Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trend Micro Apex One #1186

Closed
15 tasks
jamiehynds opened this issue Jun 23, 2021 · 2 comments
Closed
15 tasks

Trend Micro Apex One #1186

jamiehynds opened this issue Jun 23, 2021 · 2 comments
Labels

Comments

@jamiehynds
Copy link

Description

Apex One (formerly OfficeScan) provides a blend of advanced threat protection techniques delivered through a single-agent architecture to eliminate security gaps across any user activity and any endpoint.
• Automated detection and response against a variety of threats, including fileless and ransomware.
• Centralized visibility and control, with integration into endpoint detection and response (EDR) and managed detection and response (MDR) for advanced investigation and visibility across network.
• An all-in-one lightweight agent through software as a service (SaaS) and on-premises options

Architecture

Syslog in CEF is supported for both Apex Central (on-prem) and Apex One (SaaS). See here.

Integration release checklist

This checklist is intended for integrations maintainers to ensure consistency
when creating or updating a Package, Module or Dataset for an Integration.

All changes

  • Change follows the contributing guidelines
  • Supported versions of the monitoring target are documented
  • Supported operating systems are documented (if applicable)
  • Integration or System tests exist
  • Documentation exists
  • Fields follow ECS and naming conventions
  • At least a manual test with ES / Kibana / Agent has been performed.
  • Required Kibana version set to:

New Package

  • Screenshot of the "Add Integration" page on Fleet added

Dashboards changes

  • Dashboards exists
  • Screenshots added or updated
  • Datastream filters added to visualizations

Log dataset changes

  • Pipeline tests exist (if applicable)
  • Generated output for at least 1 log file exists
  • Sample event (sample_event.json) exists
@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@jamiehynds
Copy link
Author

Closing as we've prioritised Vision One instead, based on Trend Micro's guidance. Vision One docs available here - https://docs.elastic.co/integrations/trend_micro_vision_one

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants