Skip to main content

Overview

The Trend Micro Apex One integration enables ThreatAware to collect read-only data from your Trend Micro Apex One environment, providing visibility into endpoint protection status and helping validate your endpoint security controls.
Connection Method: API with Port Forwarding Setup Time: 25 minutes Access Required: Trend Micro Apex One Administrator account

Data collected

The Trend Micro Apex One integration provides:
  • Endpoint protection status
  • Threat detection and response data
  • Security policy compliance metrics
  • Device inventory and protection details

Use cases

Endpoint Security Tracking

Monitor endpoint protection status across all managed devices

Compliance Validation

Verify endpoint protection policies are properly configured

Threat Monitoring

Track threats and security incidents across your environment

Audit Support

Generate reports showing endpoint protection coverage

Setup instructions

1

Access Administration Console

In Trend Micro Apex One, navigate to Administration > Settings > Automation API Access Settings.
2

Enable Automation API Access

  • Click Add
  • Copy the Application ID and API Key
  • Select Enable application integration using Apex Central Automation APIs
  • Set the Application Name to ThreatAware
  • Set the Communication time-out to maximum
  • Click Save
3

Configure Firewall Port Forwarding

On your firewall:
  • Create a port forward to the Trend Micro server (typically on port 20000)
  • Restrict access to ThreatAware’s current allowlist IP addresses, available in-product under Settings → Integrations → AWS Account / IP Whitelist Info
  • Document the public IP address and the port you have configured
4

Configure in ThreatAware

Complete the integration setup in ThreatAware:
  • Open ThreatAware and navigate to Settings > Integrations
  • Search for and select Trend Micro Apex One
  • Enter the required credentials:
    • API Key: The key obtained from Apex One settings
    • Application ID: The ID obtained from Apex One settings
    • Public IP Address: The public IP address of your firewall
    • Forwarded Port: The port you configured on the firewall
  • Click Connect to establish the integration
5

Verify Connection

After connecting, verify the integration status shows as Active in ThreatAware.

Required credentials

Field Name: Trend Micro API Key Type: Password (encrypted) Description: The API key generated in Trend Micro Apex One settings
Store this credential securely in your organisation’s password manager for future reference.
Field Name: Trend Micro Application ID Type: String Description: The Application ID generated in Trend Micro Apex One settingsThis identifies your ThreatAware application to the Trend Micro system.
Field Name: Trend Micro Public IP Address Type: String Description: The public IP address of your firewall for port forwardingFormat: XXX.XXX.XXX.XXX Example: 203.0.113.45
Field Name: Trend Micro Forwarded Port Type: Number Description: The port you configured on your firewall for port forwardingExample: 20000 or your custom port

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the Trend Micro Apex One integration shows Active status
  2. Verify Data Collection
    • Wait 60 minutes for the initial data poll
    • Search for a known device in ThreatAware
    • Check device details for Trend Micro protection data
  3. Test Queries
    • Create a test query to filter devices by Trend Micro security status
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify the API Key and Application ID are correct
  • Ensure Automation API Access is enabled in Trend Micro settings
  • Check that credentials were copied completely without extra spaces
  • Confirm the Application Name is set to “ThreatAware”
Symptoms: Integration fails to connect with timeout errorsSolutions:
  • Verify the firewall port forwarding is correctly configured
  • Ensure ThreatAware’s allowlist IPs are correctly authorised (see Settings → Integrations → AWS Account / IP Whitelist Info)
  • Check that the public IP address is correct
  • Confirm the forwarded port matches your firewall configuration
  • Test port connectivity using a network utility
Symptoms: Integration connects intermittently or not at allSolutions:
  • Verify firewall rules allow traffic on the forwarded port
  • Ensure IP address restrictions include the ThreatAware servers
  • Check that the Trend Micro server is accessible via the public IP
  • Review firewall logs for blocked connections
  • Consult your network administrator if issues persist
Symptoms: Integration shows active but no endpoint data appearsSolutions:
  • Verify there are managed devices in your Trend Micro environment
  • Check the API permissions in Trend Micro settings
  • Ensure devices are properly enrolled and reporting
  • Review ThreatAware integration logs (contact support if needed)

Additional resources

Trend Micro API Documentation

Official Trend Micro API documentation for detailed configuration

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Credential Management
  • Create a dedicated API key specifically for ThreatAware
  • Document credentials in your organisation’s password manager
  • Rotate credentials annually or per your security policy
  • Monitor for authentication failures in ThreatAware regularly
Security Considerations
  • Only grant permissions necessary for monitoring
  • Restrict firewall access to authorised IP addresses only
  • Use port forwarding to limit direct exposure
  • Review API usage in Trend Micro periodically
  • Follow your organisation’s least privilege principles