From 24c6d2e172079b3f3225429313282686d6d51c56 Mon Sep 17 00:00:00 2001 From: Nikov Tsai Date: Tue, 21 Jan 2025 16:47:08 +0800 Subject: [PATCH 1/3] update OLH URL --- Solutions/Trend Micro Vision One/Package/mainTemplate.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Solutions/Trend Micro Vision One/Package/mainTemplate.json b/Solutions/Trend Micro Vision One/Package/mainTemplate.json index bb56d806764..7cac11c0fce 100644 --- a/Solutions/Trend Micro Vision One/Package/mainTemplate.json +++ b/Solutions/Trend Micro Vision One/Package/mainTemplate.json @@ -188,7 +188,7 @@ }, { "name": "Trend Vision One API Token", - "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://automation.trendmicro.com/xdr/home)." + "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-api-keys-third-party-apps)." } ] }, @@ -200,7 +200,7 @@ "description": ">**(Optional Step)** Securely store workspace and API authorization key(s) or token(s) in Azure Key Vault. Azure Key Vault provides a secure mechanism to store and retrieve key values. [Follow these instructions](https://docs.microsoft.com/azure/app-service/app-service-key-vault-references) to use Azure Key Vault with an Azure Function App." }, { - "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/en-us/enterprise/trend-micro-xdr-help/ObtainingAPIKeys) to create an account and an API authentication token." + "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-api-keys-third-party-apps) to create an account and an API authentication token." }, { "description": "**STEP 2 - Use the below deployment option to deploy the connector and the associated Azure Function**\n\n>**IMPORTANT:** Before deploying the Trend Vision One connector, have the Workspace ID and Workspace Primary Key (can be copied from the following), as well as the Trend Vision One API Authorization Token, readily available.", From 64889efeaa6d6323262bbb63f9e99287ae16fd31 Mon Sep 17 00:00:00 2001 From: v-prasadboke Date: Thu, 30 Jan 2025 15:16:13 +0530 Subject: [PATCH 2/3] Solution packaged --- .../Data Connectors/TrendMicroXDR.json | 5 +- .../Trend Micro Vision One/Package/3.0.1.zip | Bin 0 -> 10073 bytes .../Package/mainTemplate.json | 98 +++++++++--------- 3 files changed, 51 insertions(+), 52 deletions(-) create mode 100644 Solutions/Trend Micro Vision One/Package/3.0.1.zip diff --git a/Solutions/Trend Micro Vision One/Data Connectors/TrendMicroXDR.json b/Solutions/Trend Micro Vision One/Data Connectors/TrendMicroXDR.json index fd84180ae18..accbb8e7d16 100644 --- a/Solutions/Trend Micro Vision One/Data Connectors/TrendMicroXDR.json +++ b/Solutions/Trend Micro Vision One/Data Connectors/TrendMicroXDR.json @@ -95,8 +95,7 @@ }, { "name": "Trend Vision One API