在 Microsoft Sentinel 中為每種您想從 TrendAI Vision One™ 收集的資料類型連接一個無代碼連接器:Workbench 警報、Observed Attack Techniques (OAT) 偵測,或兩者皆有。這些連接器基於 Microsoft Sentinel 無代碼連接器框架 (CCF) 構建,且不需要 Azure Resources 來託管。
開始之前
在開始之前,請確保您擁有以下物品:
-
Microsoft Sentinel 工作區
-
在 Log Analytics 工作區上的讀寫權限
-
包含工作區的資源群組上的貢獻者或擁有者角色
-
來自具有 SIEM 角色的 TrendAI Vision One™ 使用者帳號的 API 金鑰,或授予 Workbench(檢視)和 Observed Attack Techniques(檢視)權限的自訂角色。使用者帳號的存取層級必須包含 API。
如果在您的網路上限制了對TrendAI Vision One™ API 的存取,請同時允許 Microsoft Sentinel 用於無代碼連接器的輸出 IP 位址。這些位址是以Scuba Azure 服務標籤發佈的。
提供下列連接器:
-
「TrendAI Vision One™ - Workbench Alerts (via Codeless Connector Framework)」,用於收集 Workbench 警示資料
-
「TrendAI Vision One™ - OAT Detections (via Codeless Connector Framework)」,收集 Observed Attack Techniques 資料防護
步驟
- 在 Microsoft Sentinel 中安裝「TrendAI Vision One™ (CCF)」解決方案。
- 在您的 Microsoft Sentinel 工作區中,前往。
- 搜尋「TrendAI Vision One™ (CCF)」並點擊「安裝」。
- 連接連接器。
- 在您的 Microsoft Sentinel 工作區中,前往。
- 搜尋並選取您要收集資料的連接器,然後按一下「Open connector page」。
- 指定下列設定:設定組態設定注意事項API 網域與您TrendAI Vision One™實例位置資訊相對應的 API 網域。
-
澳大利亞:「api.au.xdr.trendmicro.com」
-
加拿大:「api.ca.xdr.trendmicro.com」
-
歐洲:「api.eu.xdr.trendmicro.com」
-
印度: 「api.in.xdr.trendmicro.com」
-
日本:「api.xdr.trendmicro.co.jp」
-
中東和非洲:「api.mea.xdr.trendmicro.com」
-
新加坡: 「api.sg.xdr.trendmicro.com」
-
南非:「api.za.xdr.trendmicro.com」
-
英國:「api.uk.xdr.trendmicro.com」
-
美國:「api.xdr.trendmicro.com」
API 令牌來自您的 TrendAI Vision One™ 使用者帳號的 API 金鑰。TMV1-過濾器(可選)在每次 API 呼叫中發送的篩選表達式。例如,僅收集高嚴重性或更高的警報。留空以收集所有資料。排除第三方OAT偵測僅適用於 OAT 偵測連接器。確定連接器是否收集來自第三方來源的 Observed Attack Techniques 資料。可用的選項:-
「Yes - Exclude third-party detections (Recommended)」(預設)
-
No - Include all detections
-
- 請點選「連線」。
- 如果您想收集Workbench警報和Observed Attack Techniques資料,請對第二個連接器重複步驟2。
Microsoft Sentinel 會建立資料收集規則和自訂表格,並開始擷取由 TrendAI Vision One™ 產生的新資料。連接器會從連接時間開始收集資料。既有或歷史資料不會被收集。請允許最多 30 分鐘,資料才會首次出現在您的 Log Analytics 工作區中。
重要無代碼連接器寫入的表格與 Azure Functions 連接器不同。如果您之前使用過 Azure Functions 連接器,請更新任何引用早期表格的分析規則、狩獵查詢、工作簿、Playbooks
和解析器。
|
若要驗證資料收集,請參閱在 Log Analytics 工作區查看已匯入的資料。
