收集 Trend Micro Vision One 活動記錄

支援的國家/地區:

本文說明如何使用 AWS S3,將 Trend Micro Vision One 活動記錄檔擷取至 Google Security Operations。剖析器會將 Trend Micro Vision One 活動記錄從 JSON 格式轉換為統合式資料模型 (UDM)。

事前準備

請確認您已完成下列事前準備事項:

  • Google SecOps 執行個體
  • Trend Micro Vision One 的特殊存取權。

在 Trend Micro Vision One 上設定記錄功能

  1. 登入 Trend Micro Vision One 控制台。
  2. 依序前往「Workflow and Automation」>「Third-Party Integration」
  3. 按一下「Google Security Operations SIEM」
  4. 在「存取金鑰」下方,按一下「產生金鑰」
  5. 複製並儲存存取金鑰 ID私密存取金鑰
  6. 在「資料移轉」下方,啟用「活動資料」旁的切換鈕。
  7. 系統會產生 S3 URI,並開始將資料傳送至對應的 S3 值區。
  8. 複製 S3 URI 並儲存在安全的位置。
  9. (選用):如要修改事件和活動記錄資料的範圍,請按一下「編輯」 (修改範圍不會變更產生的 S3 URI)。

設定動態饋給

如要設定動態饋給,請按照下列步驟操作:

  1. 依序前往「SIEM 設定」>「動態饋給」
  2. 按一下「新增動態消息」
  3. 在下一個頁面中,按一下「設定單一動態饋給」
  4. 在「動態饋給名稱」欄位中,輸入動態饋給的名稱 (例如 Trend Micro Vision One 活動記錄)。
  5. 選取「Amazon S3 V2」做為「來源類型」
  6. 選取「Trend Micro Vision One Activity」做為「記錄類型」
  7. 點選「下一步」
  8. 指定下列輸入參數的值:

    • S3 URI:值區 URI (格式應為 s3://log-bucket-name/)。 請替換下列項目:
      • log-bucket-name:值區名稱。。
    • 來源刪除選項:選取「一律不刪除檔案」。S3 bucket 中的資料會在清除前保留 7 天。
    • 檔案存在時間上限:包含在過去天數內修改的檔案。預設值為 180 天。
    • 存取金鑰 ID:具有 S3 值區存取權的使用者存取金鑰。
    • 存取密鑰:具有 S3 bucket 存取權的使用者私密金鑰。
  9. 點選「下一步」

  10. 在「Finalize」(完成) 畫面中檢查新的動態饋給設定,然後按一下「Submit」(提交)

