TrendAI Vision One™ - Workbench Alerts (via Codeless Connector Framework)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID TrendAIVisionOneWorkbench
Publisher TrendAI
Used in Solutions TrendAI Vision One(CCF)
Collection Method CCF
Connector Definition Files TrendAIVisionOneWorkbench_ConnectorDefinition.json
DCR Definition Files TrendAIVisionOneWorkbench_DCR.json
CCF Configuration TrendAIVisionOneWorkbench_PollerConfig.json
CCF Capabilities APIKey, Paging
Custom Log V1 Tables Yes 🔶 — ingests into tables with type-suffixed columns

The TrendAI Vision One™ Workbench data connector ingests security alerts from TrendAI Vision One™ into Microsoft Sentinel.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
TrendAI_XDR_WORKBENCH_V2_CL 🔶 ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

⚠️ IMPORTANT: Token Rotation & Data Loss

When your API token expires or needs rotation, you must disconnect and reconnect this connector with the new token. Events generated during the disconnected period will NOT be automatically collected.

To minimize data loss:

  1. Generate a new API token before the current one expires
  2. Minimize the disconnect/reconnect window (seconds, not hours)
  3. After reconnection, if needed, manually query the TrendAI Vision One API for events during the gap period using the Workbench Alerts API

1. Retrieve your TrendAI Vision One™ API Token

  1. Log in to the TrendAI Vision One™ Console
  2. Navigate to Administration → API Keys
  3. Click Add API Key, select the SIEM role, and copy the token

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index