LogoLogo
⌘Ctrlk
  • Documentation
  • Release Notes
  • API Reference
  • Help Center
AI Assistant
Good night

I'm here to help you with the docs.

⌘Ctrli
AI Based on your context
LogoLogo
  • 🏠Welcome
    • Getting started
    • IDR for Azure AD & CDR for M365
    • CDR for AWS
    • CDR for Azure
    • NDR physical appliances
    • NDR virtual / cloud appliances
    • NDR Traffic engineering and validation
    • Match
    • Stream
    • Recall (QUX only)
    • Appliance operations
    • Deprecated / Retired
    • Navigation updates in the Vectra UI
    • ACCESS
    • COVERAGE
    • RESPONSE
      • Lockdown
      • Notifications
      • SIEM
        • Microsoft Sentinel SIEM integration (RUX)
        • Microsoft Sentinel SIEM Codeless Connector Framework (RUX)
        • Microsoft Defender XDR Codeless Connector Framework (RUX)
        • Vectra RUX Playbooks for Microsoft Sentinel CCF
        • Vectra RUX Best Practices for Microsoft Sentinel CCF
        • Microsoft Sentinel NDR (Detect) integration using AMA
        • Azure Sentinel Stream integration using AMA
        • Azure Sentinel Stream integration using OMS (Deprecated)
        • Crowdstrike Next-Gen SIEM integration (RUX)
        • Crowdstrike Next-Gen SIEM integration (QUX)
        • Google SecOps SIEM integration (QUX)
        • Google SecOps SIEM integration (RUX)
        • Google SecOps SIEM Stream integration
        • QRadar SIEM integration (RUX)
        • QRadar SIEM Integration (QUX)
        • Splunk On-Prem SIEM / Vectra integration guide (start here for RUX)
        • Splunk Cloud SIEM / Vectra integration guide (start here for RUX)
        • Splunk SIEM / Vectra integration guide (start here for QUX)
        • Splunk - Vectra Detect Add-On and Syslog Configuration (QUX)
        • Splunk - Vectra Detect Integration Steps (QUX)
        • Splunk TA - Changing from CEF to JSON for Vectra Detect (QUX)
        • Splunk - Vectra SaaS Add-on Configuration (QUX)
      • SOAR
      • Ticketing / CMDB
    • SETUP
    • TUNING
    • QUX specific
    • Response
    • SOAR
    • ITSM
    • Coverage
    • Context
    • SIEM
    • Access / Authentication
    • Notifications / Data Export
    • Analyst Guidance
    • Updates
    • Dashboards and Reports
    • Detection specific guidance
    • Licensing
    • Backup / Restore / DR
    • Investigate
    • General
    • AI and ML terminology
    • Vectra AI prioritization and scoring factors
    • Appliance support and EOS / EOL policy
    • Bandwidth used between Sensor and Brain
    • How detection PCAPs are generated
    • In-App support
    • Metadata attributes
    • Product Security
    • RSPAN and ERSPAN support
    • Host ID best practices and functionality
    • Vectra's coverage of MITRE ATT&CK and D3FEND
    • Vectra UI supported browsers
    • Why is metadata sharing important
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Documentation
  2. Configuration
  3. RESPONSE

SIEM

SIEM integration guides for forwarding Vectra detections, entity data, and telemetry to supported security platforms.

Microsoft Sentinel SIEM integration (RUX)Microsoft Sentinel SIEM Codeless Connector Framework (RUX)Azure Sentinel Stream integration using AMAAzure Sentinel Stream integration using OMS (Deprecated)Crowdstrike Next-Gen SIEM integration (RUX)Crowdstrike Next-Gen SIEM integration (QUX)Google SecOps SIEM integration (QUX)Google SecOps SIEM integration (RUX)Google SecOps SIEM Stream integrationMicrosoft Sentinel NDR (Detect) integration using AMAQRadar SIEM integration (RUX)QRadar SIEM Integration (QUX)Splunk On-Prem SIEM / Vectra integration guide (start here for RUX)Splunk Cloud SIEM / Vectra integration guide (start here for RUX)Splunk SIEM / Vectra integration guide (start here for QUX)Splunk - Vectra Detect Add-On and Syslog Configuration (QUX)Splunk - Vectra Detect Integration Steps (QUX)Splunk TA - Changing from CEF to JSON for Vectra Detect (QUX)Splunk - Vectra SaaS Add-on Configuration (QUX)Vectra RUX Playbooks for Microsoft Sentinel CCFVectra RUX Best Practices for Microsoft Sentinel CCF
PreviousSystem alertsNextMicrosoft Sentinel SIEM integration (RUX)

Last updated 2 months ago

Was this helpful?

LogoLogo
linkedinx-twitterfacebookyoutubeinstagramreddit

© 2026 Vectra AI, Inc. All rights reserved.

Was this helpful?