Configuring Log Forwarding

Enable sharing Windows security logs from an on-premises Active Directory server with Risk Insights.

Configuring log forwarding allows Active Directory to share Windows security logs (such as object access events, logon/logoff events, system events, and account management events) with Risk Insights through a configured Service Gateway.

Before you begin, you must have at least one Service Gateway virtual appliance deployed and configured. For more information, see Service Gateway Management.

Important:
  • Log Forwarding requires a Service Gateway API key. To obtain the key, go to Workflow and Automation > Service Gateway Management and click Manage API Key.

  • Changing the API key invalidates previously generated API keys.

  1. Obtain the log forwarding agent's installation package from the Trend Vision One console.
    1. Go to Workflow and Automation > Third-Party Integration.
    2. In the Integration column, click Active Directory (on-premises).
    3. Click the toggle to enable or disable the integration.
    4. Under Log forwarding, click on Download Installation Package.

      A tooltip with information about the installation package appears.

    5. Click on Download Installer.
  2. Install the agent on your Active Directory server.
    1. Execute trend-micro-vision-one-ad-connector.exe with administrator rights.
    2. Follow the on-screen wizard to configure the log forwarding agent.
      Important:

      If SSL certificates are imported, the certificates must be the same as the ones used in Service Gateways

  3. Repeat the previous step to install the agent in multiple Active Directory servers.
  4. Verify that the agent has connected to Trend Vision One and perform additional integration steps if necessary.
    Note:

    Any configuration changes on the Trend Vision One console take 5 minutes to reflect on the log forwarding agent.

    1. Go to Workflow and Automation > Third-Party Integration.
    2. In the Integration column, click Active Directory (on-premises).
    3. Verify that the log forwarding agents appear under Log forwarding.
    4. (Optional) Under Log forwarding, click on Enable automatic updates.
    Important:

    If the log forwarding agent user interface is open, the automatic updates process stops.