For the complete documentation index, see llms.txt. This page is also available as Markdown.

TrendMicro Vision One (Syslog)

Trend Micro Vision One Integration (Syslog)

Trend Micro Vision One XDR collects and automatically correlates data across multiple security layers: email, endpoint, server, cloud workload, and network. This enables faster threat detection, enhances investigation and response times through improved security analysis.

This integration ingests the following logs:

Workbench Alerts: This endpoint contains information about all the standalone alerts triggered by detection models.

Observed Attack Techniques: This endpoint contains information about observed attack techniques from Detections, Endpoint Activity, Cloud Activity, Email Activity, Mobile Activity, Network Activity, Container Activity, and Identity Activity data sources.

**Audit Logs:**This endpoint contains audit logs.

Procedure

  1. In TrendAI Vision One™, go to Workflow and AutomationThird-Party Integrations.

  2. Locate and click the Syslog Connector (On-premises) card.

  3. In the Syslog Connector (On-premises) screen, enable Syslog Connector (On-premises) .

  4. Select the data to send to your syslog server(s).

  5. Workbench alerts

b. Observed Attack Techniques

If you select this data type, you can select one or more of the following event severity levels:

  • Critical

  • High

  • Medium

c. Audit logs

If you select this data type, you can select one or more of the following log types:

  • Account

  • System

##### Note You must select at least one data type.

  1. Click Connect Syslog Server.

  2. In the Syslog Server Connection panel, configure the following settings.

Setting
Description

Server address

Specify the IP address or FQDN for the Log Collector

Syslog format

Select the syslog format.

Protocol

Select the connection protocol.

Port

Specify the port shared by BluSapphire

Security Vendor

(Optional) Specify the name of the SIEM vendor.

  1. Select a Service Gateway appliance with the Syslog Connector service installed from the Service Gateway drop-down list.

  2. Click Test Connection to perform a connection test and verify settings.

  3. Click Connect to test and save your connection settings.

  4. In the Syslog Connector (On-premises) screen, click Save.

Last updated