收集 Trend Micro Vision One Detections 記錄
支援的國家/地區:
Google SecOps
SIEM
本文說明如何使用 AWS S3,將 Trend Micro Vision One Detections 記錄檔擷取至 Google Security Operations。剖析器會將 Trend Micro Vision One Detections 記錄從 JSON 格式轉換為統一資料模型 (UDM)。
事前準備
請確認您已完成下列事前準備事項:
- Google SecOps 執行個體
- Trend Micro Vision One 的特殊存取權
在 Trend Micro Vision One 上設定記錄功能
- 登入 Trend Micro Vision One 控制台。
- 依序前往「Workflow and Automation」>「Third-Party Integration」。
- 按一下「Google Security Operations SIEM」。
- 在「存取金鑰」下方,按一下「產生金鑰」。
- 複製並儲存存取金鑰 ID 和私密存取金鑰。
- 在「資料移轉」下方,啟用「偵測資料」旁的切換按鈕。
- 系統會產生 S3 URI,並開始將資料傳送至對應的 S3 bucket。
- 複製並儲存 S3 網址,以備日後使用。
設定動態饋給
如要設定動態饋給,請按照下列步驟操作:
- 依序前往「SIEM 設定」>「動態饋給」。
- 按一下「新增動態消息」。
- 在下一個頁面中,按一下「設定單一動態饋給」。
- 在「動態饋給名稱」欄位中輸入動態饋給名稱 (例如
Trend Micro Vision One Detections Logs)。 - 選取「Amazon S3 V2」做為「來源類型」。
- 選取「Trend Micro Vision One Detections」做為「記錄類型」。
- 點選「下一步」。
指定下列輸入參數的值:
- S3 URI:值區 URI (格式應為
s3://log-bucket-name/)。 請替換下列項目:log-bucket-name:值區名稱。
- 來源刪除選項:選取「一律不刪除檔案」。S3 bucket 中的資料會在清除前保留 7 天。
- 檔案存在時間上限:包含在過去天數內修改的檔案。預設值為 180 天。
- 存取金鑰 ID:具有 S3 值區存取權的使用者存取金鑰。
- 存取密鑰:具有 S3 bucket 存取權的使用者私密金鑰。
- S3 URI:值區 URI (格式應為
點選「下一步」。
在「Finalize」(完成) 畫面中檢查新的動態饋給設定,然後按一下「Submit」(提交)。
UDM 對應表
| 記錄欄位 | UDM 對應 | 邏輯 |
|---|---|---|
about1 |
about |
已合併 |
about2 |
about |
已合併 |
about3 |
about |
已合併 |
about4 |
about |
已合併 |
attachmentFileHashMd5 |
about.file.md5 |
直接對應 |
attachmentFileType |
about.file.mime_type |
直接對應 |
fileName |
about.file.names |
已合併 |
attachmentFileHash |
about.file.sha1 |
直接對應 |
attachmentFileHashSha1 |
about.file.sha1 |
直接對應 |
attachmentFileHashSha256 |
about.file.sha256 |
直接對應 |
process_cmd |
about.process.command_line |
直接對應 |
actResult_label_1 |
additional.fields |
已合併 |
aggregatedCount_label |
additional.fields |
已合併 |
aptCampaigns_label |
additional.fields |
已合併 |
attachmentFileTlshes_label |
additional.fields |
已合併 |
blocking_label |
additional.fields |
已合併 |
eventID_label |
additional.fields |
已合併 |
eventSubId_label |
additional.fields |
已合併 |
field1 |
additional.fields |
已合併 |
groupIdCorrValues_label |
additional.fields |
已合併 |
highlightedRequest_label |
additional.fields |
已合併 |
integrity_level_label |
additional.fields |
已合併 |
level_label |
additional.fields |
已合併 |
mailMsgDirection_label |
additional.fields |
已合併 |
process_hash_id_label |
additional.fields |
已合併 |
process_launch_time_label |
additional.fields |
已合併 |
process_name_label |
additional.fields |
已合併 |
process_signer_label |
additional.fields |
已合併 |
process_signer_valid_label |
additional.fields |
已合併 |
process_sub_true_type_label |
additional.fields |
已合併 |
process_true_type_label |
additional.fields |
已合併 |
rating_label |
additional.fields |
已合併 |
requests_label |
additional.fields |
已合併 |
description |
metadata.description |
直接對應 |
eventTime |
metadata.event_timestamp |
已剖析為 UNIX_MS |
logReceivedTime |
metadata.event_timestamp |
已剖析為 UNIX_MS |
objectLastModifyTime |
metadata.event_timestamp |
已剖析為 TIMESTAMP |
has_principal |
metadata.event_type |
已對應:true → USER_UNCATEGORIZED |
has_principal_mid |
metadata.event_type |
已對應:true → NETWORK_CONNECTION、true → STATUS_UPDATE |
eventName |
metadata.product_event_type |
直接對應 |
eventType |
metadata.product_event_type |
直接對應 |
msgUuid |
metadata.product_log_id |
直接對應 |
uuid |
metadata.product_log_id |
直接對應 |
pname |
metadata.product_name |
直接對應 |
pver |
metadata.product_version |
