Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Trend Micro

Standard
Trend Micro ingests and normalizes logs from Trend Micro components into Logpoint to support security monitoring, investigation, reporting, and alerting.
Trend Micro content in Logpoint includes:
  • Universal REST API–based ingestion for Trend Vision One (TrendVisionOne)
  • Syslog-based ingestion for Trend Micro (syslog collector template)
  • Analytics content such as dashboards, reports, labels, saved searches, and alerts.

Release Details

Version: 6.2.1
Release date: 10th March, 2026
Supported On: Logpoint v7.4.0 or later and Universal REST API v2.1.0
SHA 256: 0cd847eba124f55e2bded691619f3c9afa44fc99623e7931c28f0e410394e7a4
Trend Micro User Guide
Download

Enhancement

PLUG-15797
New signatures are added to the LP_Trend Micro IMSS normalization package to normalize the new Trend Micro IMSS log format.

Bug Fix

PLUG-17556
TrendMicroCompiledNormalizer did not correctly normalize user and host fields in Trend Micro Vision One logs.

Past Releases

Trend Micro v6.2.0 ▾
Version: 6.2.0
Release date: 5th February, 2026
Supported On: Logpoint v7.4.0 or later and Universal REST API v2.1.0
SHA 256: eeeba608675873d028582e3c4dcf5e116d500bf0d7561736b4da761243855bd9
Download

Enhancement

PLUG-15797
New signatures are added to the LP_Trend Micro IMSS normalization package to normalize the new Trend Micro IMSS log format.

Bug Fixes

PLUG-13248
TrendMicroIMSVA did not use the device's time zone correctly when setting the log_ts field, causing the log_ts time to differ from the device’s local time. This led the logs to appear at the wrong time in searches and dashboards.
PLUG-17487
Indicator fields were not normalized correctly in Trend Micro Vision One Workbench logs, reducing SIEM search quality and detection coverage.
Trend Micro v6.1.0 ▾
Version: 6.1.0
Release date: 19th December, 2024
Supported On: Logpoint 7.0.0 or later, Logpoint v7.4.0 or later for log source template
SHA 256: 7155cbd087508f1abe751a5c328fb7f7fcdc59df4586cc8bdbc5ebc95470cc5a
Download

Enhancements

KB-24570
Added Universal Rest API based TrendVisionOne log source template to simplify the log source configuration process. Go to Universal Rest API based Log Source Template to learn more.
KB-19220, KB-22098KB-22836, KB-244667721978635
Added VisionOne and VisionOneCEF modules in TrendMicroCompiledNormalizer to support VisionOne and VisionOne CEF logs. To learn more, go to Compiled Normalizer .
Added CompiledNormalizer Date Preference (CNDP) support to TrendMicroCompiledNormalizer, ensuring consistent date format in normalized TrendMicro logs. Go to CNDP to learn how to configure it.
KB-24160

Updated the device_category field's value to reflect a generic taxonomy for device categories such as EDR, XDR, MDR and EPO.

CompiledNormalizer Module Former Field Value Updated Field Value
TrendMicroCompiledNormalizer ApexCentral EPO EPP
ApexOne
ControlManagerCEF
OfficeScan
TrendMicroApexCentral CompiledNormalizer
TrendMicroControlManagerCEF CompiledNormalizer
KB-25031

Removed the following generic widgets:

Dashboard Widget
LP_Trend Micro Control Manage Top 10 Email Sender IP Address
Top 10 Senders in Content Security Violation
LP_Trend Micro DB Sources Connecting Infected Destinations - List
User Logged in From Infected Sources - List
LP_Trend Micro Deep Security Top 10 Alert and Report Email Receivers
Alert And Report Emails - List
LP_Trend Micro Deep Security - Antimalware Top 10 Names in Malware
LP_Trend Micro IWSVA Hits
Top 10 Visited Websites
Top 10 Users

Updated the following widgets to improve its performance :

Dashboard Widget
LP_CEF: Trend Micro Deep Discovery - Virtual Analyser Virtual Analyzer Overview
TREND MICRO APEX CENTRAL - OVERVIEW Malware - Details
LP_Trend Micro Control Manager Top 10 Endpoints - Failed Actions

Renamed the following widgets:

Dashboard Former Widget Name Renamed Widget Name
LP_Trend Micro Deep Security - Overview Top 10 Names in Log Inspection Top 10 Event Category
Top 10 Names Integrity Monitor Top 10 Event Category from Integrity Monitor

