收集 Trend Micro Vision One Detections 記錄

支援的國家/地區:

本文說明如何使用 AWS S3,將 Trend Micro Vision One Detections 記錄檔擷取至 Google Security Operations。剖析器會將 Trend Micro Vision One Detections 記錄從 JSON 格式轉換為統一資料模型 (UDM)。

事前準備

請確認您已完成下列事前準備事項:

  • Google SecOps 執行個體
  • Trend Micro Vision One 的特殊存取權

在 Trend Micro Vision One 上設定記錄功能

  1. 登入 Trend Micro Vision One 控制台。
  2. 依序前往「Workflow and Automation」>「Third-Party Integration」
  3. 按一下「Google Security Operations SIEM」
  4. 在「存取金鑰」下方,按一下「產生金鑰」
  5. 複製並儲存存取金鑰 ID私密存取金鑰
  6. 在「資料移轉」下方,啟用「偵測資料」旁的切換按鈕。
  7. 系統會產生 S3 URI,並開始將資料傳送至對應的 S3 bucket。
  8. 複製並儲存 S3 網址,以備日後使用。

設定動態饋給

如要設定動態饋給,請按照下列步驟操作:

  1. 依序前往「SIEM 設定」>「動態饋給」
  2. 按一下「新增動態消息」
  3. 在下一個頁面中,按一下「設定單一動態饋給」
  4. 在「動態饋給名稱」欄位中輸入動態饋給名稱 (例如 Trend Micro Vision One Detections Logs)。
  5. 選取「Amazon S3 V2」做為「來源類型」
  6. 選取「Trend Micro Vision One Detections」做為「記錄類型」
  7. 點選「下一步」
  8. 指定下列輸入參數的值:

    • S3 URI:值區 URI (格式應為 s3://log-bucket-name/)。 請替換下列項目:
      • log-bucket-name:值區名稱。
    • 來源刪除選項:選取「一律不刪除檔案」。S3 bucket 中的資料會在清除前保留 7 天。
    • 檔案存在時間上限:包含在過去天數內修改的檔案。預設值為 180 天。
    • 存取金鑰 ID:具有 S3 值區存取權的使用者存取金鑰。
    • 存取密鑰:具有 S3 bucket 存取權的使用者私密金鑰。
  9. 點選「下一步」

  10. 在「Finalize」(完成) 畫面中檢查新的動態饋給設定,然後按一下「Submit」(提交)

