IBM Security QRadar

 View Only
  • 1.  TrendMicro VisionOne App

    Posted Tue January 31, 2023 11:56 AM
    Hello,
    I installed TrendMicro VisionOne app (Version 1.1.1) on Qradar to collect events from two different TrendMicro tenants: our Qradar (Version 7.5.0 up3) is multi-tenanted, two separate customers want to integrate logs from their TrendMicro SaaS platforms (so, they do not have on-prem console).
    I created two separate instances of the app to configure each of them with the appropriate API tokens: we can successfully pull the logs from TrendMicro platforms, but they are both ingested into one single (auto-discovered) log source, and most important, they are collected under "Default Domain" instead of the two separate customer domains associated to each tenant.
    We tried several operations, including opening a case to TrendMicro support but nothing has fixed the issue..has someone been able to integrate two instances of VisionOne and send each logs to the appropriate event collector\domain on Qradar?

    ------------------------------
    Davide Salardi
    ------------------------------


  • 2.  RE: TrendMicro VisionOne App

    Posted Wed February 01, 2023 06:38 AM

    I did not implement this particular log source type yet, but wondering if there's  any content in the payload that could be used to distinguish the tenants? Would it be possible to use the custom property matching to direct them to intended domains (like it was mentioned here)?

    "You can apply custom properties to the log messages that come from a log source.
    To determine which domain (...) specific log messages belong to, the value of the custom property is looked up against a mapping that is defined in the Domain Management editor."
    (example)



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 3.  RE: TrendMicro VisionOne App

    IBM Champion
    Posted Wed February 01, 2023 10:09 AM
    In addition to Dusans comments, you may have to prioritize your manually created logsources in log source parse ordering. Make sure your log source identifiers are different for both tenants. An autodiscovered logsource will always be mapped to your default domain. Please assign your two logsources to your client domain using the settings shown in the screenshot.

    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------



  • 4.  RE: TrendMicro VisionOne App

    Posted Tue February 07, 2023 11:27 AM
    Edited by Davide Salardi Tue February 07, 2023 11:36 AM
    Thanks to everybody,
    unfortunately the payload does not cantain a field that allows to distinguish the tenants..we will evaluate further this point with TM support.

    ------------------------------
    Davide Salardi
    ------------------------------