Hi,
looking through some of the new Native Dashboards and noticing that the EDR-related ones define the SENTINEL_EDR parser made me question if we are using the wrong parser for one SentinelOne EDR -> SecOps SIEM integration.
Looking through the documentation I see four different parsers/feeds for SentinelOne:

The way I understand it SENTINEL_DV is a legacy parser and SENTINELONE_ALERTS is a simple feed with alerts with incidents from within SentinelOne.
Then things become a bit more unclear.
What's the difference between SENTINEL_EDR and SENTINELONE_CF, provided we only use SentinelOne for EDR?
Currently we have SecOps ingestion setup with SENTINELONE_ALERTS and SENTINELONE_CF, but since some SecOps out of the box features such as those Native Dashboards and maybe also some Curated Detections specify the SENTINEL_EDR parser, is this the preferred parser?
This thread was inspired by a similar thread on CrowdStrike parsers.