Token", - "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://automation.trendmicro.com/xdr/home)." - } + "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://docs.trendmicro.com/documentation/article/trend-vision-one-api-keys-third-party-apps)." } ] }, "instructionSteps": [ @@ -110,7 +109,7 @@ }, { "title": "", - "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/en-us/enterprise/trend-micro-xdr-help/ObtainingAPIKeys) to create an account and an API authentication token." + "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/documentation/article/trend-vision-one-api-keys-third-party-apps) to create an account and an API authentication token." }, { "title": "", diff --git a/Solutions/Trend Micro Vision One/Package/3.0.1.zip b/Solutions/Trend Micro Vision One/Package/3.0.1.zip new file mode 100644 index 0000000000000000000000000000000000000000..bb3488e63ec37aa8636ee3a7c1e1c07294a8abb6 GIT binary patch literal 10073 zcmZ{~b8seH5bhaFY}=XGc;h#=lZkEHwr$(CGqJ6SZNJIH6YY1mws!a4TlaKVojP5o zx~l*CRX>lCEaVSNFfcG!uq!X1_JQ14p9d@$m>w}07|wrH6K69cS2Hy$F*9>3dn;Ef z2YV)K7YF+ttxtP`F0}7{p}im_9Zj~m69?nbtdBEF2$m?_(k#>XctGe6)b&Gi^uuz5p*Kb+#n+>JgtbarM5q z-vPL3ANDNn9%1}&a+KZUYBbQ!)KFCSzCy4Z zbkB+DOtg9Vz7}JeL`eLlrsd@AIl)9R7-y(m8)~l3N&w%kqFf4K(`qTxq-D&Mi#<^m zqi=Qim6{||5$pN+2>NcMx0qg~$}xz_<E*^v(u_UM4ud!x_eGFj{{SfGgi4z4T`PttsV)pwSpYQ^VSI9mJx z9>*Qx!q6Bs$jbVYO3oV0-W3A{BEp@Yj$Z^mSb^-HXVU?_$!rxnG~$E+z~f?ApO*Be zWq-~r(*{r1CC_8TRinH6TQfFLsc$1`=R)=8048bb{{Dz9lI>~o#a*M}g?lRCIO&L$ z@Kxbrt4yWiX$o&-Tl=D=29fMEJ!TN(Kulthm0#*YhVUlR<(U*&#IRe$otD$xh#b1-YQeDyQp*&3>?x$5lgce_EP z3HnswLql?0jkVHU%(_cw9g2G9yu-W0b)!Q(XT-*s$QOK5SWBab*`aGs842e$|-;VwTXo<{{G1%Tk%NquDYhf~VKDM(h10ze}w2BE?hBD*mabN?Cme zMi!{8mGu&-&-)mruC&uY(9SYz7M=M47t?5;Xt==X83xAf1RMYFZ8n*WE+xNdx)#cob5{ z0*~<*FQ*3~7@&qz?AViT%_Cu)SPbu>EE<|u07qf?Kk{E_u9U@GbApvlKJ~j%!C+j_ zE9bVRm`#x%^~sfJ=y8!O35akeoZX~0|1czfIC%ZY;DZ_CCprb^nOQdRTu=xMN%D|9 zHc?-QTW@Jl-czDq9>j~g*s6&nEniH&P%rx^RFUJ4&JU~h zS^e=WxvUUpkH$zr9GTUsknKZz;9aegC)0s&{+UcvGVA5Q_hjziKO^*slN!7=hjxs0Z}KVgB}>+|6|<{gBTepmPn2BGk~c;YJ0SPpU>Hx@*3&!@`-T zUn2!@wBzC@xmlb)iVk(pU2gnBBwfcf5n`D?Xx$5gF>P%0;OqZP))%2twhnvZg+YmvdHPyY>(&lnycNWw10~`cEf0X zY2JFl1;7(G)-vw)pD55y;K+S!-Z2pcsL_6NNZYXsWslhK&ymbv1UqFMCdl4MW<9(f zr2D2Q>hQwQg}72NSv*pjHZ1P0KFo{_`gN^Qc=TWY=6TIJxT{LEJUNO{5ALckl6*rd z=k%KV6$T#Nq+pNT3ZY%Uh6@4Rv$1$|FgNtXEc$Q>zLju#Qh02&(EHMC5PABE4#b|N zpY%tv+|5T!FJ_HPf-mGNzyE1IQEJtUdAz_*sTy*k%@KGJuNG`sELsiM+%)9J>IFTmeFax*1K&Hma0@{>8JRe41rF~#Ant0F}^R!nk5Jxk$ zitInLNSGm|=$9i~_gX%3N;bdYkrv>|<~Xegd6Tg=i74P<3L>(cxbLD!VI9N8O;4xZ zo+;_=L(e!RsoRLoNl4{wHK&-Jyff7I$7`3mq{Uu*+*U_E$(6r{`Syoa`kz=uP==-F zmJJY=BhjH(T%V$eraDNm*8pC`GS1`wWqm1*e;Vi5&kGV%2Myh>nu8*q zPlun)8*Cn;uI4MZ;Ybv9=@0V)Li=8JWMny5?ta69{7;0>Uy0k6uWXk{p8RJhrrXIc z2PM4&C09A{-@vg1;5sc@H0DU}%$&d-<>JB~zt%k}&<2{NIA@tY0`c0`8<07tcRhW> zE(4O|6lw=VhR;(LYp+lkAkz7VhAjaHD=N59@mwo;h5mfI;4k5euns;3K{=2MOlY)_J(ngXA@N2x&AANFAxF73mv3BjrWyJ2V6ESrc4xwiy0y zjKGVULmjze>Or6xjrj8^#kD3#eyy}^Rc`u^Z86sl5WiMF>qInp*bE*7#RXCSZX9+{9Vm_`Kly;2SsM z1EbV`SlqCtp2AgAD4}O`dHruUjD5Sq=N?S#``ZUZ6O>JB7R;%i zweyd<-c7rJWkY*;{=<8!ELr0!A~+SiN*N|b)Z7d2I!mgdj2#m)6PdbE zRQy%b*11>@veD9&p5dJjjO7#B{a@r_UONrsQ$zU`n$5U5RI1p6QYiY5R7o;CatZW5 zmwTv^s|v@b_oJ`AhIH>0+$iQz#bKxKMbhWkAB?MJXBJmZ9R7WSjX$dNpgs6ys{!