Vectra Stream (syslog)
Configure Vectra Stream for syslog log forwarding to Radiant Security.
In this guide, you will create a new entry in the Vectra Stream Syslog configuration. This is required in order to send Vectra Stream logs to Radiant Security with the use of an intermediary syslog relay server for additional security.
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors and click + Add Connector.
Search for and select the Vectra Stream (syslog) option and then click Data Feeds, then click Credentials.
Under Credential Name, give the credential an identifiable name (e.g.
Vectra Stream Credentials
). If you already have a credential in place, select it from the drop-down menu. Click Credentials.In the Connector tag field, enter a random value. This value will act as the salt to randomize the unique Token you’ll download in the next step.
Click Add Connector.
Important note: Vectra Stream provides network events but not alerts. In case you have Vectra NDR, it is critical to onboard it as well in order for Radiant Security to ingest the network alerts to be triaged and investigated using the network logs ingested from Vectra Stream. To onboard Vectra NDR, see the Vectra NDR (syslog) guide.
Configure a local Radiant Security Agent
Refer to the Install the Radiant Security Agent guide to set up a local agent to collect the logs.
Configure syslog forwarding
In this section, you'll create a new syslog entry on the Vectra platform.
Login to Vectra (Brain) with admin ID.
Go to Settings > Cognito Stream > Destination.
On the Destination section, enter the following parameters:
Publisher:
Syslog
Protocol:
TCP
Server IP/Hostname:
<radiantSecuritySyslogCollectorIP>
Port:
7514
Click Save.
Still on the Cognito Stream page, enable the Cognito Stream Metadata Forwarding.
Click Save.
Last updated