Vectra Cognito
Vectra Cognito NDR can be configured to send notification events via syslog to Logmanager.
To configure Vectra Cognito external logging:
- Go to Settings > Notifications > Syslog > Edit
- Put in the Logmanager IP address or hostname.
- Put in the Logmanager destination port.
- Select protocol TCP. You can also select UDP but it is not recommended. If you wish to use SSL encryption, select it and put in 6514 as the destination port.
- Select format CEF. Other formats will not work.
- Select log types you wish to forward to Logmanager.
- Select additional conditions you are interested in.
- Set Include enhanced details to ON.

Vectra syslog settings
Additional logging details can be found here: https://support.vectra.ai/s/article/KB-VS-1233