About the Device
Vectra Stream™ from Vectra® delivers scalable, security-enriched metadata from native cloud, hybrid cloud and enterprise traffic that empowers skilled security analysts and threat hunters to perform conclusive incident investigations.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Vectra (Previously Known as TraceVector) |
Product Name | Stream |
Type of Device | Hosted |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol | Log collection method |
---|---|---|---|
Vectra Stream | VECTRA_STREAM | Syslog | CyberHub |
Port Requirements
Source | Destination | Port |
---|---|---|
Vectra | CyberHub | 601 (TCP) |
Device Configuration
To update Destination Publisher Configuration to forward logs to CyberHub:
Log in to Vectra UI with Admin or Similar privileges.
Navigate to Settings > Cognito Stream and Edit the Destination Configuration from Vectra UI.
Select SYSLOG from Publisher
Set up the following parameters
Select TCP from Protocol
Enter CyberHub IP Address in Server IP/Hostname textbox.
Enter 601 in Port textbox.
Click Save.
To enable all the metadata types for forwarding:
From the Vectra UI, navigate to Settings > Cognito Stream > Metadata Types and select all metadata types.
Click Save.
To turn on meta data forwarding:
From the Vectra UI, navigate to Settings > Stream > Cognito Stream Metadata Forwarding.
Click Save.
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
IP Address | Vectra Stream interface IP address | Hostname or IP address of the device which forwards logs to the CyberHub |