收集 Trend Micro Vision One Workbench 日志

支持的平台:

本文档介绍了如何使用 AWS S3 将 Trend Micro Vision One Workbench 日志注入到 Google Security Operations。解析器会将 Trend Micro Vision One Workbench 日志从 JSON 格式转换为统一数据模型 (UDM)。

准备工作

  • Google SecOps 实例
  • 对 Trend Micro Vision One 的特权访问权限

在 Trend Micro Vision One 上配置日志记录

  1. 登录 Trend Micro Vision One 控制台。
  2. 依次前往工作流和 Automation> 第三方集成
  3. 点击 Google Security Operations SIEM
  4. 访问密钥下,点击生成密钥
  5. 复制并保存访问密钥 ID私有访问密钥
  6. 数据转移下,启用工作台数据旁边的切换开关。
  7. 系统会生成 S3 URI,并开始将数据发送到相应的 S3 存储桶。
  8. 复制并保存 S3 网址,以供日后使用。

设置 Feed

如需配置 Feed,请按以下步骤操作:

  1. 依次前往 SIEM 设置 > Feed
  2. 点击添加新 Feed
  3. 在下一页上,点击配置单个 Feed
  4. Feed 名称字段中,输入 Feed 的名称(例如 Trend Micro Vision One Workbench Logs)。
  5. 选择 Amazon S3 V2 作为来源类型
  6. 选择 Trend Micro Vision One Workbench 作为日志类型
  7. 点击下一步
  8. 为以下输入参数指定值:

    • S3 URI:存储桶 URI(格式应为:s3://log-bucket-name/)。 请替换以下内容:
      • log-bucket-name:相应存储桶的名称。
    • 源删除选项:选择永不删除文件。S3 存储桶中的数据在被清除之前会保留 7 天。
    • 文件存在时间上限:包含在过去指定天数内修改的文件。默认值为 180 天。
    • 访问密钥 ID:有权访问 S3 存储桶的用户访问密钥。
    • 私有访问密钥:有权访问 S3 存储桶的用户私有密钥。
  9. 点击下一步

