Configure Vectra NDR for syslog log forwarding to Radiant Security.
Overview
In this guide, you will create a new entry in the Vectra NDR Syslog configuration. This is required in order to send Vectra NDR alerts to Radiant Security with the use of an intermediary syslog relay server for additional security.
To do this, you’ll need to complete the following configuration steps:
- Add the data connector in Radiant Security
- Install the Radiant Security Agent
- Configure syslog forwarding
Add the data connector in Radiant Security
Important note: Vectra NDR provides network alerts but not event alerts. In case you have Vectra Stream, it is critical to onboard it in order for Radiant Security to ingest the network events that will allow our engine to triage and investigate the Vectra NDR alerts. To onboard Vectra Stream, see the Vectra Stream (syslog) guide.
Configure a local Radiant Security Agent
Refer to the Install the Radiant Security Agent guide to set up a local agent to collect the logs.
Configure syslog forwarding
In this section, you'll create a new syslog entry on the Vectra platform.
We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai
Last updated: 2025-02-17