---
isPrivate: true
title: SentinelOne Cloud Funnel EDR
description: Learn more about the SentinelOne Cloud Funnel EDR pack.
breadcrumbs: Docs > Observability Pipelines > Packs > SentinelOne Cloud Funnel EDR
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# SentinelOne Cloud Funnel EDR

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

## Overview{% #overview %}

{% image
   source="https://docs.dd-static.net/images/observability_pipelines/packs/sentinel_one.73020a3a733e573b1f435aa2837eed17.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/observability_pipelines/packs/sentinel_one.73020a3a733e573b1f435aa2837eed17.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The SentinelOne Cloud Funnel EDR pack" /%}

SentinelOne Cloud Funnel streams EDR and Deep Visibility events as JSON to cloud storage.

What this pack does:

- Drops low-value types
- Removes unused fields per event type (DNS, File, Process, Network, Registry, and so on)
- Optionally, remove counter field

## Further Reading{% #further-reading %}

Additional helpful documentation, links, and articles:

