SentinelOne Alerts

List, search, and retrieve SentinelOne security alert details with GraphQL filters.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill sentinelone-alerts
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: SentinelOne Alerts
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/sentinelone/sentinelone/skills/alerts
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill sentinelone-alerts

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill streamlines the management of security alerts within SentinelOne, enabling efficient triage, investigation, and workflow management across diverse MSP client environments.

Core Features & Use Cases

  • Alert Triage: Quickly review and prioritize new alerts based on severity and status.
  • Detailed Investigation: Access comprehensive alert details, notes, and historical timelines.
  • Advanced Searching: Utilize GraphQL filters for precise alert searching across various domains like cloud, Kubernetes, and identity.
  • Use Case: An MSP security analyst can use this skill to quickly identify and investigate all new critical alerts across all their clients, then drill down into the details of a specific alert to understand the threat context and affected assets.

Quick Start

Use the SentinelOne Alerts skill to list all new critical alerts, sorted by detection time.

Frequently Asked Questions about SentinelOne Alerts

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage SentinelOne security alerts by severity and status?

Filter SentinelOne security alerts by severity and status to quickly review, prioritize, and manage new threats across MSP client environments for effective triage.

Can I search SentinelOne alerts across cloud, Kubernetes, and identity domains?

Yes, advanced GraphQL filters enable precise SentinelOne alert searching across cloud, Kubernetes, and identity domains to pinpoint specific security events.

How do I retrieve detailed threat context and alert history for SentinelOne events?

Retrieve comprehensive SentinelOne alert details, notes, and historical timelines to perform deep dive investigations into threat context and affected assets.

What is the best way to manage security alerts across multiple MSP client environments?

Manage security alerts across MSP client environments by filtering alerts by severity, status, and view type to streamline triage, investigation, and workflow management.

Does this SentinelOne alert triage workflow support filtering by view type?

Yes, SentinelOne alert management supports filtering by view type, enabling analysts to effectively triage, investigate, and manage detected threats across diverse domains.