Set up the Securonix SIEM integration to enable Securonix to collect alerts, events, and audit logs from TrendAI Vision One™.
Procedure
- In the TrendAI Vision One™
console, obtain the endpoint URL and authentication token.
- Go to .
- Locate and click the Securonix SIEM card.
- Obtain the values from the following fields.
-
Click
to copy the
Endpoint URL. -
Click Generate and copy the Authentication token.
-
- Configure and save setup credentials for TrendAI Vision One™ on the
Securonix platform.For more information on the configuration, see Securonix Cloud documentation.
- In Unified Defense SIEM, go to .
- Click .
- In the Resource Type Information window, enter the
following values.SettingDescriptionVendorsTrend Micro Inc.Resource TypesTrend Micro Vision One - Alerts : [trendmicroxdr] [JSON]Parser NameSCNX_TRENDM_TRENDMICROVISIONONEALERT_CEDR_TRE_JSO_COMM
- Select an Ingester from the list.
- In the Connection Details window, configure the
following settings.SettingDescriptionLog TypesSelect one of the following:
-
Alerts V3
-
Audit Logs V3
Base URLPaste the endpoint URL copied from the TrendAI Vision One™ console.TokenPaste the authentication token copied from the TrendAI Vision One™ console. -
- Click Save & Next.
- In the Parser Management window, click Save & Next.
- Add a correlation rule on the Securonix platform.
- Click .
- Give the correlation rule a descriptive name.
- Specify a value for each column in the Correlate events to user using rule table.
- Click .
- In the Policy Violations window, click Save & Next.
- Run the integration to save TrendAI Vision One™ as a data source on the Securonix platform.
- In the Job Scheduling Information window, select Do you want to run job Once?.
- Click Save & Run.Securonix begins collecting event data from TrendAI Vision One™. Securonix can only collect data generated after connecting to TrendAI Vision One™. You might need to allow some time before new data starts to appear.
