> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/configuration.md).

# Configuration

- [Navigation updates in the Vectra UI](https://docs.vectra.ai/configuration/navigation-updates-rux.md): Changes to Vectra UI menu navigation, including updated locations for common settings and workflows.
- [ACCESS](https://docs.vectra.ai/configuration/access.md): Access configuration articles for APIs, authentication, SAML SSO, remote support, and other ways to connect to the Vectra platform.
- [API (RUX)](https://docs.vectra.ai/configuration/access/api-rux.md): RUX API guides, Postman quick starts, and versioned references for working with the Vectra platform API.
- [RUX API Postman quick start guide](https://docs.vectra.ai/configuration/access/api-rux/rux-api-postman-quick-start-guide.md): Use the Vectra Platform public Postman collection to get up and running quickly with the new Vectra AI Platform API.
- [v3.4 API guide (RUX)](https://docs.vectra.ai/configuration/access/api-rux/v34-api-guide-rux.md): Vectra Platform API Guide v3.4 (August 2025) for RUX deployments
- [v3.3 API guide (RUX)](https://docs.vectra.ai/configuration/access/api-rux/v33-api-guide-rux.md): Vectra Platform API Guide v3.3 (Sep 2024) for Respond UX deployments
- [v3.2 API guide (RUX)](https://docs.vectra.ai/configuration/access/api-rux/v32-api-guide-rux.md): Vectra SaaS API Guide v3.2 (Jan 2024)
- [v3.1 API guide (RUX)](https://docs.vectra.ai/configuration/access/api-rux/v31-api-guide-rux.md): Vectra SaaS API Guide v3.1 (Jan 2024)
- [v3.0 API guide (RUX)](https://docs.vectra.ai/configuration/access/api-rux/v30-api-guide-rux.md): Vectra SaaS API Guide v3.0 (Jan 2024)
- [API (QUX)](https://docs.vectra.ai/configuration/access/api-qux.md): QUX API guides, Postman quick starts, OAuth2 setup, token authentication, and versioned Vectra API references.
- [v2.5 Postman quick start guide using OAuth2](https://docs.vectra.ai/configuration/access/api-qux/v25-postman-quick-start-guide-using-oauth2.md): This article shows how to quickly get started using the QUX v2.5 API using OAuth2 for authentication and the Postman API testing tool.
- [v2.5 Postman quick start guide using token auth](https://docs.vectra.ai/configuration/access/api-qux/v25-postman-quick-start-guide-using-token-auth.md): This article shows how to quickly get started using the QUX v2.5 API using token authentication and the Postman API testing tool.
- [v2.5 API guide (QUX)](https://docs.vectra.ai/configuration/access/api-qux/v25-api-guide-qux.md): This guide is for v2.5 of the Vectra REST API for QUX deployments.
- [v2.4 API guide (QUX)](https://docs.vectra.ai/configuration/access/api-qux/v24-api-guide-qux.md): This guide is for v2.4 of the Vectra REST API. For Vectra AI Platform (RUX) users, please see the v3.x REST API Guide.
- [v2.2 API guide (QUX)](https://docs.vectra.ai/configuration/access/api-qux/v22-api-guide-qux.md): This guide is for the v2.2 of the Vectra REST API. For Vectra AI Platform (RUX) users, please see the v3.x REST API Guide.
- [CLI (Vectra appliances)](https://docs.vectra.ai/configuration/access/cli-vectra-appliances.md): This article explores the commands available in the Command Line Interface (CLI) of Vectra appliances.
- [External Authentication (QUX)](https://docs.vectra.ai/configuration/access/external-authentication-qux.md): External authentication setup for QUX, including RADIUS, LDAP, and TACACS+ profile configuration.
- [RADIUS (QUX)](https://docs.vectra.ai/configuration/access/external-authentication-qux/radius-qux.md): Configure RADIUS authentication profiles in QUX and assign users to the appropriate external authentication profile.
