Darktrace NDR
Connect Darktrace NDR to Radiant Security to forward AI Analyst and Model Breach alerts for AI triage.
Last updated
Was this helpful?
Connect Darktrace NDR to Radiant Security to forward AI Analyst and Model Breach alerts for AI triage.
Darktrace NDR is a network detection and response platform that uses self-learning AI to identify anomalous behavior, lateral movement, and emerging threats across on-premises, cloud, and hybrid networks. Connecting Darktrace NDR forwards AI Analyst alerts, Model Breach alerts, and system status alerts to Radiant Security via syslog through a Radiant Agent. Radiant uses these alerts during the Enrichment stage to correlate network anomalies with other telemetry.
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select Darktrace NDR, then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g., Radiant Agent integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.
Click Add Connector.
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive Darktrace NDR data. If you do not know the port, contact your Customer Success representative.
Log in to the Darktrace Console.
Navigate to the Admin panel.
Under System Configuration, navigate to Modules > Darktrace/Cloud.

Under Workflow Integrations, click Syslog.
Click the Syslog JSON tab.
Enter the following values:
Send Alerts: Enabled
Server: the IP address of the Radiant Agent
Server Port: the port configured on the Radiant Agent to receive Darktrace NDR data
Use Application Name: Enabled
Application Name: darktrace
Send AI Analyst Alerts: Enabled
AI Analyst Behavior Filter: Compliance, Critical, Suspicious
Send Model Breach Alerts: Enabled
Model Breach Behavior Filter: Compliance, Critical, Suspicious
Send System Status Alerts: Enabled
Send Resolved System Status Alerts: Enabled
Minimum System Status Priority: High
Master: All
At the top of the Syslog Workflow Integration window, toggle on the Enabled button.
Click Save.
After Darktrace NDR begins forwarding, confirm alerts are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"darktrace_ndr".
Confirm recent alerts appear.
Allow several minutes for alerts to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?