- 21 Jul 2025
- 4 Minutes to read
- PDF
Integrate Trend Vision One with Red Canary
- Updated on 21 Jul 2025
- 4 Minutes to read
- PDF
To integrate Trend Vision One with Red Canary, follow the procedure from beginning to end.
Prerequisites
Your Trend Vision One user must have admin level access to complete the following steps successfully.
Your Trend Vision One tenant must have one of the following licenses:
Trend Vision One Endpoint Security - Essentials
Trend Vision One Endpoint Security - Pro
Sufficient Trend Vision One credits to enable the AWS S3 bucket connector. Please contact your Trend Micro account team if you do not have access to the AWS S3 bucket connector detailed in Step 2.
Note
The 30 day trial version of TrendMicro is NOT sufficient for testing because of the Trend Vision One credits requirement.
Step 1: Configure a Trend Vision One API key
Record your Trend Vision One Business ID.
Navigate to the License Information section within your Trend Vision One console.
Copy the Business ID.
Enter your Trend Vision One Business ID into Red Canary.
Create a user role to be used with your new API key. Note: Red Canary is committed to accessing your environment using the fewest permissions required.
Navigate to the User Roles page in the Trend Vision One console and click Add Role.
Enter the name red-canary-api for the role and click Permissions.
Configure the following permissions:
Platform Capabilities
XDR Threat Investigation
Workbench check the View, filter, and search and Modify alert details boxes.
Search check the View, filter, and search box.
Workflow and Automation
Response Management check the View, filter, and search (Task list tab), Isolate endpoint, and Terminate process boxes.
Third-party integrations check the View box.
Security Functions
Endpoint Security
Endpoint Inventory check the View box.
Settings
Administration
User Roles check the View box.
API Keys check the View box.
Role permissions should look like this when completed successfully.
Create a new API key for Red Canary to ingest telemetry and alerts.
Navigate to the API Keys section within your Trend Vision One console and click Add API Key.
Name the API key red-canary and assign the user role created in step 1.2.
Expiration Time should be set to “No expiration date.”
Copy the newly created API key.
Enter the API key into Red Canary.
Step 2: Configure Trend Vision One to export data to Red Canary’s AWS S3 bucket
Navigate to the AWS S3 Bucket Connector within your Trend Vision One console.
Click Workflow and Automation in the main menu on the left.
Select Third-Party Integration.
Click AWS S3 Bucket Connector.
In the Bucket name field, copy the bucket name listed from the in-line instructions in Red Canary.
In the Role ARN field, copy the Role ARN listed in the in-line instructions in Red Canary.
In the Data Transfer section, check the following boxes:
Workbench alerts
Activity data -> Scope: Endpoint
Step 3: Trend Vision One–Provide Red Canary access to your Vision One environment
Click on the Business Name menu at the top right.
Select User Accounts.
Click Add User Account.
Select Local Account.
Enter the email listed in the in-line instructions in Red Canary into the Account field.
Select Auditor for the Role field.
Click Add.
Red Canary will accept the invite to finalize access.
Ingest Details
Red Canary collects telemetry and alert data from Trend Vision One. Vision One “Activity” data is what Red Canary considers to be telemetry, and “Workbench Alerts” are what Red Canary ingests as alerts. Both types of telemetry are required for a effective detection and investigations. In order to enable the AWS S3 bucket connector, Trend Vision One customers must have sufficient credits. It takes credits to export data to an S3 bucket, so please contact your Trend Micro account team if you don’t have access to the AWS S3 bucket connector listed in Step 2.
Troubleshooting
Error: Missing Required Permissions
Error Message: Trend Micro API Key : User role associated with the API key is missing one or more required permissions - please ensure that the provided key is correctly configured
If you receive this error message in Red Canary, it means the API key's associated user role in Trend Vision One does not have sufficient access. To resolve this, sign in to your Trend Vision One console and ensure the custom user role created for Red Canary has the following permissions enabled:
Platform Capabilities > XDR Threat Investigation
Under Workbench, check the boxes for View, filter, and search and Modify alert details.
Under Search, check the box for View, filter, and search.
Platform Capabilities > Workflow and Automation
Under Response Management, check the boxes for View, filter, and search (Task list tab), Isolate endpoint, and Terminate process.
Under Third-party integration, check the View box.
Security Functions > Endpoint Security
Under Endpoint Inventory, check the View box.
Settings > Administration
Under User Roles, check the View box.
Under API Keys, check the View box.
Error: Missing Pipeline Configurations
Error Message: Trend Micro API Key: Missing valid export pipeline configurations for telemetry configurations - please ensure that the required pipelines are configured correctly in your Trend Micro account
If you receive this error message in Red Canary, it means that the integration is not configured to send the correct telemetry and alert data to Red Canary. To fix this, you must configure the data export settings in Trend Vision One:
In your Trend Vision One console, go to the Data Transfer section.
Ensure the following boxes are checked:
Workbench alerts
Activity data (with the Scope set to Endpoint)