Deduplicate Assets by Serial Number for SentinelOne

Connector Applicability

Applies to Source Connectors

SentinelOne

Applies to Destination Connectors

All

Assumptions

These instructions assume you have already setup a source connection in CI Sync for SentinelOne using the CI Sync instructions here: Add SentinelOne to SaaS Agent

Pre-Read

Syncfish recommend customers read the following documentation before changing the Connection Setting/s described below.

  1. Understanding the use of CI Sync Connection Settings

  2. Rule 16 - Handling of Likely Duplicate Assets for SentinelOne

Locating and Amending the Connection Setting in the CI Sync UI

  1. Navigate to the Settings page

  2. Under the Source Connections heading (list), locate your SentinelOne connection.

  3. Click the Update link on the right hand side of the SentinelOne connection.

  4. Scroll down and locate the Section Heading and view the Individual Settings.

SO deduplication.jpg

The screen shot is provided only as sample to assist when reading this page. The state of your own CI Sync UI will depend on whether you are starting from the CI Sync default position or if you have already amended one/more of the settings.

  1. Tick the Override default box/boxes and then use the sliders related to the individual settings. The following table elaborates any further information about these particular settings.

Setting

Type

Additional Notes

Deduplicate Assets - by Serial Number

Slider

When enabled (the default), CI Sync will not synchronize each individual SentinelOne asset record as a separate CI, providing the individual asset records have the same serial number value. Instead, CI Sync will only synchronize the latest seen version of an asset by Serial Number - any links or mappings to the previous asset will be released, allowing the newest asset to map to the existing CI in ServiceNow.

  1. After modifying the settings, scroll to the bottom of the page, tick the “I consent…” checkbox and finally click the Save connection button.

  2. You can now run a sync job and the amended settings will be applied causing the CI Sync Data Sync rules to be modified accordingly.

Importantly

Make sure you consciously override the setting against either your TEST or PROD environment (i.e. your TEST vs PROD sync jobs).

For more information on how to use TEST vs PROD Connection Settings please read Understanding the use of CI Sync Connection Settings.

Syncfish strongly recommend making changes for TEST environment/sync jobs first. Only modify PROD related settings after thoroughly validating the intended results in TEST.