Trend Micro Vision One Connector

Supported Log Types

This connector can fetch the following logs:

  • Audit Logs: User and system-level changes for accountability and compliance.
  • Workbench Alerts: Automated threat alerts generated by Vision One’s correlation engine.
  • Attack Techniques Data: Events mapped to MITRE ATT&CK tactics and techniques via the Observed Attack Techniques (OAT) API.

Prerequisites

  • An active Trend Micro Vision One account with API access.
  • An API token with sufficient permissions for the endpoint listed above (preferably Master Administrator).
Steps to derive the Prerequisites

  • Log in to your Trend Micro Vision One console.
  • Navigate to User Accounts under Settings.
  • Select your user profile and choose Edit.
  • Ensure your Role is set to Master Administrator.
  • Enable API access and generate a new token.
Configuration Guide

FieldsDescription
Connector NameA friendly name to identify the connector.
Log TypesThe category of logs to fetch (Audit Logs, Workbench Alerts, or Attack Techniques)
Base URLAPI base URL for Trend Micro Vision One. Leave default unless directed otherwise.
Trend TokenBearer token generated from Vision One for API access.

After entering all fields:

  • Click Save to apply the configuration.
  • Click Test Connection to verify connectivity.