UDM 對應表

記錄欄位 UDM 對應 邏輯
fileName about.file.names 已合併
_field additional.fields 已合併
apiVersion_label additional.fields 已合併
appLabel_label additional.fields 已合併
app_label additional.fields 已合併
application_label additional.fields 已合併
attachmentFileSizes_label additional.fields 已合併
attachmentMd5_label additional.fields 已合併
attachmentSha1_label additional.fields 已合併
attachmentSha256_label additional.fields 已合併
awsRegion_label additional.fields 已合併
clusterId_label additional.fields 已合併
clusterName_label additional.fields 已合併
eventID_label additional.fields 已合併
groupId_label additional.fields 已合併
id_label additional.fields 已合併
idpId_label additional.fields 已合併
k8sNamespace_label additional.fields 已合併
name_label additional.fields 已合併
productCode_label additional.fields 已合併
recipientAccountId_label additional.fields 已合併
spamResultHeader_label additional.fields 已合併
spamRidHeader_label additional.fields 已合併
vpcEndpointId_label additional.fields 已合併
remarks metadata.description 直接對應
eventTime metadata.event_timestamp 已剖析為 UNIX_MS
logReceivedTime metadata.event_timestamp 已剖析為 UNIX_MS
objectFileModifiedTime metadata.event_timestamp 已剖析為 UNIX_MS
objectFirstSeen metadata.event_timestamp 已剖析為 UNIX_MS
objectLastSeen metadata.event_timestamp 已剖析為 UNIX_MS
srcFileModifiedTime metadata.event_timestamp 已剖析為 UNIX_MS
srcFirstSeen metadata.event_timestamp 已剖析為 UNIX_MS
srcLastSeen metadata.event_timestamp 已剖析為 UNIX_MS
has_email metadata.event_type 已對應:trueEMAIL_TRANSACTION
has_network metadata.event_type 已對應:trueNETWORK_UNCATEGORIZED
has_principal metadata.event_type 對應:trueFILE_UNCATEGORIZEDtrueNETWORK_CONNECTIONtrueSTATUS_UPDATE
has_process metadata.event_type 已對應:truePROCESS_UNCATEGORIZED
has_registry metadata.event_type 已對應:trueREGISTRY_UNCATEGORIZED
has_user metadata.event_type 已對應:trueUSER_UNCATEGORIZED
eventName metadata.product_event_type 直接對應
eventType metadata.product_event_type 直接對應
scanType metadata.product_event_type 直接對應
msgUuid metadata.product_log_id 直接對應
uuid metadata.product_log_id 直接對應
idpName metadata.product_name 直接對應
pname metadata.product_name 直接對應
pver metadata.product_version 直接對應
protocol network.application_protocol 直接對應
version network.application_protocol_version 直接對應
mailBccAddr network.email.bcc 已合併
mailccAddr network.email.cc 已合併
mailFromAddresses.0 network.email.from 直接對應
suser network.email.from 直接對應
mailMsgId network.email.mail_id 直接對應
msgId network.email.mail_id 直接對應
mailReplyToAddr network.email.reply_to 直接對應
mailMsgSubject network.email.subject 已合併
duser network.email.to 已合併
mailToAddr network.email.to 已合併
requestMethod network.http.method 直接對應
userAgent network.http.parsed_user_agent 直接對應
httpReferer network.http.referral_url 直接對應
userAgent network.http.user_agent 直接對應
responseSize network.received_bytes 直接對應
requestSize network.sent_bytes 直接對應
duration network.session_duration.seconds 直接對應
tlsSelectedCipher network.tls.cipher 直接對應
clientTls network.tls.version 直接對應
downstreamTls network.tls.version 直接對應
clientId principal.asset.asset_id 直接對應
deviceGUID principal.asset.asset_id 直接對應
endpointGuid principal.asset.asset_id 直接對應
clientDisplayName_label principal.asset.attribute.labels 已合併
clientOS_label principal.asset.attribute.labels 已合併
hardware principal.asset.hardware 已合併
endpointHostName principal.asset.hostname 直接對應
sender principal.asset.hostname 直接對應
ipAddress principal.asset.ip 已合併
srcIp principal.asset.ip 已合併
tmpIp principal.asset.ip 已合併
tmpMac principal.asset.mac 已合併
hostName principal.domain.name 直接對應
endpointHostName principal.hostname 直接對應
sender principal.hostname 直接對應
sourceIPAddress principal.ip 已合併
srcIp principal.ip 已合併
tmpIp principal.ip 已合併
ip_location principal.ip_location 已合併
srcLocation principal.location.country_or_region 直接對應
tmpMac principal.mac 已合併
processFilePath principal.process.file.full_path 直接對應
processFileHashMd5 principal.process.file.md5 直接對應
processName principal.process.file.names 已合併
processFileHashSha1 principal.process.file.sha1 直接對應
processFileHashSha256 principal.process.file.sha256 直接對應
parentCmd principal.process.parent_process.command_line 直接對應
parentFilePath principal.process.parent_process.file.full_path 直接對應
parentFileHashMd5 principal.process.parent_process.file.md5 直接對應
parentName principal.process.parent_process.file.names 已合併
parentFileHashSha1 principal.process.parent_process.file.sha1 直接對應
parentFileHashSha256 principal.process.parent_process.file.sha256 直接對應
parentPid principal.process.parent_process.pid 直接對應
uuid_label principal.resource.attribute.labels 已合併
userId principal.user.product_object_id 直接對應
userDisplayName principal.user.user_display_name 直接對應
objectUser principal.user.userid 直接對應
principalName principal.user.userid 直接對應
mailbox security_result.about.email 直接對應
act security_result.action_details 直接對應
urlCat security_result.category_details 已合併
_field security_result.detection_fields 已合併
action_label security_result.detection_fields 已合併
detectionType_label security_result.detection_fields 已合併
eventSourceType_label security_result.detection_fields 已合併
key security_result.detection_fields 已對應:"failedHTTPSInspection", "serverProtocol", "score"_field
mailDirection_label security_result.detection_fields 已合併
type_label security_result.detection_fields 已合併
mailScore security_result.risk_score 已重新命名/對應
policyUuid security_result.rule_id 直接對應
ruleId security_result.rule_id 直接對應
ruleUuid security_result.rule_id 直接對應
ruleName security_result.rule_name 直接對應
ruleType security_result.rule_type 直接對應
filterRiskLevel security_result.severity_details 直接對應
deliveryStatus security_result.summary 直接對應
malName security_result.threat_name 直接對應
source src 已重新命名/對應
target_udm target 已重新命名/對應
不適用 metadata.event_type 常數:GENERIC_EVENT
不適用 metadata.product_name 常數:TREND VISION ONE ACTIVITY
不適用 metadata.vendor_name 常數:TREND VISION ONE ACTIVITY
不適用 network.http.parsed_user_agent 常數:parseduseragent
不適用 network.http.response_code 常數:respCode
不適用 principal.process.integrity_level_rid 常數:integrityLevel
不適用 principal.process.parent_process.integrity_level_rid 常數:parentIntegrityLevel
不適用 principal.process.pid 常數:processPid

變更記錄

查看這個剖析器的變更記錄

還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。