收集 Trend Micro Vision One Workbench 日志
支持的平台:
Google SecOps
SIEM
本文档介绍了如何使用 AWS S3 将 Trend Micro Vision One Workbench 日志注入到 Google Security Operations。解析器会将 Trend Micro Vision One Workbench 日志从 JSON 格式转换为统一数据模型 (UDM)。
准备工作
- Google SecOps 实例
- 对 Trend Micro Vision One 的特权访问权限
在 Trend Micro Vision One 上配置日志记录
- 登录 Trend Micro Vision One 控制台。
- 依次前往工作流和 Automation> 第三方集成。
- 点击 Google Security Operations SIEM。
- 在访问密钥下,点击生成密钥。
- 复制并保存访问密钥 ID 和私有访问密钥。
- 在数据转移下,启用工作台数据旁边的切换开关。
- 系统会生成 S3 URI,并开始将数据发送到相应的 S3 存储桶。
- 复制并保存 S3 网址,以供日后使用。
设置 Feed
如需配置 Feed,请按以下步骤操作:
- 依次前往 SIEM 设置 > Feed。
- 点击添加新 Feed。
- 在下一页上,点击配置单个 Feed。
- 在 Feed 名称字段中,输入 Feed 的名称(例如
Trend Micro Vision One Workbench Logs)。 - 选择 Amazon S3 V2 作为来源类型。
- 选择 Trend Micro Vision One Workbench 作为日志类型。
- 点击下一步。
为以下输入参数指定值:
- S3 URI:存储桶 URI(格式应为:
s3://log-bucket-name/)。 请替换以下内容:log-bucket-name:相应存储桶的名称。
- 源删除选项:选择永不删除文件。S3 存储桶中的数据在被清除之前会保留 7 天。
- 文件存在时间上限:包含在过去指定天数内修改的文件。默认值为 180 天。
- 访问密钥 ID:有权访问 S3 存储桶的用户访问密钥。
- 私有访问密钥:有权访问 S3 存储桶的用户私有密钥。
- S3 URI:存储桶 URI(格式应为:
点击下一步。
在最终确定界面中查看新的 Feed 配置,然后点击提交。
UDM 映射表
| 日志字段 | UDM 映射 | 逻辑 |
|---|---|---|
indicator_value |
about.file.full_path |
直接映射 |
indicator_value |
about.url |
直接映射 |
_field |
additional.fields |
已合并 |
alertProvider_label |
additional.fields |
已合并 |
eventSourceType_label |
additional.fields |
已合并 |
hostId_label |
additional.fields |
已合并 |
incidentId_label |
additional.fields |
已合并 |
logKey_label |
additional.fields |
已合并 |
model_label |
additional.fields |
已合并 |
mpname_label |
additional.fields |
已合并 |
mpver_label |
additional.fields |
已合并 |
productCode_label |
additional.fields |
已合并 |
rtDate_label |
additional.fields |
已合并 |
description |
metadata.description |
直接映射 |
createdDateTime |
metadata.event_timestamp |
解析为 ISO8601 |
logReceivedTime |
metadata.event_timestamp |
解析为 UNIX_MS |
rt |
metadata.event_timestamp |
解析为 ISO8601 |
updatedDateTime |
metadata.event_timestamp |
解析为 ISO8601 |
fileOperation |
metadata.event_type |
已映射:Updated → FILE_MODIFICATION |
has_principal |
metadata.event_type |
映射:true → FILE_UNCATEGORIZED、true → FILE_MODIFICATION、true → `PROCESS_UNCAT... |
eventName |
metadata.product_event_type |
直接映射 |
eventId |
metadata.product_log_id |
直接映射 |
id |
metadata.product_log_id |
直接映射 |
pname |
metadata.product_name |
直接映射 |
pver |
metadata.product_version |
直接映射 |
schemaVersion |
metadata.product_version |
直接映射 |
indicator_value |
network.email.mail_id |
直接映射 |
indicator.value |
network.email.subject |
已合并 |
AccountDomain |
principal.administrative_domain |
直接映射 |
domain |
principal.administrative_domain |
直接映射 |
mDeviceGUID |
principal.asset.asset_id |
直接映射 |
endpointHostName |
principal.asset.hostname |
直接映射 |
entity.entityValue.name |
principal.asset.hostname |
直接映射 |
entityValue_name |
principal.asset.ip |
已合并 |
ip |
principal.asset.ip |
已合并 |
src_ip |
principal.asset.ip |
已合并 |
endpointHostName |
principal.hostname |
直接映射 |
entity.entityValue.name |
principal.hostname |
直接映射 |
entityValue_name |
principal.ip |
已合并 |
ip |
principal.ip |
已合并 |
src_ip |
principal.ip |
已合并 |
indicator_value |
principal.process.command_line |
直接映射 |
indicator_value |
principal.process.file.sha256 |
直接映射 |
indicator_value |
principal.process.parent_process.command_line |
直接映射 |
_field |
principal.resource.attribute.labels |
已合并 |
endpointGUID_label |
principal.resource.attribute.labels |
已合并 |
entityId_label |
principal.resource.attribute.labels |
已合并 |
entityValue_name_label |