  10. 最终确定界面中查看新的 Feed 配置,然后点击提交

    UDM 映射表

日志字段 UDM 映射 逻辑
indicator_value about.file.full_path 直接映射
indicator_value about.url 直接映射
_field additional.fields 已合并
alertProvider_label additional.fields 已合并
eventSourceType_label additional.fields 已合并
hostId_label additional.fields 已合并
incidentId_label additional.fields 已合并
logKey_label additional.fields 已合并
model_label additional.fields 已合并
mpname_label additional.fields 已合并
mpver_label additional.fields 已合并
productCode_label additional.fields 已合并
rtDate_label additional.fields 已合并
description metadata.description 直接映射
createdDateTime metadata.event_timestamp 解析为 ISO8601
logReceivedTime metadata.event_timestamp 解析为 UNIX_MS
rt metadata.event_timestamp 解析为 ISO8601
updatedDateTime metadata.event_timestamp 解析为 ISO8601
fileOperation metadata.event_type 已映射:UpdatedFILE_MODIFICATION
has_principal metadata.event_type 映射:trueFILE_UNCATEGORIZEDtrueFILE_MODIFICATIONtrue → `PROCESS_UNCAT...
eventName metadata.product_event_type 直接映射
eventId metadata.product_log_id 直接映射
id metadata.product_log_id 直接映射
pname metadata.product_name 直接映射
pver metadata.product_version 直接映射
schemaVersion metadata.product_version 直接映射
indicator_value network.email.mail_id 直接映射
indicator.value network.email.subject 已合并
AccountDomain principal.administrative_domain 直接映射
domain principal.administrative_domain 直接映射
mDeviceGUID principal.asset.asset_id 直接映射
endpointHostName principal.asset.hostname 直接映射
entity.entityValue.name principal.asset.hostname 直接映射
entityValue_name principal.asset.ip 已合并
ip principal.asset.ip 已合并
src_ip principal.asset.ip 已合并
endpointHostName principal.hostname 直接映射
entity.entityValue.name principal.hostname 直接映射
entityValue_name principal.ip 已合并
ip principal.ip 已合并
src_ip principal.ip 已合并
indicator_value principal.process.command_line 直接映射
indicator_value principal.process.file.sha256 直接映射
indicator_value principal.process.parent_process.command_line 直接映射
_field principal.resource.attribute.labels 已合并
endpointGUID_label principal.resource.attribute.labels 已合并
entityId_label principal.resource.attribute.labels 已合并
entityValue_name_label principal.resource.attribute.labels 已合并
key principal.resource.attribute.labels 已映射:srchwvendor_field
managementScopeGroupId_label principal.resource.attribute.labels 已合并
managementScopeInstanceId_label principal.resource.attribute.labels 已合并
managementScopePartitionKey_label principal.resource.attribute.labels 已合并
senderGUID_label principal.resource.attribute.labels 已合并
uuid_label principal.resource.attribute.labels 已合并
entity.entityValue principal.user.email_addresses 已合并
indicator_value principal.user.email_addresses 已合并
domain_value principal.user.user_display_name 直接映射
AccountName principal.user.userid 直接映射
entity_entityValue principal.user.userid 直接映射
indicator_value principal.user.userid 直接映射
suid principal.user.userid 直接映射
user_id_value principal.user.userid 直接映射
SecurityID principal.user.windows_sid 直接映射
sec security_result 已合并
sec_isEntity security_result 已合并
sec_res security_result 已合并
sec_wasEntity security_result 已合并
investigationResult security_result.about.investigation.comments 已合并
investigationStatus security_result.about.investigation.status 映射:NewNEWClosedCLOSEDOpenOPENReviewedREVIEWED
fileOperation security_result.action_details 直接映射
cat security_result.category_details 已合并
msg security_result.description 直接映射
LogonID_label security_result.detection_fields 已合并
_field security_result.detection_fields 已合并
access_right_label security_result.detection_fields 已合并
detectionType_label security_result.detection_fields 已合并
key security_result.detection_fields 已映射:"status", "auditid"_field
modelId_label security_result.detection_fields 已合并
modelType_label security_result.detection_fields 已合并
ownerIds_label security_result.detection_fields 已合并
prov_enance_label security_result.detection_fields 已合并
proven_ance_label security_result.detection_fields 已合并
relatedEntitie_label security_result.detection_fields 已合并
relatedIndicatorId_label security_result.detection_fields 已合并
status_label security_result.detection_fields 已合并
subRuleId_label security_result.detection_fields 已合并
subRuleName_label security_result.detection_fields 已合并
winEventId_label security_result.detection_fields 已合并
createdDateTime security_result.first_discovered_time 已重命名/已映射
updatedDateTime security_result.last_updated_time 已重命名/已映射
Score security_result.risk_score 已重命名/已映射
score security_result.risk_score 已重命名/已映射
ruleId security_result.rule_id 直接映射
ruleName security_result.rule_name 直接映射
severity security_result.severity_details 直接映射
workbenchLink security_result.url_back_to_product 已重命名/已映射
filePathName target.file.full_path 直接映射
fullPath target.file.full_path 直接映射
file target.file.names 已合并
indicator_value target.process.command_line 直接映射
processName target.process.file.full_path 直接映射
TarAccountName target.user.userid 直接映射
duser.0 target.user.userid 直接映射
TarAccountName target.user.windows_sid 直接映射
不适用 metadata.event_type 常量:GENERIC_EVENT
不适用 metadata.product_name 常量:TRENDMICRO VISION ONE WORKBENCH
不适用 metadata.vendor_name 常量:TRENDMICRO VISION ONE WORKBENCH
不适用 security_result.about.investigation.status 常量:NEW
不适用 security_result.severity 常量:CRITICAL

更新日志

查看相应解析器的更改日志

需要更多帮助?获得社区成员和 Google SecOps 专业人士的解答。