Connect a codeless connector in Microsoft Sentinel for each type of data you want to collect from TrendAI Vision One™: Workbench alerts, Observed Attack Techniques (OAT) detections, or both. The connectors are built on the Microsoft Sentinel Codeless Connector Framework (CCF) and require no Azure resources to host.
Before you begin
Before you begin, make sure you have the following:
-
A Microsoft Sentinel workspace
-
Read and write permissions on the Log Analytics workspace
-
The Contributor or Owner role on the resource group that contains the workspace
-
An API key from a TrendAI Vision One™ user account with the SIEM role, or a custom role that grants Workbench (View) and Observed Attack Techniques (View) permissions. The user account access level must include APIs.
If access to the TrendAI Vision One™ API is restricted on your network, also allow the outbound IP addresses that Microsoft
Sentinel uses for codeless connectors. These addresses are published under the Scuba Azure service tag.
The following connectors are available:
-
TrendAI Vision One™ - Workbench Alerts (via Codeless Connector Framework), which collects Workbench alert data
-
TrendAI Vision One™ - OAT Detections (via Codeless Connector Framework), which collects Observed Attack Techniques data
Procedure
- Install the TrendAI Vision One™ (CCF) solution in Microsoft Sentinel.
- In your Microsoft Sentinel workspace, go to .
- Search for TrendAI Vision One™ (CCF) and click Install.
- Connect a connector.
- In your Microsoft Sentinel workspace, go to .
- Search for and select the connector for the data you want to collect, and then click Open connector page.
- Specify the following settings:SettingConfiguration NotesAPI DomainThe API domain that corresponds to the location of your TrendAI Vision One™ instance.
-
Australia: api.au.xdr.trendmicro.com
-
Canada: api.ca.xdr.trendmicro.com
-
Europe: api.eu.xdr.trendmicro.com
-
India: api.in.xdr.trendmicro.com
-
Japan: api.xdr.trendmicro.co.jp
-
Middle East and Africa: api.mea.xdr.trendmicro.com
-
Singapore: api.sg.xdr.trendmicro.com
-
South Africa: api.za.xdr.trendmicro.com
-
United Kingdom: api.uk.xdr.trendmicro.com
-
United States: api.xdr.trendmicro.com
API TokenThe API key from your TrendAI Vision One™ user account.TMV1-Filter (Optional)A filter expression sent on every API call. For example, collect only alerts of high severity or greater. Leave empty to collect all data.Exclude third-party OAT detectionsAvailable for the OAT Detections connector only. Determines whether the connector collects Observed Attack Techniques data that originates from third-party sources.Available options:-
Yes - Exclude third-party detections (Recommended) (default)
-
No - Include all detections
-
- Click Connect.
- If you want to collect both Workbench alert and Observed Attack Techniques data, repeat step 2 for the second connector.
Microsoft Sentinel creates the data collection rule and the custom tables, and begins
retrieving new data generated by TrendAI Vision One™. The connectors collect data from connection time onward. Preexisting or historical
data is not collected. Allow up to 30 minutes for data to first appear in your Log
Analytics workspace.
ImportantThe codeless connectors write to different tables than the Azure Functions
connector. If you previously used the Azure Functions connector, update any
analytics rules, hunting queries, workbooks, playbooks, and parsers that
reference the earlier tables.
|
To verify data collection, see View the ingested data in Log Analytics workspaces.