- [LDAP (QUX)](https://docs.vectra.ai/configuration/access/external-authentication-qux/ldap-qux.md): Set up LDAP or Active Directory authentication for Vectra, including supported modes, setup steps, and user creation.
- [TACACS+ (QUX)](https://docs.vectra.ai/configuration/access/external-authentication-qux/tacacs-qux.md): Configure TACACS+ authentication profiles in QUX and migrate existing users to TACACS+ profiles with the API.
- [SAML SSO (RUX)](https://docs.vectra.ai/configuration/access/saml-sso-rux.md): SAML SSO configuration guides for RUX, including supported identity providers and setup workflows.
- [Any IdP SAML (RUX)](https://docs.vectra.ai/configuration/access/saml-sso-rux/any-idp-saml-rux.md): Enabling RUX (Respond UX) SAML SSO with any SAML 2.0 compliant Identity Provider (IdP).
- [ADFS SAML (RUX)](https://docs.vectra.ai/configuration/access/saml-sso-rux/adfs-saml-rux.md): Enabling RUX (Respond UX) SAML SSO with ADFS as the Identity Provider (IdP).
- [Entra ID (Azure AD) SAML (RUX)](https://docs.vectra.ai/configuration/access/saml-sso-rux/entra-id-azure-ad-saml-rux.md): Enabling RUX (Respond UX) SAML SSO with Entra ID (Azure AD) as the Identity Provider (IdP).
- [Keycloak SAML (RUX)](https://docs.vectra.ai/configuration/access/saml-sso-rux/keycloak-saml-rux.md): Enabling RUX (Respond UX) SAML SSO with Keycloak as the Identity Provider (IdP).
- [Okta SAML (RUX)](https://docs.vectra.ai/configuration/access/saml-sso-rux/okta-saml-rux.md): Enabling RUX (Respond UX) SAML SSO with Okta as the Identity Provider (IdP).
- [SAML SSO (QUX)](https://docs.vectra.ai/configuration/access/saml-sso-qux.md): SAML SSO configuration guides for QUX, including supported identity providers and profile setup workflows.
- [Any IdP SAML (QUX)](https://docs.vectra.ai/configuration/access/saml-sso-qux/any-idp-saml-qux.md): Enabling QUX (Quadrant UX) SAML SSO with any SAML 2.0 compliant Identity Provider (IdP).
- [ADFS SAML (QUX)](https://docs.vectra.ai/configuration/access/saml-sso-qux/adfs-saml-qux.md): Enabling QUX (Quadrant UX) SAML SSO with ADFS as the Identity Provider (IdP).
- [Entra ID (Azure AD) SAML (QUX)](https://docs.vectra.ai/configuration/access/saml-sso-qux/entra-id-azure-ad-saml-qux.md): Enabling QUX (Quadrant UX) SAML SSO with Entra ID (Azure AD) as the Identity Provider (IdP).
- [Okta SAML (QUX)](https://docs.vectra.ai/configuration/access/saml-sso-qux/okta-saml-qux.md): Enabling QUX (Quadrant UX) SAML SSO with Okta as the Identity Provider (IdP).
- [Ping Identity SAML (QUX)](https://docs.vectra.ai/configuration/access/saml-sso-qux/ping-identity-saml-qux.md): Enabling QUX (Quadrant UX) SAML SSO with Ping Identity as the Identity Provider (IdP).
- [Vectra remote support](https://docs.vectra.ai/configuration/access/vectra-remote-support.md): Configure and verify Vectra Remote Support for RUX and QUX, including VPN, UI, CLI, proxy, and connectivity requirements.
- [QUX deployments prior to v9.9](https://docs.vectra.ai/configuration/access/vectra-remote-support/qux-deployments-prior-to-v98.md): Remote support allows authorized Vectra personnel to connect to your Vectra (Brain). This article details how you can enable, disable, and verify the status of remote support.
