收集 Trend Micro Vision One 活动日志

支持的平台:

本文档介绍了如何使用 AWS S3 将 Trend Micro Vision One 活动日志注入到 Google Security Operations。解析器会将 Trend Micro Vision One 活动日志从 JSON 格式转换为统一数据模型 (UDM)。

准备工作

请确保满足以下前提条件:

  • Google SecOps 实例
  • 对 Trend Micro Vision One 的特权访问权限。

在 Trend Micro Vision One 上配置日志记录

  1. 登录 Trend Micro Vision One 控制台。
  2. 依次前往工作流和 Automation> 第三方集成
  3. 点击 Google Security Operations SIEM
  4. 在“访问密钥”下,点击生成密钥
  5. 复制并保存访问密钥 ID私有访问密钥
  6. 在“数据转移”下,启用“活动数据”旁边的切换开关。
  7. 系统会生成 S3 URI,并开始将数据发送到相应的 S3 存储桶。
  8. 复制 S3 URI 并将其保存在安全的位置。
  9. (可选):对于“事件”和“活动”数据,点击修改可修改数据范围(修改范围不会更改生成的 S3 URI)。

设置 Feed

如需配置 Feed,请按以下步骤操作:

  1. 依次前往 SIEM 设置 > Feed
  2. 点击添加新 Feed
  3. 在下一页上,点击配置单个 Feed
  4. Feed 名称字段中,输入 Feed 的名称(例如“Trend Micro Vision One 活动日志”)。
  5. 选择 Amazon S3 V2 作为来源类型
  6. 选择 Trend Micro Vision One 活动作为日志类型
  7. 点击下一步
  8. 为以下输入参数指定值:

    • S3 URI:存储桶 URI(格式应为:s3://log-bucket-name/)。 请替换以下内容:
      • log-bucket-name:存储桶的名称。。
    • 源删除选项:选择永不删除文件。S3 存储桶中的数据在被清除之前会保留 7 天。
    • 文件存在时间上限:包含在过去指定天数内修改的文件。默认值为 180 天。
    • 访问密钥 ID:有权访问 S3 存储桶的用户访问密钥。
    • 私有访问密钥:有权访问 S3 存储桶的用户私有密钥。
  9. 点击下一步

