Views:

Connect a codeless connector in Microsoft Sentinel for each type of data you want to collect from TrendAI Vision One™: Workbench alerts, Observed Attack Techniques (OAT) detections, or both. The connectors are built on the Microsoft Sentinel Codeless Connector Framework (CCF) and require no Azure resources to host.

Before you begin

Before you begin, make sure you have the following:
  • A Microsoft Sentinel workspace
  • Read and write permissions on the Log Analytics workspace
  • The Contributor or Owner role on the resource group that contains the workspace
  • An API key from a TrendAI Vision One™ user account with the SIEM role, or a custom role that grants Workbench (View) and Observed Attack Techniques (View) permissions. The user account access level must include APIs.
If access to the TrendAI Vision One™ API is restricted on your network, also allow the outbound IP addresses that Microsoft Sentinel uses for codeless connectors. These addresses are published under the Scuba Azure service tag.
The following connectors are available:
  • TrendAI Vision One™ - Workbench Alerts (via Codeless Connector Framework), which collects Workbench alert data
  • TrendAI Vision One™ - OAT Detections (via Codeless Connector Framework), which collects Observed Attack Techniques data

Procedure

  1. Install the TrendAI Vision One™ (CCF) solution in Microsoft Sentinel.
    1. In your Microsoft Sentinel workspace, go to Content managementContent hub.
    2. Search for TrendAI Vision One™ (CCF) and click Install.
  2. Connect a connector.
    1. In your Microsoft Sentinel workspace, go to ConfigurationData connectors.
    2. Search for and select the connector for the data you want to collect, and then click Open connector page.
    3. Specify the following settings:
      Setting
      Configuration Notes
      API Domain
      The API domain that corresponds to the location of your TrendAI Vision One™ instance.
      • Australia: api.au.xdr.trendmicro.com
      • Canada: api.ca.xdr.trendmicro.com
      • Europe: api.eu.xdr.trendmicro.com
      • India: api.in.xdr.trendmicro.com
      • Japan: api.xdr.trendmicro.co.jp
      • Middle East and Africa: api.mea.xdr.trendmicro.com
      • Singapore: api.sg.xdr.trendmicro.com
      • South Africa: api.za.xdr.trendmicro.com
      • United Kingdom: api.uk.xdr.trendmicro.com
      • United States: api.xdr.trendmicro.com
      API Token
      The API key from your TrendAI Vision One™ user account.
      TMV1-Filter (Optional)
      A filter expression sent on every API call. For example, collect only alerts of high severity or greater. Leave empty to collect all data.
      Exclude third-party OAT detections
      Available for the OAT Detections connector only. Determines whether the connector collects Observed Attack Techniques data that originates from third-party sources.
      Available options:
      • Yes - Exclude third-party detections (Recommended) (default)
      • No - Include all detections
    4. Click Connect.
  3. If you want to collect both Workbench alert and Observed Attack Techniques data, repeat step 2 for the second connector.
Microsoft Sentinel creates the data collection rule and the custom tables, and begins retrieving new data generated by TrendAI Vision One™. The connectors collect data from connection time onward. Preexisting or historical data is not collected. Allow up to 30 minutes for data to first appear in your Log Analytics workspace.
Important
Important
The codeless connectors write to different tables than the Azure Functions connector. If you previously used the Azure Functions connector, update any analytics rules, hunting queries, workbooks, playbooks, and parsers that reference the earlier tables.