Trend Micro Deep Security

Integration version: 5.0

Configure Trend Micro Deep Security to work with Google Security Operations

To create a new API key:

  1. Navigate to Administration> User Management> API Keys.
  2. Click New.
  3. In the Propertieswindow, enter a Name and Description for the API key.
  4. Click on the Rolelist and select a role.
  5. Next, select a Languageand a Time Zone. You can also select Expires on, which is optional, for expiry date for the API key.
  6. Click OK.
  7. Copy the Secret key value. Make sure to copy the secret key value now, because this is the only time it will be shown.

Configure Trend Micro Deep Security integration in Google SecOps

For detailed instructions on how to configure an integration in Google SecOps, see Configure integrations .

Integration parameters

Use the following parameters to configure the integration:

Parameter Display Name Type Default Value Is Mandatory Description
API Root
String https://{host or IP}:{port} Yes API root of the Trend Micro Deep Security instance.
API Secret Key
Password N/A Yes API Secret Key of the Trend Micro Deep Security instance.
API Version
String v1 Yes API Version of the Trend Micro Deep Security instance.
Verify SSL
Checkbox Checked Yes If enabled, verify the SSL certificate for the connection to the Trend Micro Deep Security server is valid.

Actions

Assign Security Profile to Host

Description

Assign the specified policy to computers.

Parameters

Parameter Type Default Value Description
Security Profile Name
String N/A Policy Name.

Use cases

N/A

Run On

This action runs on the Hostname entity.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result Name Value Options Example
is_assigned
True/False is_assigned:False
JSON Result
  N/A 
 

Get Host Info

Description

Describe a computer.

Parameters

N/A

Use cases

N/A

Run On

This action runs on the Hostname entity.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result Name Value Options Example
is_success
True/False is_success:False
JSON Result
  N/A 
 

Get Security Profiles

Description

Get all of the policies from Deep Security.

Parameters

N/A

Use cases

N/A

Run On

This action runs on all entities.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result Name Value Options Example
is_success
True/False is_success:False
JSON Result
  N/A 
 

Ping

Description

Verifies that the user has a connection to Trend Micro Deep Security via the user's device.

Parameters

Use cases

N/A

Run On

This action runs on all entities.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result Name Value Options Example
is_ connected
True/False is_connected:False
JSON Result
  N/A 
 

Scan Host

Description

Request a malware scan.

Parameters

Use cases

N/A

Run On

This action runs on the Hostname entity.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result Name Value Options Example
is_ success
True/False is_success:False
JSON Result
  N/A 
 

Need more help? Get answers from Community members and Google SecOps professionals.

Create a Mobile Website
View Site in Mobile | Classic
Share by: