Vectra Networks
You can forward logs from Vectra Networks X-Series to SIEM (InsightIDR) to capture events as Third Party Alerts.
To send Vectra Networks logs to SIEM (InsightIDR):
Configure Vectra
You must configure Vectra Networks to send CEF logs to SIEM (InsightIDR).
To do this:
- Sign in to your Vectra Networks account.
- From the top right corner, select the Cogwheel and select the Settings page.
- Select the Notifications tab.

- At the bottom of the page, find the “Syslog” section and click the Edit button.
- In the “Destination” field, provide the IP address of your SIEM (InsightIDR) Collector.
- In the “Port” field, enter the port on your Collector that will receive the Vectra logs.

- In the “Protocol” field, select a protocol from the dropdown.
- In the “Format” field, select CEF as your log format.
- Click the Save button.
Configure SIEM (InsightIDR) to collect data from the event source
After you complete the prerequisite steps and configure the event source to send data, you must add the event source in SIEM (InsightIDR).
To configure the new event source in SIEM (InsightIDR):
- From the left menu, go to Data Collection and click Setup Event Source > Add Event Source.
- Do one of the following:
- Search for Vectra Networks X-Series in the event sources search bar.
- In the Product Type filter, select Third Party Alerts.
- Select the Vectra Networks X-Series event source tile.
- Choose your collector and name your event source if you want.
- Optionally choose to send unparsed logs.
- Specify the port and protocol you used during Vectra configuration.
- Click the Save button.