Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Configuring Deep Discovery Inspector (DDI) 5.7 to integrate with Trend Micro Vision One using Deep Discovery Director (DDD) Cloud

    • Updated:
    • 17 Apr 2021
    • Product/Version:
    • Deep Discovery Director All
    • Deep Discovery Inspector 5.7
    • Trend Micro Vision One All
    • Platform:
    • N/A
Summary

Trend Micro Vision One has an ability to do detection and response across email, endpoints, servers, cloud workloads and network via a single Trend Micro Vision One platform.

Trend Micro Vision One sits on top of relevant Trend Micro products in a customers’ environment, and offers expert security analytics for alert correlation, and consolidated visibility and investigation of events across security layers, leading to earlier detection and faster response.

Recommendation

Trend Micro Vision One offers a lot of capabilities such as early detection and response, getting greater context for greater understanding, etc. across multiple products. So if you use Trend Micro Vision One, Trend Micro recommends to connect DDI to Trend Micro Vision One to fully utilize Trend Micro Vision One functionality.

Configuration

There are two (2) ways to connect DDI to Trend Micro Vision One:

connect DDI to Trend Micro Vision One

  • Scenario 1: Trend Micro Vision One integration using Deep Discovery Director (DDD) On-Premises

    • Prepare DDI and DDD On-Premises to integrate with Trend Micro Vision One.
    • DDD On-Premises can connect to Deep Discovery Director-Network Analytics SaaS (DDDNASaaS) which is located in Trend Micro Cloud side.
  • Scenario 2: Trend Micro Vision One integration using Deep Discovery Director (DDD) Cloud

    • Prepare DDI and connect it to DDD Cloud version which is located in Trend Micro Cloud side to integrate with Trend Micro Vision One.
    • DDD Cloud can connect to Deep Discovery Director-Network Analytics SaaS (DDDNASaaS) in the backend.
     
    DDDNASaaS is also referred as “XDR Addon”, it provides advanced threat analysis for data correlations made between detections selected in DDD and other related events as they occur over time.
     

This article will show you how to configure DDI for the 2nd scenario, which is to integrate DDI with Trend Micro Vision One using DDD Cloud.

For information about how to configure DDI for scenario 1, refer to the KB article: Configuring Deep Discovery Inspector (DDI) 5.7 to integrate with Trend Micro Vision One using Deep Discovery Director On-Premises.

Details
Public

*Configuration for Scenario 2: Trend Micro Vision One integration using Deep Discovery Director (DDD) Cloud

  1. Install the product version (DDI 5.7 SP3 or above) which supports integration with Trend Micro Vision One investigation platform.

    Make sure DDI has a valid AC.

    Or you can setup a new DDI virtual appliance on your network or AWS. The detailed steps are explained in the later section, Installing a new DDI virtual appliance through Trend Micro Vision One.

  2. *Provision Deep Discovery Director Cloud (DDD Cloud) from the Trend Micro Vision One console.

    1. Log on to the Trend Micro Vision One console. Go to INVENTORY MANAGEMENT > Network Inventory.

      go to  Network Inventory

      Connect Network Sensors window appears.

    2. Select Deep Discovery Director cloud version then click Next.

      select DDD cloud

      A confirmation message appears.

    3. Click Finish.

      click Finish

    4. You will see the message "The Network Inventory Service takes a few minutes to provision".

      message

    5. After the provision is completed, a notification will appear on the bell icon to let you know the DDD Cloud URL, login credentials.

      login credentials

  3. *Add Network Sensor.

    1. At the same time, Connect Network Sensor window appears. If you do not see the window, click + Connect Network Sensor on the top right part of the Network Inventory page.

      Select Deployed Deep Discovery Inspector from the Product drop down list, and select 5.7 SP3 and above from the Sensor Version drop down list. Specify the DDI IP address then click Go.

      enter DDI IP address

    2. You will be redirected to the DDI Web console.

      DDI Web console

    3. After logging in, “Registering to Trend Micro Vison One” popup window appears. Click Continue.

      popup window

    4. On the Administration > Integrated Products/Services > Deep Discovery Director page, and you can see that the registration has completed.

      registration status

    5. Go back to the Trend Micro Vison One console. The Connect Network Sensor window remains open, click Cancel once then reload Network Inventory page. You can see that DDI has been registered successfully.

      reload Network Inventory

  4. *Check on the DDD Cloud Console.

    1. Go to the DDD Cloud Console by clicking the icon on the top right part of the Network Inventory page.

      Log on to the console using the user name and password available in the notification section.

      username and password

    2. You can see that DDI is registered as well.

      DDI registered

*Installing a new DDI virtual appliance through Trend Micro Vision One

If you want to setup new DDI virtual appliance on your environment or AWS, do the following:

  1. Complete all the steps enumerated in 2. Provision Deep Discovery Director Cloud (DDD Cloud) from Trend Micro Vision One console under Configuration for Scenario 2: Trend Micro Vision One integration using Deep Discovery Director (DDD) Cloud section.
  2. Log on to the Trend Micro Vision One console. Go to INVENTORY MANAGEMENT > Network Inventory.
  3. Click + Connect Network Sensor.

    Connect Network Sensor

    The Connect Network Sensor window appears.

  4. Select New Deep Discovery Inspector from the Product drop down list.
  5. You have two options on how to setup a new DDI virtual appliance.

    • Option 1: Setup DDI virtual appliance on your network.

      1. If you setup a new DDI virtual appliance on your network using ISO file, click I agree to End User License Agreement after reading it under “Option: Deploy a Deep Discovery Inspector virtual appliance” section. Click Download Disk Image to download ISO file. You can also copy SHA-256 hash value for the file.

        download ISO file

        The Instruction message appears.

      2. Click Download after the confirmation.

        Click Download

      3. The browser will start to download the file.
      4. After the download is completed. setup DDI using this file. For the detailed steps, refer to the Installation and Deployment Guide.
    • Option 2: Setup DDI virtual appliance on AWS.

      1. If you setup a new DDI virtual appliance on AWS, click View deployment instructions to check the detailed steps under the “Option: Deploy a Deep Discovery Inspector virtual appliance on AWS” section.
      2. Click Get AMI on Market place. For the detailed succeeding steps, refer to the deployment instructions above.
  6. After the DDI setup is completed, do the following steps enumerated in Configuration for Scenario 2: Trend Micro Vision One integration using Deep Discovery Director (DDD) Cloud section:

Premium
Internal
Partner
Rating:
Category:
Configure
Solution Id:
000283362
Feedback
Did this article help you?

Thank you for your feedback!


*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.