Trend Micro
-
Universal REST API–based ingestion for Trend Vision One (TrendVisionOne)
-
Syslog-based ingestion for Trend Micro (syslog collector template)
-
Analytics content such as dashboards, reports, labels, saved searches, and alerts.
Enhancements
|
Description |
Issue ID |
|---|---|
| New signatures are added to the LP_Trend Micro IMSS normalization package to normalize the new Trend Micro IMSS log format. | PLUG-15797 |
Bug Fix
|
Description |
Issue ID |
|---|---|
| TrendMicroIMSVA did not use the device's time zone correctly when setting the log_ts field, causing the log_ts time to differ from the device’s local time. This led the logs to appear at the wrong time in searches and dashboards. | PLUG-13248 |
| Indicator fields were not normalized correctly in Trend Micro Vision One Workbench logs, reducing SIEM search quality and detection coverage. | PLUG-17487 |
Past Releases
Trend Micro v6.1.0
Release Date: 19th December, 2024
Supported On:Logpoint 7.0.0 or later, Logpoint v7.4.0 or later for log source template
Download: TrendMicro_6.1.0.pak
SHA256:7155cbd087508f1abe751a5c328fb7f7fcdc59df4586cc8bdbc5ebc95470cc5a
Key Information
Activate the label package LP_Trend Micro Control Manager to apply specific labels and group similar logs together. To learn more, go to Activating Labels Packages.
Enhancements
|
Description |
Issue ID |
Reference ID |
|||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Added Universal Rest API based TrendVisionOne log source template to simplify the log source configuration process. Go to Universal Rest API based Log Source Template to learn more. |
KB-24570 | - | |||||||||||||||||
| Added VisionOne and VisionOneCEF modules in TrendMicroCompiledNormalizer to support VisionOne and VisionOne CEF logs. To learn more, go to Compiled Normalizer. | KB-19220, KB-22098KB-22836, KB-24466
|
7721978635
|
|||||||||||||||||
| Added CompiledNormalizer Date Preference (CNDP) support to TrendMicroCompiledNormalizer, ensuring consistent date format in normalized TrendMicro logs. Go to CNDP to learn how to configure it. | |||||||||||||||||||
Updated the device_category field's value to reflect a generic taxonomy for device categories such as EDR, XDR, MDR and EPO.
|
KB-24160 | - | |||||||||||||||||
|
Removed the following generic widgets:
|
KB-25031 |
- |
|||||||||||||||||
Updated the following widgets to improve its performance:
|
|||||||||||||||||||
Renamed the following widgets:
|
Bug Fix
| Description | Issue ID | Reference ID |
|---|---|---|
| The path field with a double slash ( \\ ) in its value for raw TrendMicroApexCentral logs was not correctly normalized by TrendMicroApexCentralCompiledNormalizer. | KB-23908 | - |
| The source_address field of normalized TrendMicroApexCentral logs mapped the src field with incorrect value format. | ||
| The filterRiskLevel and riskLevel sub fields of raw TrendVisionOne logs, when normalized by TrendMicroCentralCompiledNormalizer, mapped only the riskLevel field's value in the risk_level field. | KB-25105 | - |
Trend Micro v6.0.0
Release Date: May 07, 2024
Supported On: Logpoint v7.4.0 or later for log source template
Download: TrendMicro_6.0.0.pak
SHA256: 6fff70876f57c3c5e882cab661aefaf4c9c90efb83f2ed49106a9d2b12bc3fca
Enhancements
|
Description |
Issue ID |
Reference ID |
|---|---|---|
| Added Syslog Collector based Trend Micro log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template. | KB-22742 | - |
|
Added a new compiled normalizer TrendMicroCompiledNormalizer to support DeepSecurityCEF, ControlManagerCEF, DeepDiscoveryCEF, OfficeScan, ISMS, IMSVA, ApexCentral and CloudAppSecurity logs. |
KB-20162 | - |
| Added a dashboard LP_TREND MICRO IMSVA to support IMSVA log format. To know more, go to Trend Micro Dashboards. | KB-18909 | 70584 |
Bug Fix
|
Description |
Issue ID |
Reference ID |
|---|---|---|
| TrendMicroDeepSecurityCEF logs were not normalized by TrendMicroDeepSecurityCEFCompiledNormalizer and Trend Micro normalization packages. | KB-20767 | 74135 |
Trend Micro v5.1.0
Release Date: August 16, 2022
Supported On: Logpoint v6.7.0 or later
Download: TrendMicro_5.1.0.pak
SHA256: 440ad10993d345835215ec1a10c4b9e4d1426ad69d3b4ca52ec07415ec9de217
Enhancements
|
Description |
Issue ID |
Reference ID |
|---|---|---|
| Added TrendMicroCloudAppSecurityCompiledNormalizer to normalize Trend Micro Cloud App Security logs. | KB-13319 | 56559 |
|
Added the following alerts:
To learn more, go to Trend Micro Alerts. |
KB-13885 | - |
|
Updated LP_Trend Micro IWSVA to support IWSVA new log format. To learn more, go to Log Samples. |
KB-12885 | 54736 |
Bug Fixes
The following issues are fixed:
|
Description |
Issue ID |
Reference ID |
|---|---|---|
| Labels were missing in some TrendMicro Deep Security logs. | KB-11137 | 47590 |
| Apex Central Saas Syslog and Trend Micro Apex CentralTM logs were not normalized by TrendMicroApexCentralCompiledNormalizer. | KB-11321, KB-13632 | 48465, 57023 |
Trend Micro v5.0.1
Supported On: Logpoint v6.7.0 or later
Enhancement
A minor update has been done in Trend Micro's normalizer for better signature handling.
Trend Micro v3.3.0
SHA 256: 98b5071cd40207271b4a644f625c1885c99a2faf13c6ee6ce7a7470aa503d10e
Download: TrendMicro_3.3.0.zip
Enhancement
A minor update has been done in the Websense's normalizer for better signature handling.
Support
If you have any questions or require assistance, create a support ticket.
Hi,
Very Nice article, Please i failed to find the ODBC table under ‘Knowledge Base’, there is no such configuration item. cloud you please help me locate it ?
Thank you for your help,
Regards
Hello François-Xavier,
We don't have Table on the newer version of LogPoint (6.x.x). You can configure it from Knowledge Base => Enrichment Sources => Table.
Sorry for the inconvenience caused.
Hello Ramesh,
Great, Thank you for your feedback.
Hi, I can't add ODBC fetcher, Test is working but when I click on Submit, Logpoint says "Form is Beeing Submitted" and then nothing happens, I stay on the ODBC configuration widget and can only do cancel to get back to the ODBC Fetcher Widget without my configuration saved, it's really annoying...
Hello eric,
I'm not a LogPoint support member but as a user i have already encountered this issue. Use another browser to perform this action and it should work.
regardes,
François-Xavier KOUADIO