Configure Trend Vision One Email and Collaboration Security for Arctic Wolf monitoring

You can configure Trend Vision One® Email and Collaboration Security to send the necessary logs to Arctic Wolf® for security monitoring.

Note:

To configure log monitoring for multiple Trend Vision One® products, only complete these instructions once. Make sure that the credentials that you submit to Arctic Wolf are associated with all required licenses and permissions.

These resources are required:

  • An admin user account
  • A Trend Vision One license for XDR for Email

Create a user role

  1. Sign in to the Trend Vision One console.
  2. Click Administration > User Roles.
  3. Click + Add role.
  4. In the General Information tab, in the Role Name field, enter a descriptive name for the role.
  5. Under Control flags, configure these settings:
    1. Select Yes for Can be assigned to API keys.
    2. Select No for Can be assigned to user accounts.
  6. Click the Permissions tab and grant these permissions:
    • Platform Capabilities > Agentic SIEM and XDR:
      • WorkbenchView, filter, and search
      • XDR Data ExplorerView queries and Watchlist, and filter and search queries
      • Observed Attack TechniquesView, filter, and search
    • Settings > Administration:
      • Audit LogsView, filter, and search
  7. Click Save.

Generate an API key

  1. Sign in to the Trend Vision One console.
  2. Click Administration > API Keys.
  3. Click Add API Key.
  4. In the Add API Key window, configure these settings:
    • Name — Enter a unique and descriptive name for the API key.
    • Role — Select the role created in Create a user role.
    • Expiration Time — Select an expiration date that meets your security governance requirements.
    • Status — Enabled.
  5. Click Add.
  6. Copy the API key, and then save it in a safe, encrypted location. You will provide this value to Arctic Wolf later.

Provide Trend Vision One credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Trend Vision One Endpoint and Email & Collaboration Security.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • API Token — Enter the API key obtained in Generate an API key.
    • API URL — Enter the appropriate Trend Vision One URL for your region.
      Tip:

      For more information about Trend Vision One regional domains, see Trend Vision One Regional Domains.

    • Credential Expiry — Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.