Skip to main content

How to integrate Trend Micro Deep Security

In this guide, we'll run through how to integrate Trend Micro Deep Security with the Defense.com SIEM platform.

Written by Alan Butcher

The Trend Micro integration is available on our Advanced and Enterprise packages.

Before you get started

This integration requires us to configure a collector on the edge of our network to receive your log data directly from Trend Micro Deep Security. Before you get started, please reach out to our Technical Support team and make them aware that you're planning on setting up this integration.

They will then deploy the collector required for this and provide you with the port and certificates mentioned later in this guide. The certificates will come in an attachment on the support ticket containing 2 files: client.crt and client.key.

Creating a Syslog Configuration

  1. In the Deep Security Manager console, go to Policies > Common Objects > Other > Syslog Configurations.

  2. Click New > New Configuration.

  3. On the General tab, fill in:

    • Name — a unique name for this configuration

    • Description — optional

    • Log Source Identifier — optional; only needed if you're running multi-node Deep Security Manager and want all nodes to report a shared identifier instead of each node's own hostname

Configuring the destination

Still in the same configuration:

  • Server Name - Enter the hostname provided by Defense.com Technical Support.

  • Server Port - Enter the port provided by Defense.com Technical Support.

  • Transport — set to TLS

  • Event Format - choose CEF

Setting up client authentication

  1. Go to the Credentials tab of the configuration.

  2. Open the client.crt provided by Defense.com Technical Support in a text editor (like Notepad), copy the text, and paste it into the Client Certificate field.

  3. Open the client.key in a text editor, copy the text, and paste it into the Private Key field.

  4. Click Test Connection to verify the handshake, then click Save.

Confirming log flow

Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.

  1. Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by type:"syslog".

  2. Reaching out to our Technical Support team, who'll be able to check and confirm this for you.

And that's it! You've successfully integrated Trend Micro Deep Security 🎉

Did this answer your question?