- [RUX allow-list for UI and API](https://docs.vectra.ai/configuration/access/rux-allow-list-for-ui-and-api.md): Details about new allow list feature for RUX that limits access to customer configured IP ranges for both UI and API access and how to submit a ticket requesting it.
- [COVERAGE](https://docs.vectra.ai/configuration/coverage.md): Coverage configuration articles for brain setup, network identities, remote users, threat feeds, and related data sources.
- [Brain Setup](https://docs.vectra.ai/configuration/coverage/brain-setup.md): Brain setup guidance for configuring network coverage, identity context, and data sources in the Vectra platform.
- [IP address classfication](https://docs.vectra.ai/configuration/coverage/brain-setup/ip-address-classfication.md): Configure IP address classifications in RUX and QUX to improve network context and detection accuracy.
- [Network Identities (WELI)](https://docs.vectra.ai/configuration/coverage/network-identities-weli.md): Windows Event Log Ingestion guidance for adding network identity context through WELI and supported forwarding options.
- [Windows Event Log Ingestion (WELI)](https://docs.vectra.ai/configuration/coverage/network-identities-weli/windows-event-log-ingestion-weli.md): Configure WELI to send Kerberos security events to Vectra for PAA detections, Host ID enrichment, and investigation metadata.
- [WELI via NXLog](https://docs.vectra.ai/configuration/coverage/network-identities-weli/weli-via-nxlog.md): Configure NXLog forwarding for Windows Event Log Ingestion to provide identity context and Host ID data to Vectra.
- [WELI Splunk (Raw TCP / XML) configuration](https://docs.vectra.ai/configuration/coverage/network-identities-weli/weli-splunk-raw-tcp-xml-configuration.md): Windows Event Log Ingestion - Collecting Security Events with Splunk Universal Forwarders and sending data to Vectra in Raw TCP / XML format.
- [WELI Splunk (syslog / legacy) configuration](https://docs.vectra.ai/configuration/coverage/network-identities-weli/weli-splunk-syslog-legacy-configuration.md): Configure legacy Splunk syslog forwarding for WELI when XML-based ingestion is not available.
- [Remote Users](https://docs.vectra.ai/configuration/coverage/remote-users.md): Remote user coverage guides for SASE, SSE, VPN, Zscaler, Netskope, and log ingestion options.
- [Remote users (SASE / SSE)](https://docs.vectra.ai/configuration/coverage/remote-users/remote-users-sase-sse.md): Understand SASE and SSE remote user coverage options, including supported Zscaler and Netskope deployment patterns.
- [Netskope Cloud TAP](https://docs.vectra.ai/configuration/coverage/remote-users/netskope-cloud-tap.md): Configure Netskope Cloud TAP with Vectra NDR, including vSensor setup, SASE IP remapping, and Stitcher deployment guidance for AWS/Azure.
- [Zscaler ZIA](https://docs.vectra.ai/configuration/coverage/remote-users/zscaler-zia.md): This article discusses Vectra\&apos;s support of Zscaler Internet Access (ZIA) and provides details for use with both PCAP ingestion and on-prem capture.
- [Zscaler ZPA](https://docs.vectra.ai/configuration/coverage/remote-users/zscaler-zpa.md): Configure Zscaler ZPA log ingestion so Vectra can attribute private application traffic to remote users.
- [Zscaler ZPA log ingestion via QRadar](https://docs.vectra.ai/configuration/coverage/remote-users/zscaler-zpa-log-ingestion-via-qradar.md): Forward Zscaler ZPA LSS logs from QRadar to Vectra for remote user attribution and traffic visibility.
- [Optimizing Vectra for use with VPN clients](https://docs.vectra.ai/configuration/coverage/remote-users/optimizing-vectra-for-use-with-vpn-clients.md): How to optimize Vectra observability for VPN clients by using Sensor placement, SASE/SSE integration, EDR integration, Windows Event Log Ingestion, and rDNS.
- [Threat Feeds](https://docs.vectra.ai/configuration/coverage/threat-feeds.md): Threat feed configuration articles for external STIX feeds and Vectra-managed threat intelligence.