Bug Fixes

KB-23908
The path field with a double slash ( \\ ) in its value for raw TrendMicroApexCentral logs was not correctly normalized by TrendMicroApexCentralCompiledNormalizer.
The source_address field of normalized TrendMicroApexCentral logs mapped the src field with incorrect value format.
KB-25105
The filterRiskLevel and riskLevel sub fields of raw TrendVisionOne logs, when normalized by TrendMicroCentralCompiledNormalizer, mapped only the riskLevel field's value in the risk_level field.
Trend Micro v6.0.0 ▾
Version: 6.0.0
Release date: May 07, 2024
Supported On: Logpoint v7.4.0 or later for log source template
SHA 256: 6fff70876f57c3c5e882cab661aefaf4c9c90efb83f2ed49106a9d2b12bc3fca
Download

Enhancements

KB-22742
Added Syslog Collector based Trend Micro log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
KB-20162
Added a new compiled normalizer TrendMicroCompiledNormalizer to support DeepSecurityCEF, ControlManagerCEF, DeepDiscoveryCEF, OfficeScan, ISMS, IMSVA, ApexCentral and CloudAppSecurity logs.
KB-1890970584
Added a dashboard LP_TREND MICRO IMSVA to support IMSVA log format . To know more, go to Trend Micro Dashboards .

Bug Fix

KB-2076774135
TrendMicroDeepSecurityCEF logs were not normalized by Trend MicroDeepSecurityCEF CompiledNormalizer and Trend Micro normalization packages .
Trend Micro v5.1.0 ▾
Version: 5.1.0
Release date: August 16, 2022
Supported On: Logpoint v6.7.0 or later
SHA 256: 440ad10993d345835215ec1a10c4b9e4d1426ad69d3b4ca52ec07415ec9de217
Download

Enhancements

KB-1331956559
Added TrendMicroCloudAppSecurityCompiledNormalizer to normalize Trend Micro Cloud App Security logs.
KB-13885
Added the following alerts: Trend Micro Deep Security Ransomware Detection Trend Micro Deep Security Botnet Detection To learn more, go to Trend Micro Alerts.
KB-1288554736
Updated LP_Trend Micro IWSVA to support IWSVA new log format. To learn more, go to Log Samples .

Bug Fixes

KB-1113747590
Labels were missing in some TrendMicro Deep Security logs.
KB-11321, KB-1363248465, 57023
Apex Central Saas Syslog and Trend Micro Apex CentralTM logs were not normalized by TrendMicroApexCentralCompiledNormalizer .
Trend Micro v 5.0.1 ▾
Version: 5.0.1
Supported On: Logpoint v6.7.0 or later

Enhancement

A minor update has been done in Trend Micro's normalizer for better signature handling.
Trend Micro v3.3.0 ▾
Version: 3.3.0
SHA 256: 98b5071cd40207271b4a644f625c1885c99a2faf13c6ee6ce7a7470aa503d10e
Download

Enhancement

A minor update has been done in the Websense's normalizer for better signature handling.

Support

If you have any questions or require assistance, create a support ticket.

Comments

  • Avatar
    François-Xavier Kouadio
    April 26, 2018 14:32

    Hi,
    Very Nice article, Please i failed to find the ODBC table under ‘Knowledge Base’, there is no such configuration item. cloud you please help me locate it ?

    Thank you for your help,

    Regards

    Edited by François-Xavier Kouadio April 26, 2018 14:50
    Comment actions Permalink
  • Avatar
    Permanently deleted user
    April 26, 2018 17:02

    Hello François-Xavier,

    We don't have Table on the newer version of LogPoint (6.x.x). You can configure it from Knowledge Base => Enrichment Sources => Table.
    Sorry for the inconvenience caused.

    Comment actions Permalink
  • Avatar
    François-Xavier Kouadio
    April 27, 2018 07:59

    Hello Ramesh,

    Great, Thank you for your feedback.

    Comment actions Permalink
  • Avatar
    Eric SAUGNAC
    May 03, 2018 15:58

    Hi, I can't add ODBC fetcher, Test is working but when I click on Submit, Logpoint says "Form is Beeing Submitted" and then nothing happens, I stay on the ODBC configuration widget and can only do cancel to get back to the ODBC Fetcher Widget without my configuration saved, it's really annoying...

    Comment actions Permalink
  • Avatar
    François-Xavier Kouadio
    May 04, 2018 07:12

    Hello eric,
    I'm not a LogPoint support member but as a user i have already encountered this issue. Use another browser to perform this action and it should work.
    regardes,
    François-Xavier KOUADIO

    Comment actions Permalink

Article is closed for comments.

Follow

Related articles

  • Universal REST API Fetcher
  • Vectra
  • GoogleCloudPlatform
  • Thycotic
  • Lookup
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.