Skip to content

Trend Micro Deep Security

You can integrate Trend Micro Deep Security with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Trend Micro Deep Security product overview

Trend Micro Deep Security provides advanced server and workload protection for physical, virtual, cloud, and container environments, defending against vulnerabilities, malware, and unauthorized changes through modules including anti-malware, intrusion prevention, firewall, web reputation, and integrity monitoring.

What we ingest

Sophos XDR collects Trend Micro Deep Security syslog data by listening for CEF messages your Deep Security Manager forwards to a Sophos XDR data collector. The following log categories are collected:

  • Malware detections: Anti-malware and application-control detections.
  • Intrusion prevention: Intrusion prevention (IPS) detections.
  • Web reputation: Web reputation detections.
  • Integrity monitoring: File and system integrity changes.
  • Firewall traffic1: Firewall pass and block events.

Event and data types

We ingest the following event and data types from Trend Micro Deep Security:

  • Malware detections: Anti-malware detections and application-control events, including the file, threat, and action. Normalized to antivirus telemetry.
  • Intrusion prevention: Intrusion prevention (IPS) detections, including the rule, severity, and source and destination endpoints. Normalized to third-party security alert telemetry.
  • Web reputation: Web reputation detections, including the URL and action. Normalized to HTTP telemetry.
  • Integrity monitoring: File and system integrity changes, including the affected object and change type. Normalized to file modification telemetry.
  • Firewall traffic1: Firewall pass and block events, including source and destination addresses, ports, and the action. Normalized to netflow telemetry.

Data provided by this integration

Data provided by Trend Micro Deep Security gets normalized to the following schemas:

  • antivirus
  • filemod
  • http
  • netflow 1
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview