Page cover
For the complete documentation index, see llms.txt. This page is also available as Markdown.

QRadar SIEM Integration (QUX)

Install and configure the QRadar integration for QUX, including the Vectra Detect app, syslog log source setup, dashboards, saved searches, and troubleshooting.

As stated in the summary, this article only applies to customers using Vectra's Quadrant UX. If you are using the Respond UX please see the QRadar Integration Guide for Vectra XDR (Respond UX) . If you are unsure of which UX you are using, please see Vectra Analyst User Experiences (Respond vs Quadrant).

Introduction

The Vectra Detect App for IBM QRadar enables QRadar analysts to ingest, view, and investigate Vectra signals from Vectra QUX / Vectra Detect.

This guide focuses on the Syslog-based source integration. In this deployment model, Vectra QUX sends Vectra signals to QRadar using the syslog protocol, and QRadar processes the events using the Vectra Detect App.

Video Demo of Deployment

A companion demo video for this article is available here:

Note: This video below also includes setup information for Vectra SaaS, which is deprecated and not covered in this guide. Some portions of the video are for the now deprecated Vectra SaaS deployment which has been replaced by the Respond UX (RUX). Some prerequisites still apply in the video for syslog deployment for QUX and specific steps for QUX integration, start at 6:00.

The UI shown in the video is older and may not match the current Vectra QUX UI. The Brain serial number may not be available in the same path shown in the video. Refer to this document for the updated steps to locate the Brain serial number in the current QUX UI.

The video walks through deployment requirements, required component setup, and configuration steps for bringing Vectra signals into QRadar.

For this guide, use the video only for the Vectra QUX / Syslog-based source (non-SaaS Deployment) configuration, where Vectra QUX sends Vectra Detect syslog output to QRadar.

Requirements

Before deploying the Vectra Detect App for IBM QRadar, ensure the following requirements are met.

QRadar Platform Requirements

Requirement
Details

QRadar version

QRadar v7.4.3 GA or later is required. If QRadar is running an older version, upgrade QRadar using the appropriate IBM update package before installing the Vectra Detect App.

QRadar Log Source Management App

The QRadar Log Source Management App must be installed before configuring Vectra log sources. Installing the QRadar Log Source Management App.

Vectra Detect App for QRadar

Install the Vectra Detect App for QRadar - QRadar v7.4.3 GA+ from IBM X-Force Exchange. Vectra Detect App for QRadar - QRadar v7.4.3 GA+

Syslog-Based Source Requirements

The Syslog-based source is used for Vectra QUX / Vectra Detect integrations where Vectra signals are sent to QRadar using the syslog protocol.

Requirement
Details

Syslog forwarding

Configure the Vectra deployment to send Vectra Detect syslog output to QRadar.

Brain serial number

Provide the Brain serial number. This is used as the log source identifier in QRadar.

QRadar log source

Create or configure the QRadar log source to receive Vectra syslog events.

Installation Process

This section provides the overall installation process for deploying or upgrading the Vectra Detect App for IBM QRadar for Vectra QUX / Vectra Detect integration. Links to the required applications and packages are provided in the Requirements section. Detailed configuration steps are covered in the sections that follow.

Common Installation Steps

  1. Ensure QRadar is running v7.4.3 GA or later.

    Updating QRadar is not covered in this guide. If an upgrade is required, work with IBM or your QRadar support partner.

  2. Ensure the QRadar Log Source Management App is installed.

    Installation of this app is not covered in this guide. Refer to the IBM documentation linked in the Requirements section.

  3. Install or upgrade the Vectra Detect App for QRadar - QRadar v7.4.3 GA+.

  4. Deploy the QRadar configuration after the app installation or upgrade is complete.

Syslog-Based Source Configuration

The Syslog-based source is used for Vectra QUX / Vectra Detect deployments that send Vectra signals to QRadar using syslog.

  1. Copy the Vectra Brain serial number for later use as the QRadar Log Source Identifier.

  2. Configure syslog output from Vectra QUX / Vectra Detect to QRadar.

  3. Configure the Vectra Detect syslog log source in QRadar.

  4. Deploy the QRadar configuration.

Installation of the Vectra Detect App for QRadar

This section describes how to install or upgrade the Vectra Detect App for QRadar for the Vectra QUX integration.

Upgrades from Prior Versions

The Vectra Detect App can be upgraded from a prior supported version when the existing app is installed on a supported QRadar version with App Framework v2 support.

For this guide, QRadar must be running v7.4.3 GA or later before installing or upgrading the app.

The same steps below can be used for both new installations and upgrades.

Installation Steps

  1. Log in to the QRadar console.

  2. Navigate to Admin > Extension Management.

  3. Click Add to upload and add a new extension.

  1. Select the Vectra Detect App for QRadar - QRadar v7.4.3 GA+ package.

  2. QRadar displays a list of changes that will be made by the app. Review the changes and click Install.

  1. After the installation completes, QRadar displays a confirmation message indicating that the app was installed successfully. The confirmation window also lists the components installed as part of the app.

Validate the Installation

To confirm that the installation was successful:

  1. Navigate to Admin > Extension Management.

  2. Locate Vectra Detect App for QRadar - QRadar v7.4.3 GA+.

  3. Confirm that the application status shows Installed.

After the app is installed, deploy the QRadar configuration before continuing with the Vectra QUX syslog log source configuration.

Vectra QUX Integration Configuration

This section applies to Vectra QUX / Vectra Detect deployments that send Vectra signals to QRadar.

Find and Copy the Log Source Identifier

In the Vectra UI, navigate to Configuration > Data Sources > Network > Brain Setup and copy the Brain serial number.

