Skip to main content
Connect Trend Micro Vision One so Myrmex can read your XDR detections and Workbench alerts, endpoint and account context, and help you triage and respond. Myrmex queries the Vision One REST API in real time through a Collector.
Myrmex connects on demand and reads (and acts) in real time — nothing from Vision One is stored on the Myrmex side.

What Myrmex Can Do

Detections and alerts

Read Workbench alerts and detections live and triage them in Alerts.

Endpoint context

Read agent and account context to enrich investigations.

Investigate with AI

Let Hydra query Vision One and summarize what’s happening.

Guided response

Propose response actions, always with your approval.

Before You Start

  • A Vision One account with a role that can create API keys (privileged or administrator access).
  • Your Vision One region — each region has its own API host.
  • A Collector that can reach the Vision One API over outbound HTTPS.

Step 1 — Create the Credential in Trend Micro Vision One

1

Open API Keys

In the Vision One console, go to Administration → API Keys.
2

Add an API key

Click Add API Key. Name it, choose a role that grants the access Myrmex needs (a SIEM or read role is enough to read detections), set an expiration, and set the status to Enabled.
3

Copy the key

Click Add and copy the generated token — you’ll paste it into Myrmex.
Note your console’s region (for example, US, EU, or SG); you’ll select the matching API host in the next step.

Step 2 — Add the Integration in Myrmex

In the Directory, choose Add Integration → Trend Micro Vision One and fill in:

Connect

Click Connect to validate the API key. Vision One then appears under Environment → Integrations, and you can triage your detections — queried live — in Alerts.