TrendMicro Vision One (Syslog)
Trend Micro Vision One Integration (Syslog)
Trend Micro Vision One XDR collects and automatically correlates data across multiple security layers: email, endpoint, server, cloud workload, and network. This enables faster threat detection, enhances investigation and response times through improved security analysis.
This integration ingests the following logs:
Workbench Alerts: This endpoint contains information about all the standalone alerts triggered by detection models.
Observed Attack Techniques: This endpoint contains information about observed attack techniques from Detections, Endpoint Activity, Cloud Activity, Email Activity, Mobile Activity, Network Activity, Container Activity, and Identity Activity data sources.
**Audit Logs:**This endpoint contains audit logs.
Procedure
In TrendAI Vision One™, go to Workflow and Automation → Third-Party Integrations.
Locate and click the Syslog Connector (On-premises) card.
In the Syslog Connector (On-premises) screen, enable Syslog Connector (On-premises) .
Select the data to send to your syslog server(s).
Workbench alerts
b. Observed Attack Techniques
If you select this data type, you can select one or more of the following event severity levels:
Critical
High
Medium
c. Audit logs
If you select this data type, you can select one or more of the following log types:
Account
System
##### Note You must select at least one data type.
Click Connect Syslog Server.
In the Syslog Server Connection panel, configure the following settings.
Server address
Specify the IP address or FQDN for the Log Collector
Syslog format
Select the syslog format.
Protocol
Select the connection protocol.
Port
Specify the port shared by BluSapphire
Security Vendor
(Optional) Specify the name of the SIEM vendor.
Select a Service Gateway appliance with the Syslog Connector service installed from the Service Gateway drop-down list.
Click Test Connection to perform a connection test and verify settings.
Click Connect to test and save your connection settings.
In the Syslog Connector (On-premises) screen, click Save.
Last updated