Skip to end of metadata
Go to start of metadata

You are viewing an old version of this content. View the current version.

Compare with Current View Version History

« Previous Version 2 Current »

About the Device

Vectra Cognito Detect is now known as Vectra Detect. It is a network-based threat detection and response solution that provides visibility and control over network traffic.

Vectra Detect provides a number of benefits, including:

Comprehensive threat detection: Detect uses a variety of techniques to detect threats, including machine learning, behavioral analysis, and anomaly detection.
Actionable insights: Detect provides actionable insights that can be used to investigate and respond to threats.
Integration with other security tools: Detect can be integrated with other security tools, such as firewalls and intrusion detection systems, to provide a comprehensive security solution.

Device Information

 Entity

Particulars

Vendor Name

Vectra (Previously Known as TraceVector)

Product Name

Detect (Previously Known as Cognito Detect)

Type of Device

Hosted

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log collection method

Vectra Detect

VECTRA_DETECT

Syslog - JSON

CyberHub

Port Requirements

Source

Destination

Port

Vectra Detect

CyberHub

601(TCP)

Device Configuration

  1. Log in to Vectra Brain/Detect UI.

  2. Navigate to SettingsNotificationSyslog

  3. Configure DESTINATION (Enter the IP address of CyberHUB), PORT and PROTOCOL.

  4. Select FORMAT as JSON.

  5. Select ALL LOG TYPES.

  6. Enable 'Include filtered Detections’, ‘Include detections in info category’, ‘Include host/account score decreases’ and ‘Include enhanced detail’.

  7. Click Save to complete the configuration and click Test to verify Syslog configuration.

Integration Parameters

Parameters required from customer for Integration.

Property

Default Value

Description

IP Address

Vectra Detect interface IP address

Hostname or IP address of the device which forwards logs to the CyberHub

  • No labels