Configure Trend Vision One for Arctic Wolf monitoring

You can configure Trend Vision One® to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • An admin user account
  • A Trend Vision One package with an XDR license
    Note: An XDR license is included in Trend Vision One Endpoint Security Essentials and Trend Vision One Advanced Access. Third-party vendors can change their services. You must confirm your licenses with the vendor.

Create a user role

  1. Sign in to the Trend Micro Portal.
  2. Click Administration > User Roles.
  3. Click + Add Role.
  4. In the General Information tab for the Role name field, enter a name for the role.
  5. Click the Permissions tab, and grant these permissions:
    • Platform Capabilities > XDR Threat Investigation:
      • WorkbenchView, filter, and search
      • Observed Attack TechniquesView, filter, and search
    • Settings > Administration:
      • Audit LogsView, filter, and search
  6. Click Save.

Generate an API key

  1. Sign in to the Trend Micro Portal.
  2. Click Administration > API Keys.
  3. Click Add API Key.
  4. In the Add API Key window, configure these settings:
    • Name — Enter a name for the role.
    • Role — Select the role created in Create a user role.
    • Expiration Time — Select an expiration date that meets your security governance requirements.
    • Status — Enabled.
  5. Click Add.
  6. Save the generated API key in a safe, encrypted location to provide to Arctic Wolf later.
  7. Click Close.

Provide Trend Vision One credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Trend Vision One.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • API Token — Enter the API key obtained in Generate an API key.
    • API URL — Enter the appropriate Trend Vision One URL for your region.
      Tip:

      For more information about Trend Vision One regional domains, see Trend Vision One Regional Domains.

    • Credential Expiry — (Optional) Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.