- [External threat intel integration](https://docs.vectra.ai/configuration/coverage/threat-feeds/external-threat-intel-integration.md): Configure external STIX 1.2 threat feeds so Vectra can detect malicious IPs, domains, URLs, and user agents.
- [Vectra threat intelligence](https://docs.vectra.ai/configuration/coverage/threat-feeds/vectra-threat-intelligence.md): Learn how Vectra Threat Intel works, who can use it, and how to investigate threat intelligence matches.
- [Asset Inventory coverage best practices](https://docs.vectra.ai/configuration/coverage/asset-inventory-coverage-best-practices.md): Techniques and advice to help ensure good coverage for Asset Inventory, HostID, detections, and metadata used in investigations.
- [RESPONSE](https://docs.vectra.ai/configuration/response.md): Response configuration articles for lockdown actions, notifications, SIEM, SOAR, and ticketing integrations.
- [Lockdown](https://docs.vectra.ai/configuration/response/lockdown.md): Lockdown response options for accounts, hosts, and network traffic in supported Vectra deployments.
- [Active Directory Account Lockdown](https://docs.vectra.ai/configuration/response/lockdown/active-directory-account-lockdown.md): Configure and use Active Directory Account Lockdown, including permissions, automatic thresholds, notifications, API usage, and protected account caveats.
- [Active Directory Account Lockdown custom configuration](https://docs.vectra.ai/configuration/response/lockdown/active-directory-account-lockdown-custom-configuration.md): This article details new Account Lockdown custom configuration options that are available in v8.2+ of Vectra software.
- [Entra ID (Azure AD) Account Lockdown (RUX)](https://docs.vectra.ai/configuration/response/lockdown/entra-id-azure-ad-account-lockdown-rux.md): FAQ for Entra ID account lockdown in RUX, including availability, behavior, and response workflows.
- [Host Lockdown (EDR)](https://docs.vectra.ai/configuration/response/lockdown/host-lockdown-edr.md): Frequently asked questions about Host Lockdown which uses an integrated EDR to isolate a host as a response action.
- [Traffic Lockdown](https://docs.vectra.ai/configuration/response/lockdown/traffic-lockdown.md): Enable Traffic Lockdown to publish compromised host IPs to a firewall-consumable blocklist for network containment.
- [Notifications](https://docs.vectra.ai/configuration/response/notifications.md): Notification configuration for syslog, Kafka, external app alerts, and system health alerts.
- [External app alerts (webhook)](https://docs.vectra.ai/configuration/response/notifications/external-app-alerts-webhook.md): Configure webhook-based alert destinations for Vectra prioritization and system alerts in tools like Microsoft Teams.
- [Syslog guide (QUX)](https://docs.vectra.ai/configuration/response/notifications/syslog-guide-qux.md): Configure QUX syslog forwarding for scoring, detections, campaigns, audit logs, and system health alerts.
- [Syslog sending to Kafka](https://docs.vectra.ai/configuration/response/notifications/syslog-sending-to-kafka.md): Configure Kafka as a syslog destination for Vectra notifications, including bootstrap server and topic settings.
- [Syslog and Kafka message size limits (QUX)](https://docs.vectra.ai/configuration/response/notifications/syslog-and-kafka-message-size-limits-qux.md): Understand syslog and Kafka message truncation limits and how 16 KB log size caps can affect forwarded event fields.
- [System alerts](https://docs.vectra.ai/configuration/response/notifications/system-alerts.md): Review Vectra system health alerts for sensor connectivity, capture interfaces, disk health, bandwidth drops, and packet processing.
- [SIEM](https://docs.vectra.ai/configuration/response/siem.md): SIEM integration guides for forwarding Vectra detections, entity data, and telemetry to supported security platforms.
- [Microsoft Sentinel SIEM integration (RUX)](https://docs.vectra.ai/configuration/response/siem/azure-sentinel-siem-integration-rux.md): Deploy the Microsoft Sentinel (formerly Azure Sentinel) integration for Vectra Respond UX (package v3.3.0), including ingestion, workbooks, analytics rules, and playbooks.