直接對應 |
app |
network.application_protocol |
直接對應 |
direction |
network.direction |
已對應:OUTGOING → OUTBOUND |
suser.0 |
network.email.from |
直接對應 |
msgId |
network.email.mail_id |
直接對應 |
highlightMailMsgSubject |
network.email.subject |
已合併 |
mailMsgSubject |
network.email.subject |
已合併 |
tmpUser |
network.email.to |
已合併 |
requestMethod |
network.http.method |
直接對應 |
httpReferer |
network.http.referral_url |
直接對應 |
mailSmtpFromAddresses.0 |
network.smtp.mail_from |
直接對應 |
addr |
network.smtp.rcpt_to |
已合併 |
computerDomain |
principal.administrative_domain |
直接對應 |
deviceGUID |
principal.asset.asset_id |
直接對應 |
endpointGUID |
principal.asset.asset_id |
直接對應 |
mDeviceGUID |
principal.asset.asset_id |
直接對應 |
peerEndpointGUID |
principal.asset.asset_id |
直接對應 |
hardware |
principal.asset.hardware |
已合併 |
dvchost |
principal.asset.hostname |
直接對應 |
endpointHostName |
principal.asset.hostname |
直接對應 |
tmpIp |
principal.asset.ip |
已合併 |
deviceMacAddress |
principal.asset.mac |
已合併 |
endpointMacAddress |
principal.asset.mac |
已合併 |
domainName |
principal.asset.network_domain |
直接對應 |
vul |
principal.asset.vulnerabilities |
已合併 |
domainName |
principal.domain.name |
直接對應 |
hostName |
principal.domain.name |
直接對應 |
userDomain |
principal.domain.name |
直接對應 |
groupId |
principal.group.product_object_id |
直接對應 |
dvchost |
principal.hostname |
直接對應 |
endpointHostName |
principal.hostname |
直接對應 |
peerHost |
principal.hostname |
直接對應 |
peerIpAddr |
principal.ip |
已合併 |
srcIp |
principal.ip |
已合併 |
tmpIp |
principal.ip |
已合併 |
deviceMacAddress |
principal.mac |
已合併 |
endpointMacAddress |
principal.mac |
已合併 |
processCmd |
principal.process.command_line |
直接對應 |
processFilePath |
principal.process.file.full_path |
直接對應 |
processImagePath |
principal.process.file.full_path |
直接對應 |
processFileHashMd5 |
principal.process.file.md5 |
直接對應 |
processName |
principal.process.file.names |
已合併 |
processFileHashSha1 |
principal.process.file.sha1 |
直接對應 |
processFileHashSha256 |
principal.process.file.sha256 |
直接對應 |
parentCmd |
principal.process.parent_process.command_line |
直接對應 |
parentFilePath |
principal.process.parent_process.file.full_path |
直接對應 |
parentFileHashMd5 |
principal.process.parent_process.file.md5 |
直接對應 |
parentName |
principal.process.parent_process.file.names |
已合併 |
parentFileHashSha1 |
principal.process.parent_process.file.sha1 |
直接對應 |
parentFileHashSha256 |
principal.process.parent_process.file.sha256 |
直接對應 |
parentPid |
principal.process.parent_process.pid |
直接對應 |
processPid |
principal.process.pid |
直接對應 |
suser_label |
principal.resource.attribute.labels |
已合併 |
uuid_label |
principal.resource.attribute.labels |
已合併 |
userDepartment |
principal.user.department |
已合併 |
tmpUser1 |
principal.user.email_addresses |
已合併 |
logonUsers.0 |
principal.user.userid |
直接對應 |
objectUser |
principal.user.userid |
直接對應 |
principalName |
principal.user.userid |
直接對應 |
suid |
principal.user.userid |
直接對應 |
mailbox |
security_result.about.email |
直接對應 |
security_result_action |
security_result.action |
已合併 |
act.0 |
security_result.action_details |
直接對應 |
tactics |
security_result.attack_details.tactics |
已合併 |
techniques |
security_result.attack_details.techniques |
已合併 |
category |
security_result.category_details |
已合併 |
index |
security_result.category_details |
已合併 |
tag |
