When you configure Trend Micro Deep Security Inspector to send log data to USM Appliance, you can use the Trend Micro Deep Discovery Inspector plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin.
Device | Details |
---|---|
Vendor | Trend Micro |
Device Type | Intrusion Detection |
Connection Type | Syslog |
Data Source Name | Trendmicro-ddi |
Data Source ID | 1905 |
Integrating Trend Micro Deep Discovery Inspector
Before you configure the Trend Micro Deep Discovery Inspector integration, you must have the IP Address of the USM Appliance Sensor.
To configure Trend Micro Deep Discovery Inspector to send Syslog messages to USM Appliance
- From the Trend Micro Deep Discovery Inspector Management Console, open the Syslog page display:
- For versions 3.6 and 3.7, select Logs > Syslog Server Settings.
- For version 3.8, select Administration > Integrated Products / Services > Syslog.
- From the Syslog page, click Add. The Add Syslog Server page appears.
- From the Add Syslog Server page, select Enable syslog server and specify the following:
- Server name or IP address : USM Appliance IP Address
- Port : 514
- Protocol : UDP
- Facility level : Any
- Severity level : Any
- Log format : CEF
- Under Detection Logs, select all log types.
- Click Save.
Plugin Enablement
For plugin enablement information, see Enable Plugins.
Additional Resources and Troubleshooting
For troubleshooting, see the vendor documentation.