- [Microsoft Sentinel SIEM Codeless Connector Framework (RUX)](https://docs.vectra.ai/configuration/response/siem/microsoft-sentinel-siem-codeless-connector-framework-rux.md)
- [Microsoft Defender XDR Codeless Connector Framework (RUX)](https://docs.vectra.ai/configuration/response/siem/microsoft-defender-xdr-codeless-connector-framework-rux.md)
- [Vectra RUX Playbooks for Microsoft Sentinel CCF](https://docs.vectra.ai/configuration/response/siem/vectra-rux-playbooks-for-microsoft-sentinel-ccf.md)
- [Vectra RUX Best Practices for Microsoft Sentinel CCF](https://docs.vectra.ai/configuration/response/siem/vectra-rux-best-practices-for-microsoft-sentinel-ccf.md): This guide covers operational best practices for running the Vectra RUX integration with Microsoft Sentinel. It assumes the connector, analytics rules, workbook, and playbooks are already deployed and
- [Microsoft Sentinel NDR (Detect) integration using AMA](https://docs.vectra.ai/configuration/response/siem/microsoft-sentinel-ndr-detect-integration-using-ama.md): Deploy or migrate Vectra Detect syslog CEF ingestion to Microsoft Sentinel using Azure Monitor Agent (AMA), including Logstash transformation and troubleshooting.
- [Azure Sentinel Stream integration using AMA](https://docs.vectra.ai/configuration/response/siem/azure-sentinel-stream-integration-using-ama.md): Deploy and configure the Vectra Stream app for Microsoft Sentinel using Azure Monitor Agent.
- [Azure Sentinel Stream integration using OMS (Deprecated)](https://docs.vectra.ai/configuration/response/siem/azure-sentinel-stream-integration-using-oms.md): Deprecated guide for sending Vectra Stream Raw JSON to Microsoft Sentinel via the OMS (Log Analytics) agent and a Linux collector.
- [Crowdstrike Next-Gen SIEM integration (RUX)](https://docs.vectra.ai/configuration/response/siem/crowdstrike-next-gen-siem-integration-rux.md): Ingest Vectra entity scoring events, detection events, and audit events from Vectra Respond UX.
- [Crowdstrike Next-Gen SIEM integration (QUX)](https://docs.vectra.ai/configuration/response/siem/crowdstrike-nextgen-siem-integration-qux.md): Send Vectra Detect (QUX) logs to CrowdStrike NextGen-SIEM via a log collector and HEC, using the provided parser and setup guide.
- [Google SecOps SIEM integration (QUX)](https://docs.vectra.ai/configuration/response/siem/google-secops-siem-integration-qux.md): Ingest and parse Vectra Detect (QUX) syslog into Google SecOps SIEM for detections, entities, and audit/health/lockdown data.
- [Google SecOps SIEM integration (RUX)](https://docs.vectra.ai/configuration/response/siem/google-secops-siem-integration-rux.md): Integrate Vectra Respond UX (RUX) with Google SecOps SIEM using the Vectra API, with a deployment guide and configuration template.
- [Google SecOps SIEM Stream integration](https://docs.vectra.ai/configuration/response/siem/google-secops-siem-stream-integration.md): Forward Vectra Stream security-enriched metadata to Google SecOps SIEM via syslog, using the provided implementation guide.
- [QRadar SIEM integration (RUX)](https://docs.vectra.ai/configuration/response/siem/qradar-siem-integration-rux.md): Install and configure the QRadar integration for RUX, including API clients, workflows, and log source requirements.
- [QRadar SIEM Integration (QUX)](https://docs.vectra.ai/configuration/response/siem/qradar-siem-integration-qux.md): Install and configure the QRadar integration for QUX, including the Vectra Detect app, syslog log source setup, dashboards, saved searches, and troubleshooting.
