Good day Team,
I trust this message meets you well.
With the built-in Trend Vision One Event source plugin on InsightIDR, many true-positive alerts from the "Observed Attack Techniques" portion of Trend Vision One don't get ingested to the SIEM. The built-in Rapid7 API Ingestion method only ingests "Workbench Insights" or "Workbench Alerts" and leaves out "Observed Attack Techniques". Due to this gap in missed alerts we've resulted to relying on the Custom Logs ingestion method despite Trend Vision One Plugin already being supported by InsightIDR.
Please kindly help fix this by adjusting the API ingestion method to also ingest alerts from the "Observed attack techniques" section of Trend Vision One asides only the Workbench. These alerts also triggering built-in detection rules would be super great and much appreciated as it enhances security detection coverage.
https://automation.trendmicro.com/xdr/api-fedramp/#tag/Observed-Attack-Techniques
Looking forward to your feedback and many thanks in anticipation.