TrendAI Vision One™ - OAT Detections (via Codeless Connector Framework)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID TrendAIVisionOneOAT
Publisher TrendAI
Used in Solutions TrendAI Vision One(CCF)
Collection Method CCF
Connector Definition Files TrendAIVisionOneOAT_ConnectorDefinition.json
DCR Definition Files TrendAIVisionOneOAT_DCR.json
CCF Configuration TrendAIVisionOneOAT_PollerConfig.json
CCF Capabilities APIKey, Paging
Custom Log V1 Tables Yes 🔶 — ingests into tables with type-suffixed columns

The TrendAI Vision One™ OAT data connector ingests Observed Attack Techniques (OAT) detections from TrendAI Vision One™ into Microsoft Sentinel. Detections include full process trees, file hashes, network indicators, and MITRE ATT&CK mappings.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
TrendAI_XDR_OAT_V2_CL 🔶 ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

⚠️ IMPORTANT: Token Rotation & Data Loss

When your API token expires or needs rotation, you must disconnect and reconnect this connector with the new token. Events generated during the disconnected period will NOT be automatically collected.

To minimize data loss:

  1. Generate a new API token before the current one expires
  2. Minimize the disconnect/reconnect window (seconds, not hours)
  3. After reconnection, if needed, manually query the TrendAI Vision One API for events during the gap period using the OAT Detections API

1. Retrieve your TrendAI Vision One™ API Token

  1. Log in to the TrendAI Vision One™ Console
  2. Navigate to Administration → API Keys
  3. Click Add API Key, select the SIEM role, and copy the token

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index