- [Splunk On-Prem SIEM / Vectra integration guide (start here for RUX)](https://docs.vectra.ai/configuration/response/siem/splunk-siem-vectra-integration-guide-start-here-for-rux.md): Start here for Splunk integration with Vectra Respond UX, including supported add-ons/apps, install matrix, API client setup, and data inputs.
- [Splunk Cloud SIEM / Vectra integration guide (start here for RUX)](https://docs.vectra.ai/configuration/response/siem/splunk-siem-vectra-integration-guide-start-here-for-rux-1.md): Start here for Splunk Cloud integration with Vectra Respond UX, including supported add-ons/apps, install matrix, API client setup, and data inputs.
- [Splunk SIEM / Vectra integration guide (start here for QUX)](https://docs.vectra.ai/configuration/response/siem/splunk-siem-vectra-integration-guide-start-here-for-qux.md): This article serves as the starting point for Vectra\&apos;s various integrations with Splunk. Read this prior to any other articles regarding Splunk integration.
- [Splunk - Vectra Detect Add-On and Syslog Configuration (QUX)](https://docs.vectra.ai/configuration/response/siem/splunk-vectra-detect-add-on-and-syslog-configuration-qux.md): Install the Technology Add-on for Vectra Detect (JSON) and configure Detect syslog so Splunk parses events into the correct sourcetypes.
- [Splunk - Vectra Detect Integration Steps (QUX)](https://docs.vectra.ai/configuration/response/siem/splunk-vectra-detect-integration-steps-qux.md): End-to-end steps for integrating Vectra Detect (QUX) with Splunk, including which add-ons to install and how to configure the Detect app macro.
- [Splunk TA - Changing from CEF to JSON for Vectra Detect (QUX)](https://docs.vectra.ai/configuration/response/siem/splunk-ta-changing-from-cef-to-json-for-vectra-detect-qux.md): Migrate Splunk ingestion for Vectra Detect from legacy CEF syslog to full JSON using the new TA, with install, configuration, and validation steps.
- [Splunk - Vectra SaaS Add-on Configuration (QUX)](https://docs.vectra.ai/configuration/response/siem/splunk-vectra-saas-add-on-configuration-qux.md): Install and configure the Vectra SaaS add-on for Splunk, including API client details, proxy options, and data inputs for scoring and detections.
- [SOAR](https://docs.vectra.ai/configuration/response/soar.md): SOAR integration guides for connecting Vectra with Google SecOps, XSOAR, Splunk SOAR, and ServiceNow SIR.
- [Google SecOps SOAR integration (RUX)](https://docs.vectra.ai/configuration/response/soar/google-secops-soar-integration-rux.md): Install the Google SecOps SOAR integration for RUX, including actions, connector, job, and supported use cases.
- [Google SecOps SOAR integration (QUX)](https://docs.vectra.ai/configuration/response/soar/google-secops-soar-integration-qux.md): Install the Google SecOps SOAR integration for QUX, including actions, connector, job, and supported use cases.
- [Palo Alto XSOAR integration (QUX)](https://docs.vectra.ai/configuration/response/soar/palo-alto-xsoar-integration-qux.md): Configure Palo Alto XSOAR for QUX deployments, including content pack guidance and supported integration differences.
- [Palo Alto XSOAR integration (RUX)](https://docs.vectra.ai/configuration/response/soar/palo-alto-xsoar-integration-rux.md): Configure Palo Alto XSOAR for RUX deployments, including content pack details and UX-specific implementation notes.
- [Splunk SOAR integration (RUX)](https://docs.vectra.ai/configuration/response/soar/splunk-soar-integration-rux.md): Install and configure the Splunk SOAR app for RUX, including assets, actions, playbooks, and troubleshooting.
- [Splunk SOAR integration (QUX)](https://docs.vectra.ai/configuration/response/soar/splunk-soar-integration-qux.md): Install and configure the Splunk SOAR app for QUX, including assets, actions, playbooks, and troubleshooting.
