收集 Trend Micro Vision One 活动日志
支持的平台:
Google SecOps
SIEM
本文档介绍了如何使用 AWS S3 将 Trend Micro Vision One 活动日志注入到 Google Security Operations。解析器会将 Trend Micro Vision One 活动日志从 JSON 格式转换为统一数据模型 (UDM)。
准备工作
请确保满足以下前提条件:
- Google SecOps 实例
- 对 Trend Micro Vision One 的特权访问权限。
在 Trend Micro Vision One 上配置日志记录
- 登录 Trend Micro Vision One 控制台。
- 依次前往工作流和 Automation> 第三方集成。
- 点击 Google Security Operations SIEM。
- 在“访问密钥”下,点击生成密钥。
- 复制并保存访问密钥 ID 和私有访问密钥。
- 在“数据转移”下,启用“活动数据”旁边的切换开关。
- 系统会生成 S3 URI,并开始将数据发送到相应的 S3 存储桶。
- 复制 S3 URI 并将其保存在安全的位置。
- (可选):对于“事件”和“活动”数据,点击修改可修改数据范围(修改范围不会更改生成的 S3 URI)。
设置 Feed
如需配置 Feed,请按以下步骤操作:
- 依次前往 SIEM 设置 > Feed。
- 点击添加新 Feed。
- 在下一页上,点击配置单个 Feed。
- 在 Feed 名称字段中,输入 Feed 的名称(例如“Trend Micro Vision One 活动日志”)。
- 选择 Amazon S3 V2 作为来源类型。
- 选择 Trend Micro Vision One 活动作为日志类型。
- 点击下一步。
为以下输入参数指定值:
- S3 URI:存储桶 URI(格式应为:
s3://log-bucket-name/)。 请替换以下内容:log-bucket-name:存储桶的名称。。
- 源删除选项:选择永不删除文件。S3 存储桶中的数据在被清除之前会保留 7 天。
- 文件存在时间上限:包含在过去指定天数内修改的文件。默认值为 180 天。
- 访问密钥 ID:有权访问 S3 存储桶的用户访问密钥。
- 私有访问密钥:有权访问 S3 存储桶的用户私有密钥。
- S3 URI:存储桶 URI(格式应为:
点击下一步。
在最终确定界面中查看新的 Feed 配置,然后点击提交。
UDM 映射表
| 日志字段 | UDM 映射 | 逻辑 |
|---|---|---|
fileName |
about.file.names |
已合并 |
_field |
additional.fields |
已合并 |
apiVersion_label |
additional.fields |
已合并 |
appLabel_label |
additional.fields |
已合并 |
app_label |
additional.fields |
已合并 |
application_label |
additional.fields |
已合并 |
attachmentFileSizes_label |
additional.fields |
已合并 |
attachmentMd5_label |
additional.fields |
已合并 |
attachmentSha1_label |
additional.fields |
已合并 |
attachmentSha256_label |
additional.fields |
已合并 |
awsRegion_label |
additional.fields |
已合并 |
clusterId_label |
additional.fields |
已合并 |
clusterName_label |
additional.fields |
已合并 |
eventID_label |
additional.fields |
已合并 |
groupId_label |
additional.fields |
已合并 |
id_label |
additional.fields |
已合并 |
idpId_label |
additional.fields |
已合并 |
k8sNamespace_label |
additional.fields |
已合并 |
name_label |
additional.fields |
已合并 |
productCode_label |
additional.fields |
已合并 |
recipientAccountId_label |
additional.fields |
已合并 |
spamResultHeader_label |
additional.fields |
已合并 |
spamRidHeader_label |
additional.fields |
已合并 |
vpcEndpointId_label |
additional.fields |
已合并 |
remarks |
metadata.description |
直接映射 |
eventTime |
metadata.event_timestamp |
解析为 UNIX_MS |
logReceivedTime |
metadata.event_timestamp |
解析为 UNIX_MS |
objectFileModifiedTime |
metadata.event_timestamp |
解析为 UNIX_MS |
objectFirstSeen |
metadata.event_timestamp |
解析为 UNIX_MS |
objectLastSeen |
metadata.event_timestamp |
解析为 UNIX_MS |
srcFileModifiedTime |
metadata.event_timestamp |
解析为 UNIX_MS |
srcFirstSeen |
metadata.event_timestamp |
解析为 UNIX_MS |
srcLastSeen |
metadata.event_timestamp |
解析为 UNIX_MS |
has_email |
metadata.event_type |
已映射:true → EMAIL_TRANSACTION |
has_network |
metadata.event_type |
已映射:true → NETWORK_UNCATEGORIZED |
has_principal |
metadata.event_type |
已映射:true → FILE_UNCATEGORIZED、true → NETWORK_CONNECTION、true → STATUS_UPDATE |
has_process |
metadata.event_type |
已映射:true → PROCESS_UNCATEGORIZED |
has_registry |
metadata.event_type |
已映射:true → REGISTRY_UNCATEGORIZED |
has_user |
metadata.event_type |
已映射:true → USER_UNCATEGORIZED |
eventName |
metadata.product_event_type |
直接映射 |
eventType |
metadata.product_event_type |
直接映射 |
scanType |
metadata.product_event_type |
直接映射 |
msgUuid |
metadata.product_log_id |
直接映射 |
uuid |
metadata.product_log_id |
直接映射 |
idpName |
metadata.product_name |
直接映射 |
pname |
metadata.product_name |
直接映射 |
pver |
metadata.product_version |
直接映射 |
protocol |
network.application_protocol |
直接映射 |
version |
network.application_protocol_version |
直接映射 |
mailBccAddr |
network.email.bcc |
已合并 |
mailccAddr |
network.email.cc |
已合并 |
mailFromAddresses.0 |
network.email.from |
直接映射 |
suser |
network.email.from |
直接映射 |
mailMsgId |
network.email.mail_id |
直接映射 |
msgId |
network.email.mail_id |
直接映射 |
mailReplyToAddr |
network.email.reply_to |
直接映射 |
mailMsgSubject |
network.email.subject |
已合并 |
duser |
network.email.to |
已合并 |
mailToAddr |
network.email.to |
