We're getting grilled by our compliance team (SOC 2, ISO 27001). They want specific logs for "file access attempts blocked by policy" and "all DNS queries from endpoints, including allowed ones."
SentinelOne's story seems full of holes.
* The "Threats" log only shows... threats. It doesn't show policy blocks that weren't deemed malicious.
* Network Activity shows *some* DNS, but it's inconsistent and seems to filter out "normal" queries. Useless for a full audit trail.
* I can't find a raw event log that maps to every policy action taken by the agent.
We're being told to "use the Singularity Data Lake" or "create a custom query," but that's just moving the goalpost. The base product should provide this.
Has anyone actually passed a strict audit with S1 alone? What are you giving the auditors?
Specifically:
* What exact datasets/export schemas are you using?
* Did you have to build a separate SIEM pipeline for this?
* Are they just accepting the "Risk Index" and "Deep Visibility" as answers? Because that's a vanity metric.
If it's not a retention curve, I don't care.