> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/cloud-log-forwarding/sentinelone.md).

# SentinelOne

You will need an API Token from a Service User that has the Viewer role in your SentinelOne account. If you already have an API Token from a Service User, skip this step.

Log in to your SentinelOne Dashboard.

In the left sidebar menu, click Settings.

At the top of the Settings page, click the Users tab.&#x20;

<figure><img src="/files/4lJY0SYoKyBz7NTtC2ww" alt=""><figcaption></figcaption></figure>

On the left side of the Users page, click Service Users.&#x20;

Click the Actions dropdown, then click Create New Service User.&#x20;

<figure><img src="/files/bCb2TSvSohQXSxlAj7aV" alt=""><figcaption></figcaption></figure>

On the "Create New Service User" page, enter a name and a description, choose an expiration date, then click Next.

On the "Select Scope of Access" page, configure the following:

1. Access Level: Account
2. Account selected: Ensure you have selected the correct account and that the role is set to Viewer.&#x20;

<figure><img src="/files/a5wjgLO7qvaVYq03cJQb" alt=""><figcaption></figcaption></figure>

Click Create User.

Copy the API Token and store it in a secure location.

Please share the API token with our implementation team.
