Rule Synopsis
These are the rule/s that control whether a user defined value is prepended to the default Correlation ID value on each CMDB CI record.
Rule Details and Default
-
CI Sync’s default format of the Correlation ID value of SentinelOne CIs is the Device ID value within SentinelOne.
-
By default, CI Sync does not prepend any user defined prefix value to the Correlation ID value.
Override Options
Context
Customers may consider overriding the default rule to set a different Correlation ID prefix value to meet their specific ServiceNow requirements.
The use of the Correlation ID prefix value can be important when multiple separate SentinelOne environments (e.g. accounts or other similar delineations within an organisation) are being synced to a single destination ServiceNow CMDB. Customers may want to use a unique Correlation ID prefix for each individual SentinelOne environment.
Options
-
The rule can be amended so that CI Sync does prepend a user defined static value as the prefix to the Correlation ID.
Overriding via Connection Settings
Customers can perform the override using a “Connection Setting” via the CI Sync User Interface (i.e. customers can perform the overrides themselves). Additional information for this is available via the following documentation:
-
For a general overview of CI Sync Connection Settings please read Understanding the use of CI Sync Connection Settings.
-
For the specific CI Sync Connection Setting/s related to the rule described on this page please read Correlation Fields for SentinelOne.
For documentation on all CI Sync Connection Settings please visit the page tree Connection Setting Guides.
Additional Information
-
A separate/individual prefix value can be used on each CI Sync source system connection therefore creating uniqueness of the Correlation ID across multiple SentinelOne instances.
Related Rules