> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/cloud-log-forwarding/trendmicro/trend-micro-vision-one-api.md).

# Trend Micro Vision One (API)

Trend Micro Vision One Integration (API)

[Trend Micro Vision One XDR](https://www.trendmicro.com/en_in/business/products/detection-response/xdr.html) collects and automatically correlates data across multiple security layers: email, endpoint, server, cloud workload, and network. This enables faster threat detection, enhances investigation and response times through improved security analysis.

This integration ingests the following logs:

**Workbench Alerts:** This endpoint contains information about all the standalone alerts triggered by detection models.

**Observed Attack Techniques:** This endpoint contains information about observed attack techniques from Detections, Endpoint Activity, Cloud Activity, Email Activity, Mobile Activity, Network Activity, Container Activity, and Identity Activity data sources.

\*\*Audit Logs:\*\*This endpoint contains audit logs.

### **Setup**

#### **Generate API Credentials in Trend Micro Vision One XDR**

1. In the Trend Vision One console, go to on the left side-bar menu and visit **Administration > API Keys.**
2. Generate a new authentication token. Click\*\* Add API key\*\*. Specify the settings of the new API key with the following:

**Name:** A meaningful name that can help you identify the API key

**Role:** The user role assigned to the key. Select SIEM from dropdown.

\*\*Expiration time:\*\*The time the API key remains valid.

**Status:** Whether the API key is enabled.

**Details:** Extra information about the API key.

1. Click Add.

* Share the keys with BluSapphire Team