- [ServiceNow SIR SOAR integration (RUX)](https://docs.vectra.ai/configuration/response/soar/servicenow-sir-soar-integration-rux.md): Configure the ServiceNow SIR SOAR integration for RUX and review supported ServiceNow platform versions.
- [ServiceNow SIR SOAR integration (QUX)](https://docs.vectra.ai/configuration/response/soar/servicenow-sir-soar-integration-qux.md): Configure the ServiceNow SIR SOAR integration for QUX, including compatibility, setup, actions, and limitations.
- [Palo Alto XSOAR-XSIAM Integration (RUX)](https://docs.vectra.ai/configuration/response/soar/palo-alto-xsoar-xsiam-integration-rux.md): Deploy the Palo Alto Cortex XSOAR/XSIAM integration for RUX, including incident mirroring, lifecycle sync, commands, and operational guidance.
- [Ticketing / CMDB](https://docs.vectra.ai/configuration/response/ticketing.md): Ticketing integration guides for ServiceNow ITSM and CMDB workflows with the Vectra platform.
- [ServiceNow ITSM ticketing integration (RUX)](https://docs.vectra.ai/configuration/response/ticketing/servicenow-itsm-ticketing-integration-rux.md): Configure ServiceNow ITSM ticketing for RUX and review supported ServiceNow platform versions.
- [ServiceNow ITSM ticketing integration (QUX)](https://docs.vectra.ai/configuration/response/ticketing/servicenow-itsm-ticketing-integration-qux.md): Configure ServiceNow ITSM ticketing for QUX, including MID Server setup, users, profiles, entities, and actions.
- [ServiceNow CMDB integration (RUX)](https://docs.vectra.ai/configuration/response/ticketing/servicenow-cmdb-integration-rux.md): Integrate Vectra asset discovery with ServiceNow CMDB to enrich asset records and security context.
- [SETUP](https://docs.vectra.ai/configuration/setup.md): Setup articles for account association, backup and restore, EDR integrations, external connectors, and proxies.
- [Account Association](https://docs.vectra.ai/configuration/setup/account-association.md): Link accounts across network, M365, Entra ID, Azure, and AWS activity to track attacks across identities and hosts.
- [EDR Integrations](https://docs.vectra.ai/configuration/setup/edr-integrations.md): EDR integration guides for adding endpoint context from supported providers to Vectra investigations.
- [Microsoft Defender for Endpoint](https://docs.vectra.ai/configuration/setup/edr-integrations/microsoft-defender-for-endpoint.md): Microsoft Defender for Endpoint FAQ, formerly Microsoft Defender ATP
- [Carbon Black Response](https://docs.vectra.ai/configuration/setup/edr-integrations/carbon-black-response.md): How to configure Carbon Black Response (On-Prem) integration
- [Carbon Black Cloud](https://docs.vectra.ai/configuration/setup/edr-integrations/carbon-black-cloud.md): Integrate Carbon Black Cloud EDR with Vectra to enrich hosts with endpoint context for investigations.
- [Trellix (FireEye) Endpoint Security (HX)](https://docs.vectra.ai/configuration/setup/edr-integrations/trellix-fireeye-endpoint-security-hx.md): Integrate Trellix FireEye Endpoint Security HX with Vectra to add host context and support response workflows.
- [SentinelOne](https://docs.vectra.ai/configuration/setup/edr-integrations/sentinelone.md): Integrate SentinelOne EDR with Vectra for Host Lockdown, host details, and Host ID enrichment.
- [Cybereason](https://docs.vectra.ai/configuration/setup/edr-integrations/cybereason.md): Integrate Cybereason EDR with Vectra to add endpoint host context for investigations and response.
- [Crowdstrike](https://docs.vectra.ai/configuration/setup/edr-integrations/crowdstrike.md): Integrate CrowdStrike EDR with Vectra for EDR process stitching, Host Lockdown, host details, and Host ID enrichment.
