Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

CMDB classes targeted in the Service Graph Connector for SentinelOne

When you complete setting up the connection, you can configure the integration to periodically pull data. The data is saved in tables that extend from the Configuration item [cmdb_ci] table.

AWS Datacenter [cmdb_ci_aws_datacenter]

The following attributes in the AWS Datacenter [cmdb_ci_aws_datacenter] table are populated by collected data.

Attribute labelAttribute name
Object Idobject_id
Regionregion
Namename
Parent ClassRelationship TypeChild Class
AWS Datacenter [cmdb_ci_aws_datacenter]Hosted On: HostsCloud Service Account [cmdb_ci_cloud_service_account]

Azure Datacenter [cmdb_ci_azure_datacenter]

The following attributes in the Azure Datacenter [cmdb_ci_azure_datacenter] table are populated by collected data.

Attribute labelAttribute name
Object Idregion
Namename
Regionregion
Parent ClassRelationship TypeChild Class
Azure Datacenter [cmdb_ci_azure_datacenter]Hosted On: HostsCloud Service Account [cmdb_ci_cloud_service_account]

Availability Zone [cmdb_ci_availability_zone]

The following attributes in the Availability Zone [cmdb_ci_availability_zone] table are populated by collected data.

Parent ClassRelationship TypeChild Class
Azure Datacenter [cmdb_ci_azure_datacenter]Contains:Contained byAvailability Zone [cmdb_ci_availability_zone]
Attribute labelAttribute name
Namename
Object Idobject_id
Regionregion

GCP Datacenter [cmdb_ci_google_datacenter]

The following attributes in the GCP Datacenter [cmdb_ci_google_datacenter] table are populated by collected data.

Attribute labelAttribute name
Namename
Object Idobject_id
Account Idaccount_id
Datacenter Typedatacenter_type
Parent ClassRelationship TypeChild Class
GCP Datacenter [cmdb_ci_google_datacenter]Hosted On: HostsCloud Service Account [cmdb_ci_cloud_service_account]

Cloud Service Account [cmdb_ci_cloud_service_account]

The following attributes in the Cloud Service Account [cmdb_ci_cloud_service_account] table are populated by collected data.

Attribute labelAttribute name
Namename
Object Idobject_Id
Account Idaccount_Id
Datacenter Typedatacenter_type
Parent ClassRelationship TypeChild Class
Network [cmdb_ci_network]Hosted On: HostsCloud Service Account [cmdb_ci_cloud_service_account]

Cloud Subnets [cmdb_ci_cloud_subnet]

The following attributes in the Cloud Subnets [cmdb_ci_cloud_subnet] table are populated by collected data.

Attribute labelAttribute name
Object Idobject_id
Namename
Parent ClassRelationship TypeChild Class
Network [cmdb_ci_network]Contains:Contained byCloud Subnets [cmdb_ci_cloud_subnet]

Hardware Type [cmdb_ci_compute_template]

The following attributes in the Hardware Type [cmdb_ci_compute_template] table are populated by collected data.

Attribute labelAttribute name
Namename
Object Idobject_id
Parent ClassRelationship TypeChild Class
Compute Template [cmdb_ci_compute_template]Hosted On: HostsCloud Service Account [cmdb_ci_cloud_service_account]
VM Instance [cmdb_ci_vm_instance]Provisioned From::ProvisionedCompute Template [cmdb_ci_compute_template]

Cloud Network [cmdb_ci_network]

The following attributes in the Cloud Network [cmdb_ci_network] table are populated by collected data.

Attribute labelAtribute name
Object Idobject_id
Namename
Parent ClassRelationship TypeChild Class
Network [cmdb_ci_network]Hosted on::HostsCloud Service Account [cmdb_ci_cloud_service_account]

Virtual Machine Instance [cmdb_ci_vm_instance]

The following attributes in the Virtual Machine Instance [cmdb_ci_vm_instance] table are populated by collected data.

Attribute labelAttribute name
Object Idobject_id
Namename
VM Instance IDvm_inst_id
Parent ClassRelationship TypeChild Class
VM Instance [cmdb_ci_vm_instance]Hosted On: HostsAWS Datacenter [cmdb_ci_aws_datacenter]
VM Instance [cmdb_ci_vm_instance]Virtualized by::VirtualizesServer [cmdb_ci_server]
VM Instance [cmdb_ci_vm_instance]Hosted On: HostsAWS Datacenter [cmdb_ci_aws_datacenter]

Key Value [cmdb_key_value]

The following attributes in the Key Value [cmdb_key_value] table are populated by collected data.

Attribute labelAttribute name
Keykey
Valuevalue
Tagtag

Image [cmdb_ci_os_template]

The following attributes in the Image [cmdb_ci_os_template] table are populated by collected data.

Attribute labelAttribute name
Object Idobject_id
Namename
Parent ClassRelationship TypeChild Class
Image [cmdb_ci_os_template]Hosted on::HostsCloud Service Account [cmdb_ci_cloud_service_account]

Server [cmdb_ci_server]

The following attributes in the Server [cmdb_ci_server] table are populated by collected data.

Attribute labelAttribute name
Namename
Serial numberserial_number
CPU speed (MHz)cpu_speed
CPU countcpu_count
RAM (MB)ram
OS Address Width (bits)os_address_width
Operating Systemos
CPU core countcpu_core_count
Fully qualified domain namefqdn
CPU namecpu_name
First Discoveredfirst_discovered

Computer [cmdb_ci_computer]

The following attributes in the Computer [cmdb_ci_computer] table are populated by collected data.

Attribute labelAttribute name
Namename
Serial numberserial_number
CPU speed (MHz)cpu_speed
CPU countcpu_count
RAM (MB)ram
OS Address Width (bits)os_address_width
Operating Systemos
CPU core countcpu_core_count
Fully qualified domain namefqdn
CPU namecpu_name
First Discoveredfirst_discovered

SentinelOne Asset Tags [sn_sec_sgc_sntlone_asset_tags]

The following attributes in the SentinelOne Asset Tags [sn_sec_sgc_sntlone_asset_tags] table are populated by collected data.

Attribute labelAttribute name
IDtags_id
Keytags_key
Valuetags_value
Assigned Attags_assignedat
Assigned Bytags_assignedby
Assigned By IDassigned_by_id

IP Address [cmdb_ci_ip_address]

The following attributes in the IP Address [cmdb_ci_ip_address] table are populated by collected data.

Attribute labelAttribute name
IP Addressip_address
Namename
Nicnic
IP versionip_version
Parent ClassRelationship TypeChild Class
Server [cmdb_ci_server]Owns:Owned byIP Address [cmdb_ci_ip_address]

Network Adapter [cmdb_ci_network_adapter]

The following attributes in the Network Adapter [cmdb_ci_network_adapter] table are populated by collected data.

Attribute labelAttribute name
Mac Addressmac_address
Namename
Ip Default Gatewayip_default_gateway
Discovery Sourcediscovery_source
Parent ClassRelationship TypeChild Class
Server [cmdb_ci_server]Owns:Owned byNetwork Adapter [cmdb_ci_network_adapter]

SentinelOne Additional Attributes [sn_sec_sgc_sntlone_additonal_attributes]

The following attributes in the SentinelOne Additional Attributes [sn_sec_sgc_sntlone_additonal_attributes] table are populated by collected data.

Attribute labelAttribute name
NetworkInterfaces Namenetworkinterfaces\_name
NetworkInterfaces GatewayMacAddressnetworkinterfaces\_gatewaymacaddress
UUIDuuid
Configuration itemconfiguration\_item
Network Quarantine Enablednetwork\_quarantine\_enabled
Last Successful Scan Datelast\_successful\_scan\_date
License\_Keylicense\_key
First Discoveredfirst\_discovered
Location Enabledlocation\_enabled
Ad ComputerDistinguishedNamead\_computerdistinguishedname
Agent Versionagent\_version
Scan Statusscan\_status
Scan Started Atscan\_started\_at
IDid
IP Address Subnetip\_address\_subnet
Mitigation Mode Suspiciousmitigation\_mode\_suspicious
Last Scan Finished Atlast\_scan\_finished\_at
Firewall Enabledfirewall\_enabled
Console Migration Statusconsole\_migration\_status
Group IDgroup\_id
Operational State Expirationoperational\_state\_expiration
Last IP To Mgmtlast\_ip\_to\_mgmt
Threat Reboot Requiredthreat\_reboot\_required
Machine Typemachine\_type
Is Pending Uninstall Ranger StatusIs\_pending\_uninstall ranger\_status
Ad LastUserDistinguishedNamead\_lastuserdistinguishedname
Agent Up To Dateagent\_up\_to\_date
Ranger Versionranger\_version
Last Boot Timelast\_boot\_time
Disk Encryption Statusdisk\_encryption\_status
Mitigation Modemitigation\_mode
Last Full Scanlast\_full\_scan
Agent Uninstalledagent\_uninstalled
Extenal Idextenal\_id
Updated Atupdated\_at
Last Scan Aborted Atlast\_scan\_aborted\_at
Network Statusnetwork\_status
Show Alert Iconshow\_alert\_icon
Subscribed Onsubscribed\_on
Account IDaccount\_id
Recently Activerecently\_active
Active Threatsactive\_threats
Allow Remote Shellallow\_remote\_shell
Site Namesite\_name
First Full Mode Timefirst\_full\_mode\_time
Infectedinfected
App Vulnerability Statusapp\_vulnerability\_status
Site IDsite\_id
Agent Installer Typeagent\_installer\_type
Account Nameacount\_name
NetworkInterfaces Namenetworkinterfaces\_name
NetworkInterfaces GatewayMacAddressnetworkinterfaces\_gatewaymacaddress
NetworkInterfaces IDnetworkinterfaces\_id
user\_actions\_neededuser\_actions\_needed
aws\_security\_groupaws\_security\_group
proxyState\_consoleproxyState\_console
proxyState\_deepVisibilityproxyState\_deepVisibility
Ad UserPrincipalNamead\_userPrincipalName
Ad ComputerMemberOfad\_computerMemberOf
Ad ComputerDistinguishedNamead\_computerDistinguishedName
Ad LastUserMemberOfad\_lastUserMemberOf
Ad LastUserDistinguishedNamead\_lastUserDistinguishedName
Ad Mailad\_mail
Agent Decommissionedagent\_decommissioned
Agent Operational Stateagent\_operational\_state
Last Active Datelast\_active\_date
Group Updated Atgroup\_updated\_at
Missing Permissionsmissing\_permissions

Service Graph Connector for SentinelOne Properties

PropertyDescription
sn\_sec\_sgc\_sntlone.api\_page\_sizeEnter the number of records per page to retrieve.- Type: string - Default value: 1000 - Location: System Property \[sys\_properties\] table

Note: To open the System Properties [sys_properties] table, enter sys_properties.LIST in the navigation filter.