Trend Vision One provides two types of sweeping that allows you to search your environment for indicators of compromise.
Only Endpoint Activity Data and Email Activity Data are supported for both types of sweeping.
Type |
Description |
---|---|
Auto Sweeping |
Auto Sweeping runs based on the following intelligence data:
Trend Vision One triggers Auto Sweeping tasks at the same scheduled time every day and calculates the total number of indicators applied for Auto Sweeping over the past 24 hours to track quota usage. Note:
A maximum of 50,000 indicators is allowed per day for Auto Sweeping. The quota limit is shared by Auto Sweeping tasks triggered from both intelligence reports and third-party intelligence. If the total number of indicators reaches the daily quota limit for Auto Sweeping, you can trigger Manual Sweeping when necessary. |
Manual Sweeping |
You can select any intelligence report to initiate a manual sweep based on identified indicators. Note:
A maximum of 10,000 indicators is allowed per day for Manual Sweeping. |