Configure the integration to enable sharing of information about suspicious objects (IoC) between Netskope Cloud Threat Exchange (CTE) and TrendAI Vision One™.
Procedure
- In the TrendAI Vision One™
console, obtain the authentication token.
- Go to .
- Locate and click the Netskope CTE card.
- Copy and save the Authentication token.
-
If no authentication token exists, click Generate and copy the new token. You can specify the expiration time in .
-
If the existing authentication token is expired, click Revoke, then generate and copy a new token.
-
- Download and configure the TrendAI Vision One™ integration.For more information, see the integration demo video or Netskope documentation.
- In the Netskope console, go to Plugins.
- Search for and select Trend Micro v1.0.0.
- Under Basic Information, enter a
Configuration Name and a Sync
Interval and unit of time.Use the default settings for Aging Criteria and Override Reputation.
- Click Next.
- Under Configuration Parameters, select your region
and paste the Authentication Token obtained from
the TrendAI Vision One™
console.Use the default settings for Enabling Polling and Initial Range (in days).
- Click Save.
- Configure sharing of information between Netskope CTE and TrendAI Vision One™.
- Go to Sharing.
- Click Add Sharing Configuration.The Create Sharing Configuration window appears.
- Configure the following settings.SettingDescriptionSource ConfigurationSelect Netskope CTE.Business RuleSelect a previously defined business rule.If no valid Business Rule exists, go to Business Rules and create a rule.Destination ConfigurationSelect Trend Micro.TargetSelect Add to Suspicious Object List.DescriptionEnter a description of the configuration.
- Click Save.
- Click Sync.The Share existing IoCs window appears.
- Specify the Time period (in days), then click Fetch.
- Click Sync.Netskope and TrendAI Vision One™ begin sharing data on suspicious objects. Netskope and TrendAI Vision One™ can only collect data generated after configuring the integration. You might need to allow some time before new data starts to appear.
