For the complete documentation index, see llms.txt. This page is also available as Markdown.

Trend Micro Vision One (API)

Trend Micro Vision One Integration (API)

Trend Micro Vision One XDR collects and automatically correlates data across multiple security layers: email, endpoint, server, cloud workload, and network. This enables faster threat detection, enhances investigation and response times through improved security analysis.

This integration ingests the following logs:

Workbench Alerts: This endpoint contains information about all the standalone alerts triggered by detection models.

Observed Attack Techniques: This endpoint contains information about observed attack techniques from Detections, Endpoint Activity, Cloud Activity, Email Activity, Mobile Activity, Network Activity, Container Activity, and Identity Activity data sources.

**Audit Logs:**This endpoint contains audit logs.

Setup

Generate API Credentials in Trend Micro Vision One XDR

  1. In the Trend Vision One console, go to on the left side-bar menu and visit Administration > API Keys.

  2. Generate a new authentication token. Click** Add API key**. Specify the settings of the new API key with the following:

Name: A meaningful name that can help you identify the API key

Role: The user role assigned to the key. Select SIEM from dropdown.

**Expiration time:**The time the API key remains valid.

Status: Whether the API key is enabled.

Details: Extra information about the API key.

  1. Click Add.

  • Share the keys with BluSapphire Team

Last updated