principal.resource.attribute.labels |
已合并 |
key |
principal.resource.attribute.labels |
已映射:srchwvendor → _field |
managementScopeGroupId_label |
principal.resource.attribute.labels |
已合并 |
managementScopeInstanceId_label |
principal.resource.attribute.labels |
已合并 |
managementScopePartitionKey_label |
principal.resource.attribute.labels |
已合并 |
senderGUID_label |
principal.resource.attribute.labels |
已合并 |
uuid_label |
principal.resource.attribute.labels |
已合并 |
entity.entityValue |
principal.user.email_addresses |
已合并 |
indicator_value |
principal.user.email_addresses |
已合并 |
domain_value |
principal.user.user_display_name |
直接映射 |
AccountName |
principal.user.userid |
直接映射 |
entity_entityValue |
principal.user.userid |
直接映射 |
indicator_value |
principal.user.userid |
直接映射 |
suid |
principal.user.userid |
直接映射 |
user_id_value |
principal.user.userid |
直接映射 |
SecurityID |
principal.user.windows_sid |
直接映射 |
sec |
security_result |
已合并 |
sec_isEntity |
security_result |
已合并 |
sec_res |
security_result |
已合并 |
sec_wasEntity |
security_result |
已合并 |
investigationResult |
security_result.about.investigation.comments |
已合并 |
investigationStatus |
security_result.about.investigation.status |
映射:New → NEW、Closed → CLOSED、Open → OPEN、Reviewed → REVIEWED |
fileOperation |
security_result.action_details |
直接映射 |
cat |
security_result.category_details |
已合并 |
msg |
security_result.description |
直接映射 |
LogonID_label |
security_result.detection_fields |
已合并 |
_field |
security_result.detection_fields |
已合并 |
access_right_label |
security_result.detection_fields |
已合并 |
detectionType_label |
security_result.detection_fields |
已合并 |
key |
security_result.detection_fields |
已映射:"status", "auditid" → _field |
modelId_label |
security_result.detection_fields |
已合并 |
modelType_label |
security_result.detection_fields |
已合并 |
ownerIds_label |
security_result.detection_fields |
已合并 |
prov_enance_label |
security_result.detection_fields |
已合并 |
proven_ance_label |
security_result.detection_fields |
已合并 |
relatedEntitie_label |
security_result.detection_fields |
已合并 |
relatedIndicatorId_label |
security_result.detection_fields |
已合并 |
status_label |
security_result.detection_fields |
已合并 |
subRuleId_label |
security_result.detection_fields |
已合并 |
subRuleName_label |
security_result.detection_fields |
已合并 |
winEventId_label |
security_result.detection_fields |
已合并 |
createdDateTime |
security_result.first_discovered_time |
已重命名/已映射 |
updatedDateTime |
security_result.last_updated_time |
已重命名/已映射 |
Score |
security_result.risk_score |
已重命名/已映射 |
score |
security_result.risk_score |
已重命名/已映射 |
ruleId |
security_result.rule_id |
直接映射 |
ruleName |
security_result.rule_name |
直接映射 |
severity |
security_result.severity_details |
直接映射 |
workbenchLink |
security_result.url_back_to_product |
已重命名/已映射 |
filePathName |
target.file.full_path |
直接映射 |
fullPath |
target.file.full_path |
直接映射 |
file |
target.file.names |
已合并 |
indicator_value |
target.process.command_line |
直接映射 |
processName |
target.process.file.full_path |
直接映射 |
TarAccountName |
target.user.userid |
直接映射 |
duser.0 |
target.user.userid |
直接映射 |
TarAccountName |
target.user.windows_sid |
直接映射 |
| 不适用 | metadata.event_type |
常量:GENERIC_EVENT |
| 不适用 | metadata.product_name |
常量:TRENDMICRO VISION ONE WORKBENCH |
| 不适用 | metadata.vendor_name |
常量:TRENDMICRO VISION ONE WORKBENCH |
| 不适用 | security_result.about.investigation.status |
常量:NEW |
| 不适用 | security_result.severity |
常量:CRITICAL |