Skip to content

Commit

Permalink
Merge pull request #2103 from lvoloshyn-sekoia/lv/add_docs_for_vision…
Browse files Browse the repository at this point in the history
…_one

Add docs for Trend Micro Vision One
  • Loading branch information
squioc authored Dec 2, 2024
2 parents 520797e + 35f27a8 commit 210ca57
Show file tree
Hide file tree
Showing 6 changed files with 53 additions and 0 deletions.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
uuid: 9844ea0a-de7f-45d4-9a9b-b07651f0630e
name: Trend Micro Vision One Workbench Alerts [BETA]
type: intake


## Overview

Trend Micro Vision One is an extended detection and response (XDR) platform that enhances threat detection, investigation, and response across multiple security layers. It provides a centralized view for improved security posture and faster threat remediation.
This integration will ingest Workbench Alerts from Trend Micro Vision One.

!!! Warning
Important note - This format is currently in beta. We highly value your feedback to improve its performance.

- **Supported environment**: SaaS
- **Detection based on**: Alerts
- **Supported application or feature**:
- Alerts

## Configure

### How to create an API token

1. Log in the Trend Vision One console
2. On the left panel, click `Administration` then click `API keys`

![step 1](/assets/integration/cloud_and_saas/trend_micro_vision_one/01_administration.png)

3. Click `Add API key`

![step 2](/assets/integration/cloud_and_saas/trend_micro_vision_one/02_create_api_key.png)

4. Type a name for the API key
5. Select the `SIEM` role and an expiration time
6. Check `status` to enable the API key

![step 3](/assets/integration/cloud_and_saas/trend_micro_vision_one/03_create_api_key.png)

7. Copy the API key and click `Close`

![step 4](/assets/integration/cloud_and_saas/trend_micro_vision_one/04_save_api_key.png)

### Instruction on Sekoia

{!_shared_content/integration/intake_configuration.md!}

{!_shared_content/operations_center/integrations/generated/9844ea0a-de7f-45d4-9a9b-b07651f0630e.md!}

{!_shared_content/integration/detection_section.md!}

{!_shared_content/operations_center/detection/generated/suggested_rules_9844ea0a-de7f-45d4-9a9b-b07651f0630e_do_not_edit_manually.md!}

{!_shared_content/operations_center/integrations/generated/9844ea0a-de7f-45d4-9a9b-b07651f0630e.md!}
1 change: 1 addition & 0 deletions mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -366,6 +366,7 @@ nav:
- Tanium: integration/categories/endpoint/tanium.md
- Trellix EDR: integration/categories/endpoint/trellix_edr.md
- Trend Micro Apex One: integration/categories/endpoint/trend_micro_apex_one.md
- Trend Micro Vision One Workbench: integration/categories/endpoint/trend_micro_vision_one_workbench.md
- VMWare ESXi: integration/categories/endpoint/vmware_esxi.md
- VMWare VCenter: integration/categories/endpoint/vmware_vcenter.md
- Windows: integration/categories/endpoint/windows.md
Expand Down

0 comments on commit 210ca57

Please sign in to comment.