Trend Micro
Standard
Trend Micro ingests and normalizes logs from Trend Micro components into Logpoint to support security monitoring, investigation, reporting, and alerting.
Trend Micro content in Logpoint includes:
-
Universal REST API–based ingestion for Trend Vision One (TrendVisionOne)
-
Syslog-based ingestion for Trend Micro (syslog collector template)
-
Analytics content such as dashboards, reports, labels, saved searches, and alerts.
Enhancement
PLUG-15797
New signatures are added to the LP_Trend Micro IMSS normalization package to normalize the new Trend Micro IMSS log format.
Bug Fix
PLUG-17556
TrendMicroCompiledNormalizer did not correctly normalize user and host fields in Trend Micro Vision One logs.
Past Releases
Trend Micro v6.2.0 ▾
Enhancement
PLUG-15797
New signatures are added to the LP_Trend Micro IMSS normalization package to normalize the new Trend Micro IMSS log format.
Bug Fixes
PLUG-13248
TrendMicroIMSVA did not use the device's time zone correctly when setting the log_ts field, causing the log_ts time to differ from the device’s local time. This led the logs to appear at the wrong time in searches and dashboards.
PLUG-17487
Indicator fields were not normalized correctly in Trend Micro Vision One Workbench logs, reducing SIEM search quality and detection coverage.
Trend Micro v6.1.0 ▾
Enhancements
KB-24570
Added Universal Rest API based TrendVisionOne log source template to simplify the log source configuration process. Go to Universal Rest API based Log Source Template to learn more.
KB-19220, KB-22098KB-22836, KB-244667721978635
Added VisionOne and VisionOneCEF modules in TrendMicroCompiledNormalizer to support VisionOne and VisionOne CEF logs. To learn more, go to Compiled Normalizer .
Added CompiledNormalizer Date Preference (CNDP) support to TrendMicroCompiledNormalizer, ensuring consistent date format in normalized TrendMicro logs. Go to CNDP to learn how to configure it.
KB-24160
Updated the device_category field's value to reflect a generic taxonomy for device categories such as EDR, XDR, MDR and EPO.
| CompiledNormalizer | Module | Former Field Value | Updated Field Value |
|---|---|---|---|
| TrendMicroCompiledNormalizer | ApexCentral | EPO | EPP |
| ApexOne | |||
| ControlManagerCEF | |||
| OfficeScan | |||
| TrendMicroApexCentral CompiledNormalizer | |||
| TrendMicroControlManagerCEF CompiledNormalizer |
KB-25031
Removed the following generic widgets:
| Dashboard | Widget |
|---|---|
| LP_Trend Micro Control Manage | Top 10 Email Sender IP Address |
| Top 10 Senders in Content Security Violation | |
| LP_Trend Micro DB | Sources Connecting Infected Destinations - List |
| User Logged in From Infected Sources - List | |
| LP_Trend Micro Deep Security | Top 10 Alert and Report Email Receivers |
| Alert And Report Emails - List | |
| LP_Trend Micro Deep Security - Antimalware | Top 10 Names in Malware |
| LP_Trend Micro IWSVA | Hits |
| Top 10 Visited Websites | |
| Top 10 Users |
Updated the following widgets to improve its performance :
| Dashboard | Widget |
|---|---|
| LP_CEF: Trend Micro Deep Discovery - Virtual Analyser | Virtual Analyzer Overview |
| TREND MICRO APEX CENTRAL - OVERVIEW | Malware - Details |
| LP_Trend Micro Control Manager | Top 10 Endpoints - Failed Actions |
Renamed the following widgets:
| Dashboard | Former Widget Name | Renamed Widget Name |
|---|---|---|
| LP_Trend Micro Deep Security - Overview | Top 10 Names in Log Inspection | Top 10 Event Category |
| Top 10 Names Integrity Monitor | Top 10 Event Category from Integrity Monitor |
Bug Fixes
KB-23908
The path field with a double slash ( \\ ) in its value for raw TrendMicroApexCentral logs was not correctly normalized by TrendMicroApexCentralCompiledNormalizer.
The source_address field of normalized TrendMicroApexCentral logs mapped the src field with incorrect value format.
KB-25105
The filterRiskLevel and riskLevel sub fields of raw TrendVisionOne logs, when normalized by TrendMicroCentralCompiledNormalizer, mapped only the riskLevel field's value in the risk_level field.
Trend Micro v6.0.0 ▾
Enhancements
KB-22742
Added Syslog Collector based Trend Micro log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
KB-20162
Added a new compiled normalizer TrendMicroCompiledNormalizer to support DeepSecurityCEF, ControlManagerCEF, DeepDiscoveryCEF, OfficeScan, ISMS, IMSVA, ApexCentral and CloudAppSecurity logs.
KB-1890970584
Added a dashboard LP_TREND MICRO IMSVA to support IMSVA log format . To know more, go to Trend Micro Dashboards .
Bug Fix
KB-2076774135
TrendMicroDeepSecurityCEF logs were not normalized by Trend MicroDeepSecurityCEF CompiledNormalizer and Trend Micro normalization packages .
Trend Micro v5.1.0 ▾
Enhancements
KB-1331956559
Added TrendMicroCloudAppSecurityCompiledNormalizer to normalize Trend Micro Cloud App Security logs.
KB-13885
Added the following alerts: Trend Micro Deep Security Ransomware Detection Trend Micro Deep Security Botnet Detection To learn more, go to Trend Micro Alerts.
KB-1288554736
Updated LP_Trend Micro IWSVA to support IWSVA new log format. To learn more, go to Log Samples .
Bug Fixes
KB-1113747590
Labels were missing in some TrendMicro Deep Security logs.
KB-11321, KB-1363248465, 57023
Apex Central Saas Syslog and Trend Micro Apex CentralTM logs were not normalized by TrendMicroApexCentralCompiledNormalizer .
Trend Micro v 5.0.1 ▾
Enhancement
A minor update has been done in Trend Micro's normalizer for better signature handling.
Trend Micro v3.3.0 ▾
Enhancement
A minor update has been done in the Websense's normalizer for better signature handling.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
Hi,
Very Nice article, Please i failed to find the ODBC table under ‘Knowledge Base’, there is no such configuration item. cloud you please help me locate it ?
Thank you for your help,
Regards
Hello François-Xavier,
We don't have Table on the newer version of LogPoint (6.x.x). You can configure it from Knowledge Base => Enrichment Sources => Table.
Sorry for the inconvenience caused.
Hello Ramesh,
Great, Thank you for your feedback.
Hi, I can't add ODBC fetcher, Test is working but when I click on Submit, Logpoint says "Form is Beeing Submitted" and then nothing happens, I stay on the ODBC configuration widget and can only do cancel to get back to the ODBC Fetcher Widget without my configuration saved, it's really annoying...
Hello eric,
I'm not a LogPoint support member but as a user i have already encountered this issue. Use another browser to perform this action and it should work.
regardes,
François-Xavier KOUADIO