Last updated
Trend Micro Vision One Integration (API)
Trend Micro Vision One XDR collects and automatically correlates data across multiple security layers: email, endpoint, server, cloud workload, and network. This enables faster threat detection, enhances investigation and response times through improved security analysis.
This integration ingests the following logs:
Workbench Alerts: This endpoint contains information about all the standalone alerts triggered by detection models.
Observed Attack Techniques: This endpoint contains information about observed attack techniques from Detections, Endpoint Activity, Cloud Activity, Email Activity, Mobile Activity, Network Activity, Container Activity, and Identity Activity data sources.
**Audit Logs:**This endpoint contains audit logs.
In the Trend Vision One console, go to on the left side-bar menu and visit Administration > API Keys.
Generate a new authentication token. Click** Add API key**. Specify the settings of the new API key with the following:
Name: A meaningful name that can help you identify the API key
Role: The user role assigned to the key. Select SIEM from dropdown.
**Expiration time:**The time the API key remains valid.
Status: Whether the API key is enabled.
Details: Extra information about the API key.
Click Add.
Share the keys with BluSapphire Team
Last updated