~> z;uy!ew3LkGimV@kUv5A!A?^*|zjyp!Be!lqBrhbbUI_sX0^YVS#K^Xg$#9j~dCsN` z0HI%sF0iwY)+x_OGSjXHF)TS)rdf3dG_h5TS*Zj`O;`+aWB2u0|Na||AjQ^E4K70upg245l*ejKAP?svN+Pl~;eLXd*~dqlP4!z+g+iXl`Dp<9}XcB7G4w}6cEcfS!U87YK3 zQNom?RaGHqB~+YO>)x3+T#F`{+Uk&jqt{wQY)*ug+b98+8I-Rq&-6g3FALK8mePKk z#|-99#VrOAW;}1^pul%=)H_2uC9O`u8!}H#vIfeIW3avB+ztW&o;?Oi<*{6H5XpMJ zH7hrV&NLUtm;tIj%-6*uMHpS9(3x#kkte}7s3eUA75OZ#VOKvLsh0b$LRrYtGR@gX zkxm25pfcJ67{kD7*(x^jdkvO#z5V=lSYs(ha<};k!gqjAX%WWZR$U`MOuEGqwhTky zc;|XpvRx$>*Y&uLqfWZN+$PMwQf&jb;fXxT4VIS!qloBV3{P7_#bsbA$-?2~%mRg5 zqeTuXLBqxP?dzoblr_-HEWtNQV1ud%qGDDSavYNz>o0_l5vU3dgdljIpB6N;v5+># zPef~EA{UJ*Xo$|DnmT43T=r33T={#?c0tFOzdruUw8 zXCg&r&{7a&2OlX>6X5R)XWf&{=7+xj9E8j;R|5CydEozgRiS_>*bR!*KJ?foyAR7& zCb8`OcNC%k*MSUa!}hO%_E>Y#xHteFDy0%-BZ}3=#%f4;NPmm2?({F26r)`QcSOgiQy!^ z;#|<8jX<#9J7F(B9ATq92On`D_uN4U-f+UQG3MTUMW%W^!u2`{$@zr z@GfYp(Afy>Q(*U--ZKUPdF4m*Ht;|BLbjNb!7&xY)9G5W+< zwll^L)k`J*HBdEB_~C?qP@9`5p$PjksE!^t)vl%K$tVs8{|C{>#YaF#oO}~bpuiSs zQ4Z6<0G~E(zjUK{6Z2=+&u98ksgx5(;#|}8u?AH7HXAKf*UYO;i;-c%V#$m2Ijm6p zI=)2vRS{#Ut>|Y_v*$%k+VR7*Xn9&I+0;qWN2rc%OV>WW!w~B}z5ztC4+%vj3d))t z2=?$mZ!IasEY8O@V%tr#bC`MuAoFV4N#_zkC{!)jBlJ^qkwXsZ(o}}~pr{!nV1$!S z@VD4`G`9tUZ*(1Q5?R?;P&P}rtz3<>r0kI*&aKgvf?KOMTs!^TtWc zDqiD88Z0PPeQ+J2j%x|1qHq(J`snlwhEm`A;-@Z}GJ<%PlxJCB587g8DTHd_k0~Z_ zPOK+&A>Ql9%xNjbEfTrOHZr@wz(Z&HyV9b?%i&JbK+=gQKWxrn1@sP~XRQN?r2eg` ziH)BTaNZ#qN~^_ynZU;H@V&QBSp6J#V?&Q?KxSbaU=^qMTHDkgy0|^m+!GR>!C#pn z-D(ii+hP=5OTOECJSp*pZxsmbgb#}w(%^_Q%zPIk1H__hV(JK5)9-yk0x1NiYhGA5jVj|`nPUs=E7x27CjjP#y(ZSx=1B_K1X-n(>Sb1&{68oj8gCj zH?HmXpM#u|l)N=+%Kdz&8FUR&X$edP&271uI0hvkmW+zx^NZNkWXSM9kOV)*NEZN1 z7VP=(BQv+_2jQT`9j~K-lGgbi~EiulOAwsR?#_^U$bj>uqd+Mo-a#u>V?x{-= zpPINbE)e2{h`Xg*SdDwkuqvX^z5+J{0??T=hq}2}^FzDuN;*s1{c|#w#g7!fa{ayi zme?OlFPI@CTt8$*kly{Q4Pxh)$fN)q49e!14BRA7m@#>29Bnm|^$09B3m)dMd%XT2 zJs@AHk!Z4l7{FFv0$?K`@R3=eO@n}_5sV`b#5imkuAI_x{l{EUy&pwqdF{-E1}2px z`Uw0x8cc6gdj=n7jj*bqPQd-SSsecZ>|qDnu8USw$<>Km-CSjyY`EeR*Mh(i*WUL0 zPJzll~;;xZ+{n25|?_C(~C z+*243!FkGw*sVxfHp(%jW+I|&!!m3vklMtT$OwOh`TAF7wM|XomROfJS8E)~peHm`V1Ql)<4KPR71nDyK_iA!f?x z^9B^9jQ|TVu-OE52XJf`y!4c4PYBGJ=yLSDv-;%1`;sOQUB_N<`xA_4mf+zg$fMuIrdJ!geS;Fl@(EZwj-IYRxxH`E#ueE3`9Pc!~F{*-jA^jBJBH_|%3rmx;z zXXI^Ktc<2kFhvo!Kr3nJUk8Erpr^Yb zB$0Yq42pCjs`_P+s&sOytVsSeC$3YTYp@J(6pOJmrT-MJMxsHSp&NHnqkt?IUpu!h z9Ra3czK{u%rizx1!OJb>F2cQ?&=z8i4u7iVAsvQf!EDB4s z5wmb{wqGB58BuBU~ zgW@@7`zg)!hS>HZ-qwat)kyc7p-Mwm!klQdX52U=i-&-`&8?GF!v>7`D${#Zp=SYm z5?