security_result.category_details |
已合併 |
actResult_label |
security_result.detection_fields |
已合併 |
cccaDetectionSource_label |
security_result.detection_fields |
已合併 |
cccaRiskLevel_label |
security_result.detection_fields |
已合併 |
field1 |
security_result.detection_fields |
已合併 |
key |
security_result.detection_fields |
已對應:`"engineOperation","engType","detectionAggressivenessLevel","patVer","channel","thre... |
mailbox_label |
security_result.detection_fields |
已合併 |
matchedFilter_id_label |
security_result.detection_fields |
已合併 |
matchedFilter_name_label |
security_result.detection_fields |
已合併 |
matchedRules_id_label |
security_result.detection_fields |
已合併 |
matchedRules_name_label |
security_result.detection_fields |
已合併 |
matchedRules_threatType_label |
security_result.detection_fields |
已合併 |
riskType_label |
security_result.detection_fields |
已合併 |
subRuleId_label |
security_result.detection_fields |
已合併 |
score |
security_result.risk_score |
已重新命名/對應 |
matchedRule.id |
security_result.rule_id |
直接對應 |
ruleId |
security_result.rule_id |
直接對應 |
matchedRule.name |
security_result.rule_name |
直接對應 |
ruleName |
security_result.rule_name |
直接對應 |
ruleType |
security_result.rule_type |
直接對應 |
ruleVer |
security_result.rule_version |
直接對應 |
filterRiskLevel |
security_result.severity_details |
直接對應 |
malName |
security_result.threat_name |
直接對應 |
matchedRule.threatType |
security_result.threat_name |
直接對應 |
mergethreatNames |
security_result.threat_name |
直接對應 |
threatName |
security_result.threat_name |
直接對應 |
source |
src |
已重新命名/對應 |
interestedHost |
target.asset.hostname |
直接對應 |
malDst |
target.asset.hostname |
直接對應 |
tmpIp |
target.asset.ip |
已合併 |
requestBase |
target.domain.name |
直接對應 |
objectFilePath |
target.file.full_path |
直接對應 |
objectFileHashMd5 |
target.file.md5 |
直接對應 |
objectFileName |
target.file.names |
已合併 |
objectFileHashSha1 |
target.file.sha1 |
直接對應 |
objectFileHashSha256 |
target.file.sha256 |
直接對應 |
dstGroup |
target.group.group_display_name |
直接對應 |
dhost |
target.hostname |
直接對應 |
interestedHost |
target.hostname |
直接對應 |
malDst |
target.hostname |
直接對應 |
dstIp |
target.ip |
已合併 |
objectIp |
target.ip |
已合併 |
tmpIp |
target.ip |
已合併 |
dmac |
target.mac |
已合併 |
dOSName |
target.platform_version |
直接對應 |
objectCmd |
target.process.command_line |
直接對應 |
objectTargetProcess |
target.process.file.full_path |
直接對應 |
objectPid |
target.process.pid |
直接對應 |
objectRegistryKeyHandle |
target.registry.registry_key |
直接對應 |
objectRegistryData |
target.registry.registry_value_data |
直接對應 |
objectRegistryValue |
target.registry.registry_value_name |
直接對應 |
tmpUser_label |
target.resource.attribute.labels |
已合併 |
request |
target.url |
直接對應 |
objectUser |
target.user.userid |
直接對應 |
samUser |
target.user.userid |
直接對應 |
| 不適用 | about.file.size |
常數:attachmentFileSize |
| 不適用 | metadata.event_type |
常數:GENERIC_EVENT |
| 不適用 | metadata.product_name |
常數:TREND VISION ONE DETECTIONS |
| 不適用 | metadata.vendor_name |
常數:TREND VISION ONE DETECTIONS |
| 不適用 | network.direction |
常數:OUTBOUND |
| 不適用 | network.http.response_code |
常數:respCode |
| 不適用 | principal.process.integrity_level_rid |
常數:integrityLevel |
| 不適用 | principal.process.parent_process.integrity_level_rid |
常數:parentIntegrityLevel |
| 不適用 | target.port |
常數:dpt |
變更記錄
還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。