已合并 |
requestMethod |
network.http.method |
直接映射 |
userAgent |
network.http.parsed_user_agent |
直接映射 |
httpReferer |
network.http.referral_url |
直接映射 |
userAgent |
network.http.user_agent |
直接映射 |
responseSize |
network.received_bytes |
直接映射 |
requestSize |
network.sent_bytes |
直接映射 |
duration |
network.session_duration.seconds |
直接映射 |
tlsSelectedCipher |
network.tls.cipher |
直接映射 |
clientTls |
network.tls.version |
直接映射 |
downstreamTls |
network.tls.version |
直接映射 |
clientId |
principal.asset.asset_id |
直接映射 |
deviceGUID |
principal.asset.asset_id |
直接映射 |
endpointGuid |
principal.asset.asset_id |
直接映射 |
clientDisplayName_label |
principal.asset.attribute.labels |
已合并 |
clientOS_label |
principal.asset.attribute.labels |
已合并 |
hardware |
principal.asset.hardware |
已合并 |
endpointHostName |
principal.asset.hostname |
直接映射 |
sender |
principal.asset.hostname |
直接映射 |
ipAddress |
principal.asset.ip |
已合并 |
srcIp |
principal.asset.ip |
已合并 |
tmpIp |
principal.asset.ip |
已合并 |
tmpMac |
principal.asset.mac |
已合并 |
hostName |
principal.domain.name |
直接映射 |
endpointHostName |
principal.hostname |
直接映射 |
sender |
principal.hostname |
直接映射 |
sourceIPAddress |
principal.ip |
已合并 |
srcIp |
principal.ip |
已合并 |
tmpIp |
principal.ip |
已合并 |
ip_location |
principal.ip_location |
已合并 |
srcLocation |
principal.location.country_or_region |
直接映射 |
tmpMac |
principal.mac |
已合并 |
processFilePath |
principal.process.file.full_path |
直接映射 |
processFileHashMd5 |
principal.process.file.md5 |
直接映射 |
processName |
principal.process.file.names |
已合并 |
processFileHashSha1 |
principal.process.file.sha1 |
直接映射 |
processFileHashSha256 |
principal.process.file.sha256 |
直接映射 |
parentCmd |
principal.process.parent_process.command_line |
直接映射 |
parentFilePath |
principal.process.parent_process.file.full_path |
直接映射 |
parentFileHashMd5 |
principal.process.parent_process.file.md5 |
直接映射 |
parentName |
principal.process.parent_process.file.names |
已合并 |
parentFileHashSha1 |
principal.process.parent_process.file.sha1 |
直接映射 |
parentFileHashSha256 |
principal.process.parent_process.file.sha256 |
直接映射 |
parentPid |
principal.process.parent_process.pid |
直接映射 |
uuid_label |
principal.resource.attribute.labels |
已合并 |
userId |
principal.user.product_object_id |
直接映射 |
userDisplayName |
principal.user.user_display_name |
直接映射 |
objectUser |
principal.user.userid |
直接映射 |
principalName |
principal.user.userid |
直接映射 |
mailbox |
security_result.about.email |
直接映射 |
act |
security_result.action_details |
直接映射 |
urlCat |
security_result.category_details |
已合并 |
_field |
security_result.detection_fields |
已合并 |
action_label |
security_result.detection_fields |
已合并 |
detectionType_label |
security_result.detection_fields |
已合并 |
eventSourceType_label |
security_result.detection_fields |
已合并 |
key |
security_result.detection_fields |
已映射:"failedHTTPSInspection", "serverProtocol", "score" → _field |
mailDirection_label |
security_result.detection_fields |
已合并 |
type_label |
security_result.detection_fields |
已合并 |
mailScore |
security_result.risk_score |
已重命名/已映射 |
policyUuid |
security_result.rule_id |
直接映射 |
ruleId |
security_result.rule_id |
直接映射 |
ruleUuid |
security_result.rule_id |
直接映射 |
ruleName |
security_result.rule_name |
直接映射 |
ruleType |
security_result.rule_type |
直接映射 |
filterRiskLevel |
security_result.severity_details |
直接映射 |
deliveryStatus |
security_result.summary |
直接映射 |
malName |
security_result.threat_name |
直接映射 |
source |
src |
已重命名/已映射 |
target_udm |
target |
已重命名/已映射 |
| 不适用 | metadata.event_type |
常量:GENERIC_EVENT |
| 不适用 | metadata.product_name |
常量:TREND VISION ONE ACTIVITY |
| 不适用 | metadata.vendor_name |
常量:TREND VISION ONE ACTIVITY |
| 不适用 | network.http.parsed_user_agent |
常量:parseduseragent |
| 不适用 | network.http.response_code |
常量:respCode |
| 不适用 | principal.process.integrity_level_rid |
常量:integrityLevel |
| 不适用 | principal.process.parent_process.integrity_level_rid |
常量:parentIntegrityLevel |
| 不适用 | principal.process.pid |
常量:processPid |
更新日志
需要更多帮助?获得社区成员和 Google SecOps 专业人士的解答。