...
Source | Destination | Port |
---|---|---|
Vectra Detect | CyberHub | 601(TCP) |
To facilitate secure communication and align with our best practice, we strongly encourage the use of Transport Layer Security (TLS) between your security devices and our Adaptive MxDR platform for event forwarding.
While we understand that TLS support may not be available on all devices, if your devices do support TLS communication, we recommend utilizing port 6514 for seamless integration.
In some cases, the upgraded version of the device might incorporate TLS support without prior notice. If you come across such a scenario or for further assistance in configuring TLS, we kindly ask you to reach out to your dedicated Adaptive MxDR Service Delivery Lead.
Device Configuration
Log in to Vectra Brain/Detect UI.
Navigate to Settings → Notification → Syslog
Configure DESTINATION (Enter the IP address of CyberHUB), PORT and PROTOCOL.
Select FORMAT as JSON.
Select ALL LOG TYPES.
Enable 'Include filtered Detections’, ‘Include detections in info category’, ‘Include host/account score decreases’ and ‘Include enhanced detail’.
Click Save to complete the configuration and click Test to verify Syslog configuration.
...