Trend Vision One
Configure the Trend Vision One data connector in Radiant Security to ingest alerts and telemetry for AI triage.
Last updated
Was this helpful?
Configure the Trend Vision One data connector in Radiant Security to ingest alerts and telemetry for AI triage.
Connect Trend Vision One to Radiant Security to ingest alerts, observed attack techniques, and search data for AI triage. This guide covers generating the API key in Trend Vision One and adding the data connector in Radiant.
The user role assigned to the API key must grant the following permissions.
Alerts / Workbench
Workbench
View, filter, and search
Observed Attack Techniques
Observed Attack Techniques
View, filter, and search
Search
Search
View, filter, and search
API Keys
IAM
View
The API Keys: View permission lets Radiant read API key metadata only, not key values. Radiant uses this metadata to track your credential's expiration date.
In the Trend Vision One console, go to Administration > API Keys.
Click Add API key.
In Name, enter RADIANT_SECURITY_API_KEY.
In Role, select a role that grants the permissions listed in Required permissions.
In Expiration time, set how long the key remains valid. The default is one year.
Confirm that Status is enabled and add a description in Details if needed.
Click Add.
Copy the API key and store it in a secure location.
The Name value must be exactly RADIANT_SECURITY_API_KEY. Radiant uses this name to identify the credential and track its expiration date.
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors and click + Add Connector.
Search for and select the Trend Micro Vision One API option, click Data Feeds
Click on all data feeds to select them and click Credentials.
Under Credential Name, give the credential an identifiable name (e.g. Trend Vision One Integration).
Enter your API Base URL and API Key.
Click Add Connector
After Trend Vision One begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by the rs_connectorType for each data feed you enabled:
Trend Micro Vision One Alerts
rs_connectorType:"trendmicro_vision_one_alerts"
Trend Micro Vision One Sensor Info
rs_connectorType:"trendmicro_vision_one_sensor_info"
Trend Micro Vision One Query
rs_connectorType:"trendmicro_vision_one_query"
Confirm recent alerts and events appear for each enabled feed.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?