threat\_reboot\_required |
| Machine Type | machine\_type |
| Is Pending Uninstall Ranger Status | Is\_pending\_uninstall ranger\_status |
| Ad LastUserDistinguishedName | ad\_lastuserdistinguishedname |
| Agent Up To Date | agent\_up\_to\_date |
| Ranger Version | ranger\_version |
| Last Boot Time | last\_boot\_time |
| Disk Encryption Status | disk\_encryption\_status |
| Mitigation Mode | mitigation\_mode |
| Last Full Scan | last\_full\_scan |
| Agent Uninstalled | agent\_uninstalled |
| Extenal Id | extenal\_id |
| Updated At | updated\_at |
| Last Scan Aborted At | last\_scan\_aborted\_at |
| Network Status | network\_status |
| Show Alert Icon | show\_alert\_icon |
| Subscribed On | subscribed\_on |
| Account ID | account\_id |
| Recently Active | recently\_active |
| Active Threats | active\_threats |
| Allow Remote Shell | allow\_remote\_shell |
| Site Name | site\_name |
| First Full Mode Time | first\_full\_mode\_time |
| Infected | infected |
| App Vulnerability Status | app\_vulnerability\_status |
| Site ID | site\_id |
| Agent Installer Type | agent\_installer\_type |
| Account Name | acount\_name |
| NetworkInterfaces Name | networkinterfaces\_name |
| NetworkInterfaces GatewayMacAddress | networkinterfaces\_gatewaymacaddress |
| NetworkInterfaces ID | networkinterfaces\_id |
| user\_actions\_needed | user\_actions\_needed |
| aws\_security\_group | aws\_security\_group |
| proxyState\_console | proxyState\_console |
| proxyState\_deepVisibility | proxyState\_deepVisibility |
| Ad UserPrincipalName | ad\_userPrincipalName |
| Ad ComputerMemberOf | ad\_computerMemberOf |
| Ad ComputerDistinguishedName | ad\_computerDistinguishedName |
| Ad LastUserMemberOf | ad\_lastUserMemberOf |
| Ad LastUserDistinguishedName | ad\_lastUserDistinguishedName |
| Ad Mail | ad\_mail |
| Agent Decommissioned | agent\_decommissioned |
| Agent Operational State | agent\_operational\_state |
| Last Active Date | last\_active\_date |
| Group Updated At | group\_updated\_at |
| Missing Permissions | missing\_permissions |
Service Graph Connector for SentinelOne Properties
| Property | Description |
|---|
| sn\_sec\_sgc\_sntlone.api\_page\_size | Enter the number of records per page to retrieve.- Type: string - Default value: 1000 - Location: System Property \[sys\_properties\] table |
Note: To open the System Properties [sys_properties] table, enter sys_properties.LIST in the navigation filter.