Configuring Trend Micro

Log sources for Trend Micro can be configured using Log Source Templates or Devices. We recommend using the log source templates to minimize setup requirements and eliminate normalization issues.

Using Log Source Templates

Log source templates include predefined settings and configurations to receive the normalized Trend Micro logs, but some configurations must be done manually.

Syslog Collector based Log Source Template

If you have configured your Trend Micro to send its Syslog messages via port UDP 514 or TCP, use the Syslog Collector based Trend Micro log source template. Go to Creating Log Source via a Template to learn more.

_images/TrendMicroLST.png

Selecting Trend Micro Log Source Template

Universal Rest API Fetcher based Log Source Template

If you have set up authentication, made HTTP requests, and implemented specific API endpoints required by Trend Micro’s services, use the Universal REST API Fetcher based TrendVisionOne log source template. You must configure Source, Connector and Routing, while other are optional.

To configure:

  1. Go to Settings >> Log Sources from the navigation bar and click Browse Log Source Templates.

  2. Search and click TrendVisionOne.

_images/template.png

Log Source Templates

Source

You must add the root address from where the TrendVisionOne fetches logs. The base URL provides a consistent entry point for the log collection system to interact with the Trend Micro’s API or service. The specific endpoints or paths added to the base URL would allow you to collect different types of logs or interact with different aspects of the log source, such as to get application logs, error logs or get performance metrics.

  1. In Base URL, enter the endpoint URL and port number using the https://<your server>:port number format. For example, http://1.1.1.1:50.

_images/source.png

Configuring Source

Connector

Connector is a pathway for transmitting logs from various sources to Logpoint. You must authenticate TrendVisionOne to retrieve or interact with Trend Micro via providing the API Key. You do not need to select the Product and ensure No Auth is selected as Authorization Type.

  1. Click Connector.

  2. In Custom headers,

2.1. In Authorization Value, replace {{token}} with the generated API key.

_images/connector1.png

Configuring Connector

Endpoints

These are specific points within a system, application, or network from which logs are collected. These endpoints generate or provide access to log data that can be used for monitoring, analysis, troubleshooting, and security purposes. Go to Endpoints to configure details about the Trend Micro endpoints.

Routing

In routing, you can create repos and routing criteria for Trend Micro. Repos are locations where incoming logs are stored and routing criteria is created to determine the conditions under which these logs are sent to repos.

  1. Click Routing to create repos and routing criteria.

1.1. Click + Create Repo.

1.2. Enter a Repo name.

1.3. In Path, enter the location to store incoming logs.

1.4. In Retention (Days), enter the number of days logs are kept in a repository before they are automatically deleted.

1.5. In Availability, select the Remote logpoint and Retention (Days).

1.6. Click Create Repo.

_images/createrepo.png

Creating a Repo

1.7. In Repo, click the drop-down and select the just created repo’s name. This is where Trend Micro logs will be stored.

1.8. Click + Add row.

1.9. Enter a Key and Value. The routing criteria are only applied to those logs which have this key value pair.

1.10. Select an Operation for logs that have this key value pair.

1.10.1. Select Store raw message to store both the incoming and the normalized logs in the selected repo.

1.10.2. Select Discard raw message to discard the incoming logs and store the normalized ones.

1.10.3. Select Discard entire event to discard both the incoming and the normalized logs.

1.11. In Repository, select a repo to store logs.

_images/createrepository.png

Creating a Routing Criteria

Note

Click the (uninstall) icon under Action to delete the created routing criteria.

Normalization

Normalizers transform incoming logs into a standardized format for consistent and efficient analysis. You can select normalizers for the incoming Trend Micro logs.

  1. Click Normalization.

  2. You can either select a previously created normalization policy from the Select Normalization Policy drop-down or select a Normalizer from the list and click the swap(Swap) icon.

Enrichment

Enrichment policies are used to add additional information to a log, such as user information, device type or geolocation, before analyzing it. You can select an enrichment policy for the incoming Trend Micro logs. Go to Enrichment to select normalizers for the incoming Trend Micro logs.

  1. Click Enrichment.

  2. Select an enrichment policy for the incoming logs.

Click Save Configuration to save all the above configurations.

Using Devices

Configuring a Repo for Trend Micro

  1. Go to Settings >> Configuration from the navigation bar and click Repos.

  2. Click Add.

  3. Enter a Repo Name.

  4. Select a Repo Path to store incoming logs.

  5. Set a Retention Day to keep logs in a repository before they are automatically deleted.

Note

You can add and remove multiple Repo Path and Retention Day.

  1. Select a Remote Logpoint. This will create a copy of the repo in the Remote Logpoint. If the configured repo is not accessible, the copy will be used in Search.

