It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda RMM
formerly Managed Workplace

Using the Default SentinelOne Monitoring Policies

  • Last updated on

A default SentinelOne monitoring policy, named SentinelOne Antivirus, is provided for you, and is installed automatically by default. This monitoring policy is auto-applied to Windows devices with the SentinelOne agent applied through Barracuda RMM and the following SentinelOne alert configurations:

  • SentinelOne Disabled
  • SentinelOne Threat Detected
While Avast Antivirus and Microsoft Defender Antivirus have their own policy formats, SentinelOne does not. SentinelOne policies are monitoring policies with auto-application rules and SentinelOne agent monitors that ensure they apply to devices with the SentinelOne agent.

Only devices with the SentinelOne agent installed through Barracuda RMM can be monitored with a monitoring policy. Devices with an agent that was not installed through Barracuda RMM cannot be monitored with a monitoring policy. The Antivirus > SentinelOne page will not display alarms for them.

To use SentinelOne, you must purchase your SentinelOne license from Barracuda Networks. Contact your Barracuda Networks sales representative.

Using the Default SentinelOne Monitoring Policies

Only devices with the SentinelOne agent installed through Barracuda RMM can be monitored with a monitoring policy. Devices with an agent that was not installed through Barracuda RMM cannot be monitored with a monitoring policy. The Antivirus > SentinelOne page will not display alarms for them.

To use SentinelOne, you must purchase your SentinelOne license from Barracuda Networks. Contact your Barracuda Networks sales representative.
While Avast Antivirus and Microsoft Defender Antivirus have their own policy formats, SentinelOne does not. SentinelOne policies are monitoring policies with auto-application rules and SentinelOne agent monitors that ensure they apply to devices with the SentinelOne agent.

Two default SentinelOne monitoring policies have been provided for you, and are installed automatically by default.

The policies are:

  • Barracuda-Deployed SentinelOne (macOS and Windows Alerting)
  • SentinelOne Antivirus
Barracuda-Deployed SentinelOne (macOS and Windows Alerting)

This monitoring policy applies to both Windows and macOS devices with the SentinelOne agent applied through Barracuda RMM. It can only be used by partners on the North American and European portals. Partners who use a third-party portal can’t use this monitoring policy. This monitoring policy contains the following SentinelOne alert configurations:

  • SentinelOne Agent Disabled - This rule supports self-heal.
  • SentinelOne Threat Detected - This rule doesn’t support self-heal.

 

Notes
  • This monitoring policy can’t be added to devices directly, only to services. By default, this monitoring policy is included in the Baseline Monitoring and Enhanced Monitoring services. To add this policy to a different service, see To add policies to a a service in Modifying Services.
  • If both default policies are applied, duplicate alerts will be received for Windows devices.
SentinelOne Antivirus

This monitoring policy is auto-applied to Windows devices with the SentinelOne agent applied and the following SentinelOne alert configurations:

    • SentinelOne Agent Disabled - This rule supports self-heal.
    • SentinelOne Threat Detected - This rule doesn’t support self-heal.
This monitoring policy doesn’t alert on macOS devices.
Applying a Default SentinelOne Monitoring Policy

If you want to apply a SentinelOne Antivirus monitoring policy to a group or device directly, see Applying a Monitoring Policy to a Group or Device.

Re-installing the Default SentinelOne Monitoring Policy

The default SentinelOne monitoring policy is installed automatically, but if it is deleted, you can reinstall it using the following procedure.

To install the default SentinelOne monitoring policy
  1. In Service Center, click Service Delivery > Policies > Monitoring.
  2. Click Get More.
    Update Center opens, with the list filtered to display the monitoring policies available for installation.
  3. Select the check box beside SentinelOne Antivirus monitoring policy.
  4. Click Install.