Logmanager documentation
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Vectra Cognito

Vectra Cognito NDR can be configured to send notification events via syslog to Logmanager.

To configure Vectra Cognito external logging:

  1. Go to Settings > Notifications > Syslog > Edit
  2. Put in the Logmanager IP address or hostname.
  3. Put in the Logmanager destination port.
  4. Select protocol TCP. You can also select UDP but it is not recommended. If you wish to use SSL encryption, select it and put in 6514 as the destination port.
  5. Select format CEF. Other formats will not work.
  6. Select log types you wish to forward to Logmanager.
  7. Select additional conditions you are interested in.
  8. Set Include enhanced details to ON.
    Vectra syslog settings

    Vectra syslog settings

Additional logging details can be found here: https://support.vectra.ai/s/article/KB-VS-1233