+f|PLJWnl_`yV>m_(4{S9n}zEEb4M@uH(*q=wAM(`e)ssDs0_D>;v3p9>GDT6%M z$Mfn(j%?T_=NFZY&t$fKOZt3U_XZP9gIC4bawg>OFmIQ`!G|71_TyH<*QRtNHIhJKf&_DM&Uf|i4i zO*Wv*u=`jeovI7AZ)%AQMJKw8^m^EG9oCDo!Jjl_hlz_e#t z%lv7jMGCN?H%H#H7+F&~mN$p4m3rCrSWbYCl>kVi=yZ2^ zu4Z{?|~!u>1Gi>4waeEmZitQ=~=(jTB~Rf&jldWrBmJ0za8`z>6NTw1tI!&(0V~ zl|A}h6PmR}G;~JGzBn8QhO423_v_XmQio|oi#&DDZ?J2p13Cj1BP0v8+D{5e=?=R~_0jeOLqfO`ohV@+IXK8DhL{@CFOjG+sw$(u=Y2pvmge9M!=YL? zz#{*GLEW@@Hq^|}F7L^r7UXH=;Z$SMP;s~e8}5oCO@_Qgz@NVY< z7bu(g6Srv@!0#U-YagQ!aSrvbH!8vSiu9kN%72U2Q_OtJXWSqucBNn%-qYYGL7Lw6 zDXNEP8ndfK6rG&IvlI!0(d$a{)(Mq_IdybCci#R=n<~3rW`Ve5e&!8DapgtVj$&1AC$6XY}gY$iVXcB}j zh9&2u(_Q62Dlo$)Mz7e1x^ZtCYH^4mzbBJ~i$5VwX!l&Dfy-uj`E7Bd6 zk;DO#Y4GrGYJ*$Zj51$8>-F!2;fL$hEln8Th@I=7A8I+OU;8T%b*Xsn%UGow4l>S| z`B*;Yq4?pQlr1*@Z6myD5|>Dv_o|J^-}swqd=!08kbjb-eDL+991<=Zz-Q+4nuM(S z6yUC#w9}tQ19SG+i=mGcU<%!O^V22-te#@SD40U}0Ewm64iA4X=|!!eFJm;hbo8>> zTIOZkm8*tWTbO6`=hmUhD@j%&|CSe5R_B3|j=7TDWC%t4UZkWzYq2tZMR%>?G6|XO zJ37acTynLw_^;O$R*M>z`stY^rjiUVMWB^s7mFN9cHkKgsC4zXqeSv^VlVqIyq@z~-Z@-Y zIwP7GCpW|^Kz+6@S51{ZqGfyqGwNUzsrcz^>HIQ=P0zXJ$E9xj8)f5{w!S4YY@A-9!uQ2?8`D`3oA`ovyO*F}zLt=!`QtBFK`-W0F3 z`}Gf2u))j<_)`qVe`0lDgM2u4+UJ((=$06mZxpGHOY%y42SuP)YRgm?T8VH-o&~yp zOHWF({U}o*m@Qz4Tqhbfrf@v!p2D7$`EqMFjlL8WzA7bk}`?=tOm=a)dfD$n?Z7gm&>dT z+HlZ9amsc6TvZrc5>!P-8cEr|8BURGn2I3|4)g74&OK$P6O(IEDNiy9qJZnF_~=8o z1c~dtojnE1;7#u0Zi1La$f2nzYH-o2rzTT5a|E=)CbX>SRy;R9XY+oPN8heP zNSf($im#8t@8GXHvE$gK)CF(uY=m{GhP;=_BUp9By(?PhvxaO~aA=ZDt6=1GE1MVw ze>R17v~n36q@d4g0hj%ti#Qz&`NimhZY0f#*Biu!;m;5(Kcc=Vou6MbUWPRO9R4X# zoz0tDUq2P}S5Geo<+8>KJ+4NLagctKgLIgrRbO8PcWe20oxeJXN3x+byESN??=TYE zs-fv*(IpO~U#O*SDja_S)}p5nSL|pU{-%}5A?Erxj;I3kqq}GhEOKheG5*9g!Qy;D zcS+mmHX22@<0AasZc~O{E*rs&R*R&NRxyN#6~YC2a|W({f01{a|Ewd)GhGDGAs=;=a8bQ)x?~8P=xL)bltPzv&h+p^wGLc=Q zrs4Qs=6%-2^aR?5TEwi0i%ZZ{Uew_Fb%!XuO(bdLn8~@ zf;xUR#gWn814X?ntLhSJa(QFh*>kEFUljH=>Z_*EjQoHb9wY8D{;-Nef)s-)D4ECs z^=%Apa*m;fhIbO`;A~Cev!t!4o+u{l$LoLpczc|U%Ci64`L8pkOEqF|ingRC;euwDbyC|c3Y^nsjbu$!!SQ?-{8p4>-c}x@= z8WNH*$ZaPH0dig4AYHRhqVnWmfaIUG6?caI8DtuzOM9@CFdu$V)OZ3F$(`Fsl;|Ny zksus0!ys0xoKWLeSHJCTi~%5HmnzMI@0SJ7FH^2#Mtvk^TK%QE2?PVmY)Pdj$EoE6 z`}~tusgJkb&xR)So%}NEtm+Ly^#}xN*b>ny=|D^`V;aAe+cGR7Hoa3>5jdai+fPQu zA8jHTW}(S3wDKrK~^h$>6Lrd|1h@gdo&DMB)Yz4=!i zN-|E|v{Qp2XMvoNe&N7%{})uiH;IxgI0Pox|JlIypDz6WJO2ke+yC0+e^r+MzYewk cdE@>!omoj13i^M1f%q>%|GWFC{>SV80xru(U;qFB literal 0 HcmV?d00001 diff --git a/Solutions/Trend Micro Vision One/Package/mainTemplate.json b/Solutions/Trend Micro Vision One/Package/mainTemplate.json index 7cac11c0fce..94305e6e693 100644 --- a/Solutions/Trend Micro Vision One/Package/mainTemplate.json +++ b/Solutions/Trend Micro Vision One/Package/mainTemplate.json @@ -39,7 +39,7 @@ }, "variables": { "_solutionName": "Trend