All Apps and Add-ons

Trend Micro Vision one integration

debjit_k
Path Finder

Hi All,

Hope you are doing good!! 

Basically we want to integrate trend micro vision one solution in our splunk.

So before doing it I just wants to verify myself whether I know correct or not.

 

1. We need to install vision one application from splunk base.

2. After installation the app we need open that app and then click on configuration.

3. Then need to put url n authentication token.

4. Need to choose the log file type

Then we will start receiving the data? Kindly let me know if my understanding is correct or not..

 

If my above understand is correct I want to know 1 things 

How to create UC because we are using some 3D party software to onboard data now how we can write query and all, sorry im sounding armature but this is my first time.. 

 

Thanks

Debjit

 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @debjit_k,

I never integrated Trend Micro Vision One, but if you followed the instructions and you have the data with the correct sourcetype and a correct parsing I can say that you're correct.

How to check that you're right? at first see if running a simpe search on data (index=xdr) you see data and you see all the fields (correct parsing).

If yes, you can see if the panels are populated.

If you don't see the data you have to debug it and it's difficoult to guide you, if parsing isn't correct, check the sourcetype and see in documentation or in props.conf what's the correct sourcetype to apply.

Ciao.

Giuseppe

debjit_k
Path Finder

Hi @gcusell,

DACAE6A5-B629-4B88-B22D-AF3643F7385D.jpeg

0FC32321-D1B6-477C-8DA6-2D6A06C1771B.jpeg

  

Kindly need your suggestion for the below query. 

Attaching the snap for reference steps which im following.

Note 

I change the index name from default to xdr and also created one local file inside the xdr app.

 

Thanks 

0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...