Explore and analyze Trend Micro events

Dashboards

The integration includes vendor dashboards for Trend Micro:

  • LP_TREND VISION ONE OAT – observed attack techniques overview and high/critical OAT hosts

  • LP_TREND VISION ONE ALERTS – workbench alerts, severity trends, top models, top malware/commands

  • LP_CEF: Trend Micro Deep Discovery - Virtual Analyser – suspicious files, malicious sites, affected hosts

  • LP_Trend Micro Deep Security - Firewall – firewall actions, denied connections, top sources/destinations

  • LP_CEF: Trend Micro Deep Discovery - Threat – infected files/hosts, threat types, suspicious behavior, grayware

  • LP_Trend Micro Control Manager – antimalware actions, endpoint outcomes, C&C destinations, NCI threats

  • LP_Trend Micro DB – virus and threat type trends, infection sources, infected workstation users

  • LP_CEF: Trend Micro Deep Discovery - Overview

  • LP_Trend Micro Office Scan

  • LP_Trend Micro Deep Security - Overview

  • LP_Trend Micro Deep Security - Intrusion Prevention

  • LP_Trend Micro Deep Security

  • LP_Trend Micro Deep Security - Anti-Malware

  • LP_Trend Micro IWSVA

  • LP_TREND MICRO IMSVA

To add Trend Micro dashboards:

  1. Go to Settings >> Knowledge Base and select Dashboard.

  2. Select VENDOR DASHBOARD.

  3. Use the Trend Micro dashboards and select the repo that stores Trend Micro logs.

Reports

The integration includes vendor report templates such as:

  • LP_CEF: Trend Micro Deep Discovery - Virtual Analyser

  • LP_Trend Micro Deep Security - Firewall

  • LP_CEF: Trend Micro Deep Discovery - Threat

  • LP_Trend Micro Control Manager

  • LP_Trend Micro DB

  • LP_CEF: Trend Micro Deep Discovery - Overview

  • LP_Trend Micro Deep Security - Overview

  • LP_Trend Micro Deep Security - Intrusion Prevention

  • LP_Trend Micro Deep Security

  • LP_Trend Micro Deep Security - Anti-Malware

  • LP_Trend Micro IWSVA

Alerts

The integration includes predefined alert rules and example queries:

  • Infected file quarantined:

    • Query:

  • Virus/malware quarantined:

    • Query:

  • Botnet detection:

    • Query:

  • Ransomware detection:

    • Query:

  • Antimalware engine offline:

    • Query:

Last updated

Was this helpful?