Configure Trend Vision One Endpoint Security for Arctic Wolf monitoring

You can configure Trend Vision One® Endpoint Security to send the necessary logs to Arctic Wolf® for security monitoring.

Note:

To configure log monitoring for multiple Trend Vision One® products, only complete these instructions once. Make sure that the credentials that you submit to Arctic Wolf are associated with all required licenses and permissions.

These resources are required:

  • An admin user account
  • A Trend Vision One license for XDR for Endpoint

Create a user role

  1. Sign in to the Trend Vision One console.
  2. Click Administration > User Roles.
  3. Click + Add role.
  4. In the General Information tab, in the Role Name field, enter a descriptive name for the role.
  5. Under Control flags, configure these settings:
    1. Select Yes for Can be assigned to API keys.
    2. Select No for Can be assigned to user accounts.
  6. Click the Permissions tab and grant these permissions:
    • Platform Capabilities > Agentic SIEM and XDR:
      • WorkbenchView, filter, and search
      • XDR Data ExplorerView queries and Watchlist, and filter and search queries
      • Observed Attack TechniquesView, filter, and search
    • Settings > Administration:
      • Audit LogsView, filter, and search
  7. Click Save.

Generate an API key

  1. Sign in to the Trend Vision One console.
  2. Click Administration > API Keys.
  3. Click Add API Key.
  4. In the Add API Key window, configure these settings:
    • Name — Enter a unique and descriptive name for the API key.
    • Role — Select the role created in Create a user role.
    • Expiration Time — Select an expiration date that meets your security governance requirements.
    • Status — Enabled.
  5. Click Add.
  6. Copy the API key, and then save it in a safe, encrypted location. You will provide this value to Arctic Wolf later.

Provide Trend Vision One credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. ナビゲーションメニューで、[データ収集] > [クラウドセンサ]をクリックします。
  3. Click Add Account +.
  4. On the Add Account page, click Trend Vision One Endpoint and Email & Collaboration Security.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • API Token — Enter the API key obtained in Generate an API key.
    • API URL — Enter the appropriate Trend Vision One URL for your region.
      Tip:

      For more information about Trend Vision One regional domains, see Trend Vision One Regional Domains.

    • Credential Expiry — Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.