Micro Vision One", - "_solutionVersion": "3.0.0", + "_solutionVersion": "3.0.1", "solutionId": "trendmicro.trend_micro_vision_one_xdr_mss", "_solutionId": "[variables('solutionId')]", "uiConfigId1": "TrendMicroXDR", @@ -77,7 +77,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Trend Micro Vision One data connector with template version 3.0.0", + "description": "Trend Micro Vision One data connector with template version 3.0.1", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('dataConnectorVersion1')]", @@ -188,7 +188,7 @@ }, { "name": "Trend Vision One API Token", - "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-api-keys-third-party-apps)." + "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://docs.trendmicro.com/documentation/article/trend-vision-one-api-keys-third-party-apps)." } ] }, @@ -200,7 +200,7 @@ "description": ">**(Optional Step)** Securely store workspace and API authorization key(s) or token(s) in Azure Key Vault. Azure Key Vault provides a secure mechanism to store and retrieve key values. [Follow these instructions](https://docs.microsoft.com/azure/app-service/app-service-key-vault-references) to use Azure Key Vault with an Azure Function App." }, { - "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-api-keys-third-party-apps) to create an account and an API authentication token." + "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/documentation/article/trend-vision-one-api-keys-third-party-apps) to create an account and an API authentication token." }, { "description": "**STEP 2 - Use the below deployment option to deploy the connector and the associated Azure Function**\n\n>**IMPORTANT:** Before deploying the Trend Vision One connector, have the Workspace ID and Workspace Primary Key (can be copied from the following), as well as the Trend Vision One API Authorization Token, readily available.", @@ -419,7 +419,7 @@ }, { "name": "Trend Vision One API Token", - "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://automation.trendmicro.com/xdr/home)." + "description": "A Trend Vision One API Token is required. See the documentation to learn more about the [Trend Vision One API](https://docs.trendmicro.com/documentation/article/trend-vision-one-api-keys-third-party-apps)." } ] }, @@ -431,7 +431,7 @@ "description": ">**(Optional Step)** Securely store workspace and API authorization key(s) or token(s) in Azure Key Vault. Azure Key Vault provides a secure mechanism to store and retrieve key values. [Follow these instructions](https://docs.microsoft.com/azure/app-service/app-service-key-vault-references) to use Azure Key Vault with an Azure Function App." }, { - "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/en-us/enterprise/trend-micro-xdr-help/ObtainingAPIKeys) to