Trend Micro Apex Central
You can integrate Apex Central with Sophos Central so that it sends audit data to Sophos for analysis.
This integration uses a log collector hosted on a virtual machine (VM). Together they are called a data collector. The data collector receives third-party data and sends it to the Sophos Data Lake.
Note
You can add multiple instances of Apex Central to the same data collector.
To do this, set up your Apex Central integration in Sophos Central, then configure one Apex Central instance to send logs to it. Then configure your other Apex Central instances to send logs to the same Sophos data collector.
You don't have to repeat the Sophos Central part of the setup.
The key steps to add an integration are as follows:
- Add an integration for this product. This configures an image to use on a VM.
- Download and deploy the image on your VM. This becomes your data collector.
- Configure Apex Central to send data to the data collector.
Requirements
Data collectors have system and network access requirements. To check that you meet them, see Data collector requirements.
Add an integration
To integrate Apex Central with Sophos Central, do as follows:
- In Sophos Central, go to Threat Analysis Center and click Integrations.
-
Click Trend Micro Apex Central.
If you've already set up connections to Apex Central, you see them here.
-
Click Add.
Note
If this is the first integration you've added, we'll ask for details about your internal domains and IPs. See My domains and IPs.
Integration steps appears.
Configure the VM
In Integration setup steps you configure your VM to receive data from Apex Central. You can use an existing VM, or create a new one.
To configure the VM, do as follows:
- Add a name and description for the new integration.
-
Enter a name and description for the data collector.
If you've already set up a data collector integration you can choose it from a list.
-
Select the virtual platform. Currently we support VMware ESXi 6.7 or later and Microsoft Hyper-V 6.0.6001.18016 (Windows Server 2016) or later.
-
Specify the IP settings for the Internet-facing network ports. This sets up the management interface for the VM.
-
Select DHCP to assign the IP address automatically.
Note
If you select DHCP, you must reserve the IP address.
-
Select Manual to specify network settings.
-
-
Select the Syslog IP version and enter the Syslog IP address.
You'll need this syslog IP address later, when you configure Apex Central to send data to your data collector.
-
Select a Protocol.
You must use the same protocol when you configure Apex Central to send data to your data collector.
-
Click Save.
We create the integration and it appears in your list.
In the integration details, you can see the port number for the data collector. You'll need this later when you configure Apex Central to send data to it.
It might take a few minutes for the VM image to be ready.
Deploy the VM
Restriction
If you're using ESXi, the OVA file is verified with Sophos Central, so it can only be used once. If you have to deploy another VM, you must create an OVA file again in Sophos Central.
Use the VM image to deploy the VM. To do this, do as follows:
- In the list of integrations, in Actions, click the download action for your platform, for example Download OVA for ESXi.
- When the image download finishes, deploy it on your VM. See Deploy a VM for integrations.
When you've deployed the VM, the integration shows as Connected.
Configure Apex Central
Now configure Apex Central to send audit data to your data collector, as follows:
- Go to Detections > Notifications > Notification Method Settings.
-
In the Syslog Settings section, enter the following:
- Server IP address: The syslog IP address of your data collector. You set this earlier in Sophos Central.
- Port: The port number of your data collector.
- Facility: Select the facility code.
-
Click Save.
Turn on syslog forwarding
We use syslog forwarding to send data to the Sophos data collector.
To forward syslog traffic, do as follows:
- Log in to Apex Central console using an Administrator account.
- Go to Administration > Settings > Syslog Settings.
- Select Enable syslog forwarding.
-
Configure the following settings:
- Server address: The syslog IP address of your data collector.
- Port: The port number of your Sophos data collector.
- Protocol: Select TCP or UDP. Choose the same one that you set up for your data collector.
-
Select CEF as the log format:
-
Select the log types to forward:
-
Select a log category from the Log type drop-down list:
- Security logs
- Product information
-
Select the check boxes for the logs you want to forward. Apex Central shows the total number of selected log types next to the Log type list.
- You can select another log category from Log type dropdown list.
-
-
Click Test Connection to test the server connection. The syslog server connection status appears at the top of the screen.
-
Click Save.
Apex Central starts forwarding logs to your data collector. The data should appear in the Sophos Data Lake after validation.
To monitor the log forwarding status, go to Administration > Command Tracking and select Forward Syslog from the Command drop-down list.