Send data via Trend Micro to your Logstash instance provided by

Trend Micro

Ship Trend Micro logs to logstash

Step 1 - Configure Trend Micro to forward logsCopy

Configure Trend Micro to send logs to TCP port 9000 of your Filebeat server.

You can consult the Trend Micro documentation to do this.

Step 2 - Install the Trend Micro certificateCopy

Trend Micro sends data in an encrypted format.

You need to install the Trend Micro certificate on your Filebeat server.

sudo mkdir /etc/filebeat/certificates
sudo openssl req -newkey rsa:2048 -nodes \
-keyout /etc/filebeat/certificates/Trendmicro.key -x509 \
-days 365 \
-out /etc/filebeat/certificates/Trendmicro.crt

Step 2 - Install FilebeatCopy

deb (Debian/Ubuntu/Mint)

curl -L -O
sudo dpkg -i -oss-7.15.1-amd64.deb

rpm (CentOS/RHEL/Fedora)

curl -L -O
sudo rpm -vi -oss-7.15.1-x86_64.rpm


curl -L -O
tar xzvf -oss-7.15.1-darwin-x86_64.tar.gz


  • Download and extract the Windows zip file.
  • Rename the -<version>-windows directory to ``.
  • Open a PowerShell prompt as an Administrator.
  • Run the following to install as a Windows service:
If script execution is disabled on your system, you need to set the execution policy for the current session to allow the script to run. For example: PowerShell.exe -ExecutionPolicy UnRestricted -File .\install-service-.ps1.
Step 3 - Configure FilebeatCopy

Copy and use the Filebeat configuration below.

Replace <APACHE_STORM_LOGS_PATH> with the path you located in step one.

For use with version 7.x Filebeats.
# ============================== Filebeat inputs ==============================
- type: tcp
  max_message_size: 10MiB

  host: ""
  ssl.enabled: true
  ssl.certificate: "/etc/filebeat/certificates/Trendmicro.crt"
  ssl.key: "/etc/filebeat/certificates/Trendmicro.key"
  ssl.verification_mode: none

    type: trend_micro
  fields_under_root: true
  ignore_older: 3h

filebeat.registry.path: /var/lib/filebeat

# ================================== Outputs ===================================
<div class="sw-warning">
Step 4 - Start FilebeatCopy

Ok, time to start ingesting data!


sudo systemctl enable filebeat
sudo systemctl start filebeat




PS C:\Program Files\Filebeat> Start-Service filebeat

Step 5 - how to diagnose no data in StackCopy

If you don't see data appearing in your Stack after following the steps, visit the Help Centre guide for steps to diagnose no data appearing in your Stack or Chat to support now.

