> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/cloud-log-forwarding/sentinelone.md).

# SentinelOne

You will need an API Token from a Service User that has the Viewer role in your SentinelOne account. If you already have an API Token from a Service User, skip this step.

Log in to your SentinelOne Dashboard.

In the left sidebar menu, click Settings.

At the top of the Settings page, click the Users tab.&#x20;

<figure><img src="https://2078222076-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MMRHZBPHlLDUc8519fX%2Fuploads%2FIFpUEO9N2wpN8Bp0opHg%2Fimage.png?alt=media&amp;token=6e6b3ec8-ff31-4640-a964-dbac1d0ff2ca" alt=""><figcaption></figcaption></figure>

On the left side of the Users page, click Service Users.&#x20;

Click the Actions dropdown, then click Create New Service User.&#x20;

<figure><img src="https://2078222076-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MMRHZBPHlLDUc8519fX%2Fuploads%2FSZ0zlGPQypf8rTkSJN9E%2Fimage.png?alt=media&amp;token=e518b280-c473-43be-a765-6dc5f991d611" alt=""><figcaption></figcaption></figure>

On the "Create New Service User" page, enter a name and a description, choose an expiration date, then click Next.

On the "Select Scope of Access" page, configure the following:

1. Access Level: Account
2. Account selected: Ensure you have selected the correct account and that the role is set to Viewer.&#x20;

<figure><img src="https://2078222076-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MMRHZBPHlLDUc8519fX%2Fuploads%2Fqeotr6YahnIU58RsKr8M%2Fimage.png?alt=media&amp;token=36832b41-98a8-4759-aad1-b2246f887417" alt=""><figcaption></figcaption></figure>

Click Create User.

Copy the API Token and store it in a secure location.

Please share the API token with our implementation team.
