SentinelOne

Download 41
Last updated May 8, 2026

sentinelone-activities

Enuemrate activities in the SentinelOne service.

sentinelone-activities [profile=PROFILE] [duration=DURATION] [from=FROM] [to=TO] [order=ORDER]
profile=PROFILE
Connect profile code of SentinelOne
duration=DURATION
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=FROM
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=TO
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
order=ORDER
asc or desc.

Output Fields

FieldTypeNameDescription
_timeDateTimeCreated time.
profileStringConnect profileSentinelOne connect profile code
site_nameStringSite namee.g. Default site
group_nameStringGroup namee.g. Linux Server, MacOS, Windows PC
agent_idStringAgent IDe.g. 1234567890123456789
hostnameStringHostnamee.g. logpresso's MacBook Pro
host_ipIPHost IPIP address of the host where the activity occurred.
activity_typeIntegerActivity typee.g. 3631, 4020
event_categoryStringEvent categorye.g. process, registry, indicators, command_script
threat_classificationStringThreat classificatione.g. Malware, Ransomware, PUA, Infostealer, Cryptominer
primary_descriptionStringPrimary descriptione.g. Live Updates for Static AI, StaticSigMac251-9.3, were sent to endpoint
secondary_descriptionStringSecondary descriptione.g. IP address: x.x.x.x
account_nameStringAccount namee.g. Logpresso
createdDateCreatedTime the record was created.
updatedDateUpdatedTime the record was updated.
paramsMAPParametersElements with account_name, site_name, scope_level, group_name, hostname, asset_type, source_type, etc.
idStringActivity IDSequence number of activities.
activity_uuidStringActivity UUID36 characters in GUID format.
account_idStringAccount IDe.g. 1234567890123456789
site_idStringSite IDe.g. 1234567890123456789
group_idStringGroup IDe.g. 1234567890123456789
user_idStringUser IDe.g. 1234567890123456789
threat_idStringThreat IDe.g. 1234567890123456789