> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/log-forward/trendmicro/trendmicro-vision-one-syslog.md).

# TrendMicro Vision One (Syslog)

Trend Micro Vision One Integration (Syslog)

[Trend Micro Vision One XDR](https://www.trendmicro.com/en_in/business/products/detection-response/xdr.html) collects and automatically correlates data across multiple security layers: email, endpoint, server, cloud workload, and network. This enables faster threat detection, enhances investigation and response times through improved security analysis.

This integration ingests the following logs:

**Workbench Alerts:** This endpoint contains information about all the standalone alerts triggered by detection models.

**Observed Attack Techniques:** This endpoint contains information about observed attack techniques from Detections, Endpoint Activity, Cloud Activity, Email Activity, Mobile Activity, Network Activity, Container Activity, and Identity Activity data sources.

\*\*Audit Logs:\*\*This endpoint contains audit logs.

#### **Procedure**

1. In TrendAI Vision One™, go to **Workflow and Automation** → **Third-Party Integrations**.
2. Locate and click the **Syslog Connector (On-premises)** card.
3. In the **Syslog Connector (On-premises)** screen, enable **Syslog Connector (On-premises)** .
4. Select the data to send to your syslog server(s).
5. **Workbench alerts**

**b. Observed Attack Techniques**

If you select this data type, you can select one or more of the following event severity levels:

* **Critical**
* **High**
* **Medium**

**c. Audit logs**

If you select this data type, you can select one or more of the following log types:

* **Account**
* **System**

| ##### **Note** You must select at least one data type. |
| ------------------------------------------------------ |

1. Click **Connect Syslog Server**.
2. In the **Syslog Server Connection** panel, configure the following settings.

| Setting         | Description                                          |
| --------------- | ---------------------------------------------------- |
| Server address  | Specify the IP address or FQDN for the Log Collector |
| Syslog format   | Select the syslog format.                            |
| Protocol        | Select the connection protocol.                      |
| Port            | Specify the port shared by BluSapphire               |
| Security Vendor | (Optional) Specify the name of the SIEM vendor.      |

1. Select a Service Gateway appliance with the Syslog Connector service installed from the **Service Gateway** drop-down list.
2. Click **Test Connection** to perform a connection test and verify settings.
3. Click **Connect** to test and save your connection settings.
4. In the **Syslog Connector (On-premises)** screen, click **Save**.