  10. 最终确定界面中查看新的 Feed 配置,然后点击提交

UDM 映射表

日志字段 UDM 映射 逻辑
fileName about.file.names 已合并
_field additional.fields 已合并
apiVersion_label additional.fields 已合并
appLabel_label additional.fields 已合并
app_label additional.fields 已合并
application_label additional.fields 已合并
attachmentFileSizes_label additional.fields 已合并
attachmentMd5_label additional.fields 已合并
attachmentSha1_label additional.fields 已合并
attachmentSha256_label additional.fields 已合并
awsRegion_label additional.fields 已合并
clusterId_label additional.fields 已合并
clusterName_label additional.fields 已合并
eventID_label additional.fields 已合并
groupId_label additional.fields 已合并
id_label additional.fields 已合并
idpId_label additional.fields 已合并
k8sNamespace_label additional.fields 已合并
name_label additional.fields 已合并
productCode_label additional.fields 已合并
recipientAccountId_label additional.fields 已合并
spamResultHeader_label additional.fields 已合并
spamRidHeader_label additional.fields 已合并
vpcEndpointId_label additional.fields 已合并
remarks metadata.description 直接映射
eventTime metadata.event_timestamp 解析为 UNIX_MS
logReceivedTime metadata.event_timestamp 解析为 UNIX_MS
objectFileModifiedTime metadata.event_timestamp 解析为 UNIX_MS
objectFirstSeen metadata.event_timestamp 解析为 UNIX_MS
objectLastSeen metadata.event_timestamp 解析为 UNIX_MS
srcFileModifiedTime metadata.event_timestamp 解析为 UNIX_MS
srcFirstSeen metadata.event_timestamp 解析为 UNIX_MS
srcLastSeen metadata.event_timestamp 解析为 UNIX_MS
has_email metadata.event_type 已映射:trueEMAIL_TRANSACTION
has_network metadata.event_type 已映射:trueNETWORK_UNCATEGORIZED
has_principal metadata.event_type 已映射:trueFILE_UNCATEGORIZEDtrueNETWORK_CONNECTIONtrueSTATUS_UPDATE
has_process metadata.event_type 已映射:truePROCESS_UNCATEGORIZED
has_registry metadata.event_type 已映射:trueREGISTRY_UNCATEGORIZED
has_user metadata.event_type 已映射:trueUSER_UNCATEGORIZED
eventName metadata.product_event_type 直接映射
eventType metadata.product_event_type 直接映射
scanType metadata.product_event_type 直接映射
msgUuid metadata.product_log_id 直接映射
uuid metadata.product_log_id 直接映射
idpName metadata.product_name 直接映射
pname metadata.product_name 直接映射
pver metadata.product_version 直接映射
protocol network.application_protocol 直接映射
version network.application_protocol_version 直接映射
mailBccAddr network.email.bcc 已合并
mailccAddr network.email.cc 已合并
mailFromAddresses.0 network.email.from 直接映射
suser network.email.from 直接映射
mailMsgId network.email.mail_id 直接映射
msgId network.email.mail_id 直接映射
mailReplyToAddr network.email.reply_to 直接映射
mailMsgSubject network.email.subject 已合并
duser network.email.to 已合并
mailToAddr network.email.to 已合并
requestMethod network.http.method 直接映射
userAgent network.http.parsed_user_agent 直接映射
httpReferer network.http.referral_url 直接映射
userAgent network.http.user_agent 直接映射
responseSize network.received_bytes 直接映射
requestSize network.sent_bytes 直接映射
duration network.session_duration.seconds 直接映射
tlsSelectedCipher network.tls.cipher 直接映射
clientTls network.tls.version 直接映射
downstreamTls network.tls.version 直接映射
clientId principal.asset.asset_id 直接映射
deviceGUID principal.asset.asset_id 直接映射
endpointGuid principal.asset.asset_id 直接映射
clientDisplayName_label principal.asset.attribute.labels 已合并
clientOS_label principal.asset.attribute.labels 已合并
hardware principal.asset.hardware 已合并
endpointHostName principal.asset.hostname 直接映射
sender principal.asset.hostname 直接映射
ipAddress principal.asset.ip 已合并
srcIp principal.asset.ip 已合并
tmpIp principal.asset.ip 已合并
tmpMac principal.asset.mac 已合并
hostName principal.domain.name 直接映射
endpointHostName principal.hostname 直接映射
sender principal.hostname 直接映射
sourceIPAddress principal.ip 已合并
srcIp principal.ip 已合并
tmpIp principal.ip 已合并
ip_location principal.ip_location 已合并
srcLocation principal.location.country_or_region 直接映射
tmpMac principal.mac 已合并
processFilePath principal.process.file.full_path 直接映射
processFileHashMd5 principal.process.file.md5 直接映射
processName principal.process.file.names 已合并
processFileHashSha1 principal.process.file.sha1 直接映射
processFileHashSha256 principal.process.file.sha256 直接映射
parentCmd principal.process.parent_process.command_line 直接映射
parentFilePath principal.process.parent_process.file.full_path 直接映射
parentFileHashMd5 principal.process.parent_process.file.md5 直接映射
parentName principal.process.parent_process.file.names 已合并
parentFileHashSha1 principal.process.parent_process.file.sha1 直接映射
parentFileHashSha256 principal.process.parent_process.file.sha256 直接映射
parentPid principal.process.parent_process.pid 直接映射
uuid_label principal.resource.attribute.labels 已合并
userId principal.user.product_object_id 直接映射
userDisplayName principal.user.user_display_name 直接映射
objectUser principal.user.userid 直接映射
principalName principal.user.userid 直接映射
mailbox security_result.about.email 直接映射
act security_result.action_details 直接映射
urlCat security_result.category_details 已合并
_field security_result.detection_fields 已合并
action_label security_result.detection_fields 已合并
detectionType_label security_result.detection_fields 已合并
eventSourceType_label security_result.detection_fields 已合并
key security_result.detection_fields 已映射:"failedHTTPSInspection", "serverProtocol", "score"_field
mailDirection_label security_result.detection_fields 已合并
type_label security_result.detection_fields 已合并
mailScore security_result.risk_score 已重命名/已映射
policyUuid security_result.rule_id 直接映射
ruleId security_result.rule_id 直接映射
ruleUuid security_result.rule_id 直接映射
ruleName security_result.rule_name 直接映射
ruleType security_result.rule_type 直接映射
filterRiskLevel security_result.severity_details 直接映射
deliveryStatus security_result.summary 直接映射
malName security_result.threat_name 直接映射
source src 已重命名/已映射
target_udm target 已重命名/已映射
不适用 metadata.event_type 常量:GENERIC_EVENT
不适用 metadata.product_name 常量:TREND VISION ONE ACTIVITY
不适用 metadata.vendor_name 常量:TREND VISION ONE ACTIVITY
不适用 network.http.parsed_user_agent 常量:parseduseragent
不适用 network.http.response_code 常量:respCode
不适用 principal.process.integrity_level_rid 常量:integrityLevel
不适用 principal.process.parent_process.integrity_level_rid 常量:parentIntegrityLevel
不适用 principal.process.pid 常量:processPid

更新日志

查看相应解析器的更改日志

需要更多帮助?获得社区成员和 Google SecOps 专业人士的解答。