  2. Set an Available for (day) to specify the days you want the repo copy to remain highly available.

  3. Click Submit.

_images/addrepo.png

Adding a Repo

Adding a Normalization Policy for Trend Micro

  1. Go to Settings >> Configuration from the navigation bar and click Normalization Policies.

  2. Click Add .

  3. Enter a Policy Name.

  4. Select the Compiled Normalizer and Normalization Packages for Trend Micro.

  5. Click Submit.

_images/normtrend1.png

Adding a Normalization Policy

Configuring a Processing Policy for Trend Micro

  1. Go to Settings >> Configuration from the navigation bar and click Processing Policies.

  2. Click Add .

  3. Enter a Policy Name.

  4. Select the previously created Normalization Policy.

  5. Select the Enrichment Policy and Routing Policy.

  6. Click Submit.

_images/pp.png

Adding a Processing Policy

Adding Trend Micro as a device in Logpoint

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click Add.

  3. Enter a device Name.

  4. Enter the Trend Micro server IP address(es).

  5. Select the Device Groups.

  6. Select an appropriate Log Collection Policy for the logs.

  7. Select a collector or a forwarder from the Distributed Collector drop-down.

Note

It is optional to select the Device Groups, the Log Collection Policy and the Distributed Collector.

  1. Select a Time Zone. The timezone of the device must be same as its log source.

  2. Configure the Risk Values for Confidentiality, Integrity and Availability used to calculate the risk levels of the alerts generated from the device.

  3. Click Submit.

_images/normtrend2.png

Create Device Panel

Configuring the Syslog Collector for Trend Micro

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click the Add icon from Actions of the previously added device.

  3. Click Syslog Collector.

Note

You can select a different collector depending on your requirements and added device. To learn more about available collectors, go to collectors. If you require assistance, contact our support team.

  1. Select Syslog Parser as Parser.

  2. Select the previously created Processing Policy.

  3. Select the Charset. The default value is utf_8.

  4. In Proxy Server, select None

  5. Click Submit.

Syslog Collector Panel

Configuring the Syslog Collector

Configuring the ODBC Fetcher for Trend Micro

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click the Add Collectors/Fetchers icon from Actions of the previously added device.

  3. Click ODBC Fetcher.

_images/normtrend6.png

AVAILABLE COLLECTORS FETCHERS Panel

  1. Click ADD.

_images/normtrend3.png

ODBC Fetcher Panel

  1. Select a Mode. The ODBC Fetcher has General and Advanced modes of configuration. The Advanced mode allows you to define the incremental key value. But, in the General mode, the incremental key value is 0.

In General mode, you can select the Trend Micro Office Scan v11.0 or None template. The Trend Micro Office Scan v11.0 template has predefined configurations. But you must perform some configurations manually.

For General mode with None template

  1. In Driver, enter MSSQL.

  2. Select the Port option and enter 1433.

  3. In Database, enter db_ControlManager.

  4. Enter the Username and Password.

  5. Enter the Fetch Interval.

  6. Enter the following Query to retrieve the logs:

    For  TrendMicro DB v11:
    SELECT * FROM v_Virus_HostDetail
    
    For  TrendMicro DB v12:
    SELECT * FROM tb_AVVirusLog
    
  7. In Incremental Key, enter the following:

Note

  • If you are using the Advanced mode, provide the initial Incremental Key Value. The default value is 0.

  • If you are using the General mode, you cannot set the value of the Incremental Key Value. The application sets the value to 0 automatically.

  1. In Incremental Key Table, enter the given key table:

    For  TrendMicro DB v11:
    v_Virus_HostDetail
    
    For  TrendMicro DB v12:
    tb_AVVirusLog
    

    Note

    If you are using the Advanced Mode, you do not have to provide the Incremental Key Table.

  2. Enter a New Line Separator to replace the newline characters in the ODBC data. For example, if you provide the New Line Separator as “_”, the application displays the ODBC data as “data1_data2_data3”.

  3. Select the previously created Processing Policy.

  4. Enter the Charset. The default value is utf_8.

  5. Click Test to validate the configuration.

  6. Click Submit.

_images/odbc12.png

Configuring in General Mode with None Template

For General mode with a template

The template has predefined values for Driver, Database, Query, Incremental Key, Incremental Key Table and New Line Separator.

  1. Select the Port option and enter 1433.

  2. Enter the Username and Password.

  3. Enter the Fetch Interval.

  4. Select the previously created Processing Policy.

  5. Click Test to validate the configuration.

  6. Click Submit.

_images/odbc11.png

Configuring in General Mode with a Template

Note

The configuration for Advanced mode is similar to above.

_images/advanced.png

Configuring in Advanced Mode


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support