<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trend Micro Vision one integration in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trend-Micro-Vision-one-integration/m-p/624659#M78173</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352" target="_blank" rel="noopener"&gt;@gcusell&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DACAE6A5-B629-4B88-B22D-AF3643F7385D.jpeg" style="width: 1940px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23079i9A3A0E0B995B7603/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DACAE6A5-B629-4B88-B22D-AF3643F7385D.jpeg" alt="DACAE6A5-B629-4B88-B22D-AF3643F7385D.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0FC32321-D1B6-477C-8DA6-2D6A06C1771B.jpeg" style="width: 1539px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23080i9A21184D468E0787/image-size/medium?v=v2&amp;amp;px=400" role="button" title="0FC32321-D1B6-477C-8DA6-2D6A06C1771B.jpeg" alt="0FC32321-D1B6-477C-8DA6-2D6A06C1771B.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;Kindly need your suggestion for the below query.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attaching the snap for reference steps which im following.&lt;/P&gt;&lt;P&gt;Note&amp;nbsp;&lt;/P&gt;&lt;P&gt;I change the index name from default to xdr and also created one local file inside the xdr app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Dec 2022 14:00:36 GMT</pubDate>
    <dc:creator>debjit_k</dc:creator>
    <dc:date>2022-12-18T14:00:36Z</dc:date>
    <item>
      <title>Trend Micro Vision one integration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trend-Micro-Vision-one-integration/m-p/624492#M78172</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hope you are doing good!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically we want to integrate trend micro vision one solution in our splunk.&lt;/P&gt;&lt;P&gt;So before doing it I just wants to verify myself whether I know correct or not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. We need to install vision one application from splunk base.&lt;/P&gt;&lt;P&gt;2. After installation the app we need open that app and then click on configuration.&lt;/P&gt;&lt;P&gt;3. Then need to put url n authentication token.&lt;/P&gt;&lt;P&gt;4. Need to choose the log file type&lt;/P&gt;&lt;P&gt;Then we will start receiving the data? Kindly let me know if my understanding is correct or not..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If my above understand is correct I want to know 1 things&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to create UC because we are using some 3D party software to onboard data now how we can write query and all, sorry im sounding armature but this is my first time..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Debjit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 05:18:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trend-Micro-Vision-one-integration/m-p/624492#M78172</guid>
      <dc:creator>debjit_k</dc:creator>
      <dc:date>2022-12-16T05:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trend Micro Vision one integration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trend-Micro-Vision-one-integration/m-p/624659#M78173</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352" target="_blank" rel="noopener"&gt;@gcusell&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DACAE6A5-B629-4B88-B22D-AF3643F7385D.jpeg" style="width: 1940px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23079i9A3A0E0B995B7603/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DACAE6A5-B629-4B88-B22D-AF3643F7385D.jpeg" alt="DACAE6A5-B629-4B88-B22D-AF3643F7385D.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0FC32321-D1B6-477C-8DA6-2D6A06C1771B.jpeg" style="width: 1539px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23080i9A21184D468E0787/image-size/medium?v=v2&amp;amp;px=400" role="button" title="0FC32321-D1B6-477C-8DA6-2D6A06C1771B.jpeg" alt="0FC32321-D1B6-477C-8DA6-2D6A06C1771B.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;Kindly need your suggestion for the below query.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attaching the snap for reference steps which im following.&lt;/P&gt;&lt;P&gt;Note&amp;nbsp;&lt;/P&gt;&lt;P&gt;I change the index name from default to xdr and also created one local file inside the xdr app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Dec 2022 14:00:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trend-Micro-Vision-one-integration/m-p/624659#M78173</guid>
      <dc:creator>debjit_k</dc:creator>
      <dc:date>2022-12-18T14:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Trend Micro Vision one integration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trend-Micro-Vision-one-integration/m-p/624669#M78174</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243225"&gt;@debjit_k&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I never integrated Trend Micro Vision One, but if you followed the instructions and you have the data with the correct sourcetype and a correct parsing I can say that you're correct.&lt;/P&gt;&lt;P&gt;How to check that you're right? at first see if running a simpe search on data (index=xdr) you see data and you see all the fields (correct parsing).&lt;/P&gt;&lt;P&gt;If yes, you can see if the panels are populated.&lt;/P&gt;&lt;P&gt;If you don't see the data you have to debug it and it's difficoult to guide you, if parsing isn't correct, check the sourcetype and see in documentation or in props.conf what's the correct sourcetype to apply.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 18 Dec 2022 16:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Trend-Micro-Vision-one-integration/m-p/624669#M78174</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-18T16:50:43Z</dc:date>
    </item>
  </channel>
</rss>