create an account and an API authentication token." + "description": "**STEP 1 - Configuration steps for the Trend Vision One API**\n\n [Follow these instructions](https://docs.trendmicro.com/documentation/article/trend-vision-one-api-keys-third-party-apps) to create an account and an API authentication token." }, { "description": "**STEP 2 - Use the below deployment option to deploy the connector and the associated Azure Function**\n\n>**IMPORTANT:** Before deploying the Trend Vision One connector, have the Workspace ID and Workspace Primary Key (can be copied from the following), as well as the Trend Vision One API Authorization Token, readily available.", @@ -474,7 +474,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "TrendMicroXDROverview Workbook with template version 3.0.0", + "description": "TrendMicroXDROverview Workbook with template version 3.0.1", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('workbookVersion1')]", @@ -560,7 +560,7 @@ "[extensionResourceId(resourceId('Microsoft.OperationalInsights/workspaces', parameters('workspace')), 'Microsoft.SecurityInsights/contentPackages', variables('_solutionId'))]" ], "properties": { - "description": "Create Incident for XDR Alerts_AnalyticalRules Analytics Rule with template version 3.0.0", + "description": "Create Incident for XDR Alerts_AnalyticalRules Analytics Rule with template version 3.0.1", "mainTemplate": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "[variables('analyticRuleObject1').analyticRuleVersion1]", @@ -588,100 +588,100 @@ "status": "Available", "requiredDataConnectors": [ { + "connectorId": "TrendMicroXDR", "dataTypes": [ "TrendMicro_XDR_WORKBENCH_CL" - ], - "connectorId": "TrendMicroXDR" + ] } ], "entityMappings": [ { - "entityType": "Account", "fieldMappings": [ { - "identifier": "Name", - "columnName": "UserAccountName_s" + "columnName": "UserAccountName_s", + "identifier": "Name" }, { - "identifier": "NTDomain", - "columnName": "UserAccountNTDomain_s" + "columnName": "UserAccountNTDomain_s", + "identifier": "NTDomain" } - ] + ], + "entityType": "Account" }, { - "entityType": "File", "fieldMappings": [ { - "identifier": "Name", - "columnName": "FileName_s" + "columnName": "FileName_s", + "identifier": "Name" }, { - "identifier": "Directory", - "columnName": "FileDirectory_s" + "columnName": "FileDirectory_s", + "identifier": "Directory" } - ] + ], + "entityType": "File" }, { - "entityType": "Process", "fieldMappings": [ { - "identifier": "CommandLine", - "columnName": "ProcessCommandLine_s" + "columnName": "ProcessCommandLine_s", + "identifier": "CommandLine" } - ] + ], + "entityType": "Process" }, { - "entityType": "RegistryKey", "fieldMappings": [ { - "identifier": "Key", - "columnName": "RegistryKey_s" + "columnName": "RegistryKey_s", + "identifier": "Key" } - ] + ], + "entityType": "RegistryKey" }, { - "entityType": "RegistryValue", "fieldMappings": [ { - "identifier": "Name", - "columnName": "ProcessCommandLine_s" + "columnName": "ProcessCommandLine_s", + "identifier": "Name" }, { - "identifier": "Value", - "columnName": "RegistryValue_s" + "columnName": "RegistryValue_s", + "identifier": "Value" } - ] + ], + "entityType": "RegistryValue" } ], "eventGroupingSettings": { "aggregationKind": "AlertPerResult" }, "customDetails": { + "Provider": "alertProvider_s", + "PriorityScore": "priorityScore_d", + "ImpactScopeSummary": "impactScope_Summary_s", "WorkbenchID": "workbenchId_s", "WorkbenchLink": "workbenchLink_s", - "CreatedAt": "createdTime_t", - "PriorityScore": "priorityScore_d", + "WorkbenchName": "workbenchName_s", "Severity": "severity_s", - "ImpactScopeSummary": "impactScope_Summary_s", "XDRCustomerID": "xdrCustomerID_g", - "WorkbenchName": "workbenchName_s", - "Provider": "alertProvider_s" + "CreatedAt": "createdTime_t" }, "alertDetailsOverride": { "alertDisplayNameFormat": "{{workbenchName_s}}", - "alertDescriptionFormat": "{{description_s}}", - "alertSeverityColumnName": "Severity" + "alertSeverityColumnName": "Severity", + "alertDescriptionFormat": "{{description_s}}" }, "incidentConfiguration": { "createIncident": true, "groupingConfiguration": { - "groupByCustomDetails": [ - "WorkbenchID" - ], - "lookbackDuration": "5m", "matchingMethod": "Selected", "enabled": true, - "reopenClosedIncident": false + "lookbackDuration": "5m", + "reopenClosedIncident": false, + "groupByCustomDetails": [ + "WorkbenchID" + ] } } } @@ -731,7 +731,7 @@ "apiVersion": "2023-04-01-preview", "location": "[parameters('workspace-location')]", "properties": { - "version": "3.0.0", + "version": "3.0.1", "kind": "Solution", "contentSchemaVersion": "3.0.0", "displayName": "Trend Micro Vision One", From a84183be704b2b9dccb89233546034a61e82cef1 Mon Sep 17 00:00:00 2001 From: v-prasadboke Date: Thu, 30 Jan 2025 15:17:38 +0530 Subject: [PATCH 3/3] Create ReleaseNotes.md --- Solutions/Trend Micro Vision One/ReleaseNotes.md | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 Solutions/Trend Micro Vision One/ReleaseNotes.md diff --git a/Solutions/Trend Micro Vision One/ReleaseNotes.md b/Solutions/Trend Micro Vision One/ReleaseNotes.md new file mode 100644 index 00000000000..84a1caf5d3e --- /dev/null +++ b/Solutions/Trend Micro Vision One/ReleaseNotes.md @@ -0,0 +1,3 @@ +| **Version** | **Date Modified (DD-MM-YYYY)** | **Change History** | +|-------------|--------------------------------|---------------------------------------------| +| 3.0.1 | 30-01-2025 | Updated hyperlink in **Data Connector** | \ No newline at end of file