Trend Vision One
Support Added: FortiSIEM 7.1.1
Vendor Version Tested: Not Provided
Vendor: Trend Micro
Product Information: https://www.trendmicro.com/en_us/business.html
Trend Vision One is the solution name for the new Trend Vision One platform that enhances and consolidates detection, investigation and response capabilities across email, endpoints, servers, cloud workloads and networks.
Event Types
In ADMIN > Device Support > Event Types, search for "Trend_Vision" to see the event types associated with this device.
Configuration
Required API Permissions for Trend Vision One Integration
The following APIs are called for the Trend Vision One integration. The required API key role permissions are provided here.
Note: See https://automation.trendmicro.com/xdr/api-v3 for more information.
API |
API Key Role Permissions Required |
---|---|
v3.0/audit/logs |
|
v3.0/workbench/alerts |
|
v3.0/sandbox/analysisResults |
|
v3.0/search/endpointActivities v3.0/search/detections v3.0/search/emailActivities v3.0/search/networkActivities v3.0/search/containerActivities |
|
Acquire Trend Vision One API Token
FortiSIEM requires an API token from Trend Vision One. Take the following steps from your Trend Vision One console.
-
Navigate to Administration > User Accounts.
-
Click on your Account Name.
-
Copy the authentication token and place it in a secure location.
Note: By default, an authentication token expires one year after its creation. However, a Master Administrator can delete and re-generate a token at any time.
-
Click Close.
FortiSIEM Setup
Take the following steps to configure Trend Vision One with FortiSIEM.
Create Trend Vision One Credential
-
Login to FortiSIEM as an administrator.
-
Navigate to Admin > Setup > Credentials.
-
Under Step 1: Enter Credentials, click New.
-
In the Access Method Definition window, input the following:
-
In the Name field, enter "TrendMicro Trend Vision One".
-
From the Device Type drop-down list, select TrendMicro Trend Vision One.
-
In the Token field, enter/paste the authentication token information from Acquire Trend Vision One API Token.
-
In the Confirm Token field, enter/paste the same authentication token information from Acquire Trend Vision One API Token.
-
Click Save.
-
Ensure the Trend Vision One Credential is selected. If it isn't, select it.
-
Create IP to Credential Mapping
Under Step 2: Enter IP Range to Credential Associations, take the following steps.
-
Click New.
-
From the Device Credential Mapping Definition window, take the following steps.
-
From the Credentials drop-down list, select the credential you just created in the above steps.
-
In the IP/Host Name field, enter the host name based on your appropriate region.
Region
Host Name
Australia
api.au.xdr.trendmicro.com
European Union
api.eu.xdr.trendmicro.com
India
api.in.xdr.trendmicro.com
Japan
api.xdr.trendmicro.co.jp
Singapore
api.sg.xdr.trendmicro.com
United States
api.xdr.trendmicro.com
-
Click Save.
-
Verifying Mapping
To verify your configuration, take the following steps.
-
Under Step 2: Enter IP Range to Credential Associations, select the "IP to Credential Mapping" you just created.
-
Click the Test drop-down, and select Test Connectivity without Ping.
-
Navigate to Admin > Setup > Pull Events. The new job will appear in the Pull Events table.
-
Events can be queried from the Analytics page by doing a search of
Raw Event Log CONTAIN Trend_Vision_One_
.