- [External Connectors](https://docs.vectra.ai/configuration/setup/external-connectors.md): External connector setup for host identity, cloud, Active Directory, vCenter, SIEM log ingestion, and related integrations.
- [Active Directory](https://docs.vectra.ai/configuration/setup/external-connectors/active-directory.md): Integrate Active Directory with Vectra NDR for host identity context in RUX and QUX deployments.
- [AWS Host ID integration](https://docs.vectra.ai/configuration/setup/external-connectors/aws-hostid-integration.md): This article goes over the AWS Host ID integration available for Vectra AI NDR deployments that see traffic from AWS VPCs.
- [Azure Host ID integration](https://docs.vectra.ai/configuration/setup/external-connectors/azure-hostid-integration.md): This article goes over the Azure Host ID integration available for Vectra AI NDR deployments that see traffic from Azure virtual networks.
- [GCP Host ID integration](https://docs.vectra.ai/configuration/setup/external-connectors/gcp-hostid-integration.md): This article goes over the GCP Host ID integration available for Vectra AI NDR deployments that capture traffic from GCP VPCs.
- [SIEM (Vectra Brain ingesting logs)](https://docs.vectra.ai/configuration/setup/external-connectors/siem-vectra-brain-ingesting-logs.md): Configure SIEM event forwarding to Vectra Brain for DHCP and selected Windows event log ingestion use cases.
- [vCenter integration (VMware)](https://docs.vectra.ai/configuration/setup/external-connectors/vcenter-integration-vmware.md): Configure the Vectra Brain to query the VMware vCenter API (read-only) for infrastructure visibility and vSensor planning.
- [Proxies](https://docs.vectra.ai/configuration/setup/proxies.md): This article is designed to assist in understanding how Vectra appliances interact with proxy systems.
- [TUNING](https://docs.vectra.ai/configuration/tuning.md): Tuning guidance for triage filters, AD groups, dynamic groups, and reducing noise from known benign scanning.
- [Triage best practices](https://docs.vectra.ai/configuration/tuning/triage-best-practices.md): Use triage filters to manage known detection behavior, improve scoring precision, and reduce repetitive alert review.
- [Active Directory (AD) groups](https://docs.vectra.ai/configuration/tuning/active-directory-ad-groups.md): Create and manage Active Directory groups in Vectra to simplify triage filters and influence entity urgency scoring.
- [Dynamic groups](https://docs.vectra.ai/configuration/tuning/dynamic-groups.md): How to create and manage dynamic groups that are based on regular expressions (regex) along with FAQs.
- [Creating triage filters via API](https://docs.vectra.ai/configuration/tuning/creating-triage-filters-via-api.md): Create and manage triage filters through the Vectra API, with examples for QUX API v2.5.
- [Noise elimination for Tanium and other mesh scanners](https://docs.vectra.ai/configuration/tuning/noise-elimination-for-tanium-and-other-mesh-scanners.md): Reduce benign detection noise from Tanium and other full-mesh scanners with targeted tuning recommendations.
- [QUX specific](https://docs.vectra.ai/configuration/qux-specific.md): QUX-specific configuration articles for SSL certificates, digest emails, login captions, and SMTP settings.
- [SSL certificate installation](https://docs.vectra.ai/configuration/qux-specific/ssl-certificate-installation.md): This article discusses SSL certificate options for Quadrant UX deployments. For RUX deployments, the cert used to support the GUI is fully managed by Vectra only.
- [Digest emails](https://docs.vectra.ai/configuration/qux-specific/digest-emails.md): Digest Emails provide a feature to send a summary of detections count per category in for last 24 hours
- [Login caption](https://docs.vectra.ai/configuration/qux-specific/login-caption.md): Create and manage a login caption in Vectra Quadrant UX.
- [SMTP configuration (QUX)](https://docs.vectra.ai/configuration/qux-specific/smtp-configuration-qux.md): Configure SMTP on QUX Brain appliances to send email alert notifications.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/configuration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
