Allow Logpoint to collect alert and event data from Workbench and Observed Attack Techniques for analysis.
Procedure
- In the TrendAI Vision One™ console, obtain the Authentication
token.
- Go to .
- Locate and click the Logpoint SIEM card.
- Use the copy icon (
) to obtain the
Authentication token.
- Add Trend Vision One Alerts as a log source in the Logpoint
console.
- Add a new log source on the Log Sources
screen.The Add Log Source window appears.
- Select the Trend Vision One Alerts template.
- On the Connector tab, specify the
Authorization Type and paste the
authentication token obtained from the TrendAI Vision One™
console.Logpoint provides default settings for the Source, Endpoints, Routing, and Normalization tabs. You can select an optional enrichment policy on the Enrichment tab.
- Click Save Changes.
Logpoint begins collecting alert and event data from TrendAI Vision One™. Logpoint can only collect data generated after connecting TrendAI Vision One™ as a log source. You might need to allow some time before new data starts to appear in the Logpoint console. - Add a new log source on the Log Sources
screen.
