For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/integrations/trend-micro-vision-one-xdr.md. A documentation index is available at /llms.txt.

TrendAI Vision One XDR

Integration version1.1.0

To find out if this integration is available in your organization, see your Datadog Integrations page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email support@ddog-gov.com.

Overview

TrendAI Vision One XDR collects and automatically correlates data across multiple security layers: email, endpoint, server, cloud workload, and network. This enables faster threat detection, enhances investigation and response times through improved security analysis.

This integration ingests the following logs:

  • Workbench Alerts: This endpoint contains information about all the standalone alerts triggered by detection models.
  • Observed Attack Techniques: This endpoint contains information about observed attack techniques from Detections, Endpoint Activity, Cloud Activity, Email Activity, Mobile Activity, Network Activity, Container Activity, and Identity Activity data sources.

This integration collects logs from the sources listed above and sends them to Datadog for analysis with our Log Explorer and Cloud SIEM products

Setup

Generate API Credentials in TrendAI Vision One XDR

  1. In the TrendAI Vision One console, go to on the left side-bar menu and visit Administration > API Keys.
  2. Generate a new authentication token. Click Add API key. Specify the settings of the new API key with the following:
    • Name: A meaningful name that can help you identify the API key
    • Role: The user role assigned to the key. Select SIEM from dropdown.
    • Expiration time: The time the API key remains valid.
    • Status: Whether the API key is enabled.
    • Details: Extra information about the API key.
  3. Click Add.
  4. To identify the Host Region of your TrendAI Vision One XDR console please refer here.

Connect your TrendAI Vision One XDR Account to Datadog

  1. Add your Host Region and API Key.

    ParametersDescription
    Host RegionThe Region of your TrendAI Vision One XDR Console.
    API KeyThe API Key of your TrendAI Vision One XDR Console.
  2. Click the Save button to save your settings.

Data Collected

Logs

The TrendAI Vision One XDR integration collects and forwards Workbench Alerts and Observed Attack Techniques logs to Datadog.

Metrics

TrendAI Vision One XDR does not include any metrics.

Service Checks

TrendAI Vision One XDR does not include any service checks.

Events

TrendAI Vision One XDR does not include any events.

Support

For further assistance, contact Datadog Support.