Hello,
I'm looking for best practices/tips on crafting SentinelOne EDR Cloud Funnel queries / field selection for exporting to SecOps.
We're perhaps not surprisingly running into issues due to the huge amounts of data being generated by SentinelOne and are looking for ways to slash the data without losing detection capability.
Thus far we've reduced the number of fields to only include those mapped by the SecOps UDM parser and we're investigating if we can make do with only the "Behavioral Indicator" type of events.
I would greatly appreciate if anyone here with hands-on experience of using SentinelOne CloudFunnel could share some of their experiences and advice!