UDM 對應表

記錄欄位 UDM 對應 邏輯
about1 about 已合併
about2 about 已合併
about3 about 已合併
about4 about 已合併
attachmentFileHashMd5 about.file.md5 直接對應
attachmentFileType about.file.mime_type 直接對應
fileName about.file.names 已合併
attachmentFileHash about.file.sha1 直接對應
attachmentFileHashSha1 about.file.sha1 直接對應
attachmentFileHashSha256 about.file.sha256 直接對應
process_cmd about.process.command_line 直接對應
actResult_label_1 additional.fields 已合併
aggregatedCount_label additional.fields 已合併
aptCampaigns_label additional.fields 已合併
attachmentFileTlshes_label additional.fields 已合併
blocking_label additional.fields 已合併
eventID_label additional.fields 已合併
eventSubId_label additional.fields 已合併
field1 additional.fields 已合併
groupIdCorrValues_label additional.fields 已合併
highlightedRequest_label additional.fields 已合併
integrity_level_label additional.fields 已合併
level_label additional.fields 已合併
mailMsgDirection_label additional.fields 已合併
process_hash_id_label additional.fields 已合併
process_launch_time_label additional.fields 已合併
process_name_label additional.fields 已合併
process_signer_label additional.fields 已合併
process_signer_valid_label additional.fields 已合併
process_sub_true_type_label additional.fields 已合併
process_true_type_label additional.fields 已合併
rating_label additional.fields 已合併
requests_label additional.fields 已合併
description metadata.description 直接對應
eventTime metadata.event_timestamp 已剖析為 UNIX_MS
logReceivedTime metadata.event_timestamp 已剖析為 UNIX_MS
objectLastModifyTime metadata.event_timestamp 已剖析為 TIMESTAMP
has_principal metadata.event_type 已對應:trueUSER_UNCATEGORIZED
has_principal_mid metadata.event_type 已對應:trueNETWORK_CONNECTIONtrueSTATUS_UPDATE
eventName metadata.product_event_type 直接對應
eventType metadata.product_event_type 直接對應
msgUuid metadata.product_log_id 直接對應
uuid metadata.product_log_id 直接對應
pname metadata.product_name 直接對應
pver metadata.product_version 直接對應
app network.application_protocol 直接對應
direction network.direction 已對應:OUTGOINGOUTBOUND
suser.0 network.email.from 直接對應
msgId network.email.mail_id 直接對應
highlightMailMsgSubject network.email.subject 已合併
mailMsgSubject network.email.subject 已合併
tmpUser network.email.to 已合併
requestMethod network.http.method 直接對應
httpReferer network.http.referral_url 直接對應
mailSmtpFromAddresses.0 network.smtp.mail_from 直接對應
addr network.smtp.rcpt_to 已合併
computerDomain principal.administrative_domain 直接對應
deviceGUID principal.asset.asset_id 直接對應
endpointGUID principal.asset.asset_id 直接對應
mDeviceGUID principal.asset.asset_id 直接對應
peerEndpointGUID principal.asset.asset_id 直接對應
hardware principal.asset.hardware 已合併
dvchost principal.asset.hostname 直接對應
endpointHostName principal.asset.hostname 直接對應
tmpIp principal.asset.ip 已合併
deviceMacAddress principal.asset.mac 已合併
endpointMacAddress principal.asset.mac 已合併
domainName principal.asset.network_domain 直接對應
vul principal.asset.vulnerabilities 已合併
domainName principal.domain.name 直接對應
hostName principal.domain.name 直接對應
userDomain principal.domain.name 直接對應
groupId principal.group.product_object_id 直接對應
dvchost principal.hostname 直接對應
endpointHostName principal.hostname 直接對應
peerHost principal.hostname 直接對應
peerIpAddr principal.ip 已合併
srcIp principal.ip 已合併
tmpIp principal.ip 已合併
deviceMacAddress principal.mac 已合併
endpointMacAddress principal.mac 已合併
processCmd principal.process.command_line 直接對應
processFilePath principal.process.file.full_path 直接對應
processImagePath principal.process.file.full_path 直接對應
processFileHashMd5 principal.process.file.md5 直接對應
processName principal.process.file.names 已合併
processFileHashSha1 principal.process.file.sha1 直接對應
processFileHashSha256 principal.process.file.sha256 直接對應
parentCmd principal.process.parent_process.command_line 直接對應
parentFilePath principal.process.parent_process.file.full_path 直接對應
parentFileHashMd5 principal.process.parent_process.file.md5 直接對應
parentName principal.process.parent_process.file.names 已合併
parentFileHashSha1 principal.process.parent_process.file.sha1 直接對應
parentFileHashSha256 principal.process.parent_process.file.sha256 直接對應
parentPid principal.process.parent_process.pid 直接對應
processPid principal.process.pid 直接對應
suser_label principal.resource.attribute.labels 已合併
uuid_label principal.resource.attribute.labels 已合併
userDepartment principal.user.department 已合併
tmpUser1 principal.user.email_addresses 已合併
logonUsers.0 principal.user.userid 直接對應
objectUser principal.user.userid 直接對應
principalName principal.user.userid 直接對應
suid principal.user.userid 直接對應
mailbox security_result.about.email 直接對應
security_result_action security_result.action 已合併
act.0 security_result.action_details 直接對應
tactics security_result.attack_details.tactics 已合併
techniques security_result.attack_details.techniques 已合併
category security_result.category_details 已合併
index security_result.category_details 已合併
tag security_result.category_details 已合併
actResult_label security_result.detection_fields 已合併
cccaDetectionSource_label security_result.detection_fields 已合併
cccaRiskLevel_label security_result.detection_fields 已合併
field1 security_result.detection_fields 已合併
key security_result.detection_fields 已對應:`"engineOperation","engType","detectionAggressivenessLevel","patVer","channel","thre...
mailbox_label security_result.detection_fields 已合併
matchedFilter_id_label security_result.detection_fields 已合併
matchedFilter_name_label security_result.detection_fields 已合併
matchedRules_id_label security_result.detection_fields 已合併
matchedRules_name_label security_result.detection_fields 已合併
matchedRules_threatType_label security_result.detection_fields 已合併
riskType_label security_result.detection_fields 已合併
subRuleId_label security_result.detection_fields 已合併
score security_result.risk_score 已重新命名/對應
matchedRule.id security_result.rule_id 直接對應
ruleId security_result.rule_id 直接對應
matchedRule.name security_result.rule_name 直接對應
ruleName security_result.rule_name 直接對應
ruleType security_result.rule_type 直接對應
ruleVer security_result.rule_version 直接對應
filterRiskLevel security_result.severity_details 直接對應
malName security_result.threat_name 直接對應
matchedRule.threatType security_result.threat_name 直接對應
mergethreatNames security_result.threat_name 直接對應
threatName security_result.threat_name 直接對應
source src 已重新命名/對應
interestedHost target.asset.hostname 直接對應
malDst target.asset.hostname 直接對應
tmpIp target.asset.ip 已合併
requestBase target.domain.name 直接對應
objectFilePath target.file.full_path 直接對應
objectFileHashMd5 target.file.md5 直接對應
objectFileName target.file.names 已合併
objectFileHashSha1 target.file.sha1 直接對應
objectFileHashSha256 target.file.sha256 直接對應
dstGroup target.group.group_display_name 直接對應
dhost target.hostname 直接對應
interestedHost target.hostname 直接對應
malDst target.hostname 直接對應
dstIp target.ip 已合併
objectIp target.ip 已合併
tmpIp target.ip 已合併
dmac target.mac 已合併
dOSName target.platform_version 直接對應
objectCmd target.process.command_line 直接對應
objectTargetProcess target.process.file.full_path 直接對應
objectPid target.process.pid 直接對應
objectRegistryKeyHandle target.registry.registry_key 直接對應
objectRegistryData target.registry.registry_value_data 直接對應
objectRegistryValue target.registry.registry_value_name 直接對應
tmpUser_label target.resource.attribute.labels 已合併
request target.url 直接對應
objectUser target.user.userid 直接對應
samUser target.user.userid 直接對應
不適用 about.file.size 常數:attachmentFileSize
不適用 metadata.event_type 常數:GENERIC_EVENT
不適用 metadata.product_name 常數:TREND VISION ONE DETECTIONS
不適用 metadata.vendor_name 常數:TREND VISION ONE DETECTIONS
不適用 network.direction 常數:OUTBOUND
不適用 network.http.response_code 常數:respCode
不適用 principal.process.integrity_level_rid 常數:integrityLevel
不適用 principal.process.parent_process.integrity_level_rid 常數:parentIntegrityLevel
不適用 target.port 常數:dpt

變更記錄

查看這個剖析器的變更記錄

還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。