檢視次數:

在 Microsoft Sentinel 中為每種您想從 TrendAI Vision One™ 收集的資料類型連接一個無代碼連接器:Workbench 警報、Observed Attack Techniques (OAT) 偵測,或兩者皆有。這些連接器基於 Microsoft Sentinel 無代碼連接器框架 (CCF) 構建,且不需要 Azure Resources 來託管。

開始之前

在開始之前,請確保您擁有以下物品:
  • Microsoft Sentinel 工作區
  • 在 Log Analytics 工作區上的讀寫權限
  • 包含工作區的資源群組上的貢獻者或擁有者角色
  • 來自具有 SIEM 角色的 TrendAI Vision One™ 使用者帳號的 API 金鑰,或授予 Workbench(檢視)和 Observed Attack Techniques(檢視)權限的自訂角色。使用者帳號的存取層級必須包含 API。
如果在您的網路上限制了對TrendAI Vision One™ API 的存取,請同時允許 Microsoft Sentinel 用於無代碼連接器的輸出 IP 位址。這些位址是以Scuba Azure 服務標籤發佈的。
提供下列連接器:
  • TrendAI Vision One™ - Workbench Alerts (via Codeless Connector Framework)」,用於收集 Workbench 警示資料
  • TrendAI Vision One™ - OAT Detections (via Codeless Connector Framework)」,收集 Observed Attack Techniques 資料防護

步驟

  1. 在 Microsoft Sentinel 中安裝TrendAI Vision One™ (CCF)」解決方案。
    1. 在您的 Microsoft Sentinel 工作區中,前往「Content management」「Content hub」
    2. 搜尋TrendAI Vision One™ (CCF)」並點擊「安裝」
  2. 連接連接器。
    1. 在您的 Microsoft Sentinel 工作區中,前往「組態」「Data connectors」
    2. 搜尋並選取您要收集資料的連接器,然後按一下「Open connector page」
    3. 指定下列設定:
      設定
      組態設定注意事項
      API 網域
      與您TrendAI Vision One™實例位置資訊相對應的 API 網域。
      • 澳大利亞:「api.au.xdr.trendmicro.com」
      • 加拿大:「api.ca.xdr.trendmicro.com」
      • 歐洲:「api.eu.xdr.trendmicro.com」
      • 印度: 「api.in.xdr.trendmicro.com」
      • 日本:「api.xdr.trendmicro.co.jp」
      • 中東和非洲:「api.mea.xdr.trendmicro.com」
      • 新加坡: 「api.sg.xdr.trendmicro.com」
      • 南非:「api.za.xdr.trendmicro.com」
      • 英國:「api.uk.xdr.trendmicro.com」
      • 美國:「api.xdr.trendmicro.com」
      API 令牌
      來自您的 TrendAI Vision One™ 使用者帳號的 API 金鑰。
      TMV1-過濾器(可選)
      在每次 API 呼叫中發送的篩選表達式。例如,僅收集嚴重性或更高的警報。留空以收集所有資料。
      排除第三方OAT偵測
      僅適用於 OAT 偵測連接器。確定連接器是否收集來自第三方來源的 Observed Attack Techniques 資料。
      可用的選項:
      • 「Yes - Exclude third-party detections (Recommended)」(預設)
      • No - Include all detections
    4. 請點選「連線」。
  3. 如果您想收集Workbench警報和Observed Attack Techniques資料,請對第二個連接器重複步驟2。
Microsoft Sentinel 會建立資料收集規則和自訂表格,並開始擷取由 TrendAI Vision One™ 產生的新資料。連接器會從連接時間開始收集資料。既有或歷史資料不會被收集。請允許最多 30 分鐘,資料才會首次出現在您的 Log Analytics 工作區中。
重要
重要
無代碼連接器寫入的表格與 Azure Functions 連接器不同。如果您之前使用過 Azure Functions 連接器,請更新任何引用早期表格的分析規則、狩獵查詢、工作簿、Playbooks 和解析器。
若要驗證資料收集,請參閱在 Log Analytics 工作區查看已匯入的資料