Configure the integration to allow Picus Security to pull events from TrendAI Vision One™, as well as to query logs and alerts to analyze and validate simulated attacks.
Procedure
- In the TrendAI Vision One™
console, obtain the endpoint URL and authentication token.
- Go to .
- Locate and click the Picus Security card.
- Click
to copy and save the
Endpoint URL. - Copy and save the Authentication token.
-
If no authentication token exists, click Generate and copy the new token. You can specify the expiration time in .
-
If the existing authentication token is expired, click Revoke, then generate and copy a new token.
-
- Configure the integration in the Picus Security console.For more information, see the integration demo video.
- Click Integrations.
- Find the TrendAI™ integration and use the edit icon to select Edit Configuration.
- Paste the endpoint URL and authentication token obtained from the TrendAI Vision One™ console in the Login Credentials section.
- (Optional) Configure your Communication Preferences.
- Click Login.
- On the Log Analysis tab, specify a Delay Time (Seconds) and an optional Early Time (Seconds) for the query interval.
- (Optional) On the Alert Analysis (optional) tab, specify the starting and ending times of the alert analysis interval.
- Click Submit.Picus Security begins collecting data from TrendAI Vision One™ and displaying information in the Simulations menu in the Picus console. Picus can only collect data generated after connecting to TrendAI Vision One™. You might need to allow some time before new data starts to appear.