The Brain serial number will be used later as the Log Source Identifier when configuring the Vectra Detect log source in QRadar.

Configure Vectra Output to QRadar

In the Vectra UI, navigate to Settings > Notifications > Syslog.

Click the pencil icon or Edit > Add Destination to update the syslog settings.

Configure the following required settings:

Setting
Recommended value

Destination IP

Enter the IP address of the QRadar server or syslog listener

Destination Port

Enter the QRadar syslog listener port used in your environment

Protocol

TCP

Format

JSON

Log Types

Include all log types

Enhanced Detail

Enabled

Note: In the example screenshot, port 5141 is used. The default QRadar syslog listener port is 514. Use the port that matches your QRadar environment.

The following options can be selected based on your environment and reporting requirements:

Option
Description

Include filtered

Includes detections that have been triaged by AI or filtered by rules created in Vectra

Include detections in info

Controls whether Info category detections are forwarded

Include host/account score decreases

Controls whether host and account score decreases are forwarded

The Enhanced Detail option should be enabled. This provides additional event detail in the syslog output. The ability to disable enhanced detail is mainly intended for environments where a downstream tool is not configured to process the additional fields.

After completing the syslog configuration, save the settings and open the QRadar console to continue the QRadar-side log source configuration.

Configure the Vectra Detect Log Source in QRadar

This section describes how to configure the QRadar log source for Vectra QUX / Vectra Detect. This configuration allows QRadar to receive Vectra signals from the Vectra Brain.

Create a New Log Source

  1. In the QRadar console, navigate to Admin > Apps > Log Source Management.

  • Select Log Sources.

  • Click + New Log Source.

  • Select Single Log Source.

  • On the Select a Log Source Type screen, search for Vectra Detect.

  • Select Vectra Detect, then click Step 2: Select Protocol Type.

  • Select Syslog as the protocol.

  • Click Step 3: Configure Log Source Parameters.

Configure Log Source Parameters

On the Configure Log Source Parameters screen, configure the required fields listed below. Fields not listed here are optional unless required by your QRadar environment.

Field
Required value

Name

Enter a name for the log source, such as Vectra Brain

Extension

Select VectraDetectCustom_ext for post-processing of events after parsing

Coalescing Events

Uncheck this option to prevent QRadar from grouping events based on source and destination IP

After completing the required fields, click Step 4: Configure Protocol Parameters.

Configure Protocol Parameters

On the Configure Protocol Parameters screen, paste the Vectra Brain serial number into the Log Source Identifier field.

Use the same serial number that was copied earlier from Configuration > Data Sources > Network > Brain Setup in the Vectra Brain UI.

After entering the Log Source Identifier:

  1. Click Finish.

  2. Close the Log Source Management app.

  3. Deploy the QRadar configuration changes.

After the configuration is deployed, the Syslog-based Vectra Detect integration with QRadar is complete.

Supplemental Information

QRadar Deployment Guidance

The configuration steps in this guide assume that users are familiar with deploying configuration changes in QRadar.

If you are not familiar with the process, use the following steps:

  1. Navigate to the Admin panel in QRadar.

  2. Click Deploy Changes.

  3. From the Advanced dropdown, select Deploy Full Configuration.

A full configuration deployment is recommended after installing the required components, adding log sources, or making protocol-related configuration changes.

Uninstalling the Application

To uninstall the Vectra Detect App for QRadar, complete the following steps:

  1. Navigate to the Admin panel in QRadar.

  2. Open Extension Management.

  3. Select Vectra Detect App for QRadar - QRadar v7.4.3 GA+.

  4. Click Uninstall.

  5. Follow the QRadar prompts to complete the uninstallation.

After the application is removed, deploy the QRadar configuration changes if prompted.

Steps to Check Application Logs

This section describes how to check logs for the Vectra Detect App for QRadar.

Check Data Collection Logs

To check data collection logs, log in to the QRadar appliance using SSH as the root user.

Run the following command:

This command monitors QRadar logs and filters entries related to the Vectra Detect App for QRadar.

Check Dashboard Logs from the Application Container

Dashboard-related logs can be checked from inside the application container.

  1. Log in to the QRadar appliance using SSH as the root user.

  2. Run the following command to list the installed QRadar applications:

  1. From the output, locate the application named Vectra Detect App for QRadar and copy its App-ID.

  2. Connect to the application container using the App-ID:

  1. After connecting to the container, navigate to the application log directory:

  1. List the available log files:

  1. Review the required log file. For dashboard-related logs, check:

The app.log file contains logs related to the Vectra Detect App dashboard.

Visualizations

The Vectra Detect App for QRadar includes dashboards made up of individual panels. Each panel displays specific metrics based on Vectra signals received in QRadar.

All dashboards allow users to filter events by time range.

Overview Dashboard

The Overview dashboard provides high-level visibility into host scoring and detection events received from Vectra Detect.

This dashboard includes:

Panel
Description

Critical, High, Medium, and Low

Single-value panels showing event counts by severity. These panels use a Last 30 Days time range, regardless of the selected dashboard time filter.

Worst Offenders

Table panel showing entities with the highest level of activity or risk.

Key Assets

Table panel showing activity related to key assets.

Top 10 Detections by Type

Bar chart showing the most common detection types.

Top 10 Detections by Category

Bar chart showing the most common detection categories.

Dashboard Navigation

Users can drill down from the Overview dashboard into more detailed dashboards:

User action
Destination

Click a Critical, High, Medium, or Low single-value panel

Redirects to the Entities dashboard

Click a row in the Worst Offenders table

Redirects to the Detections dashboard

Click a row in the Key Assets table

Redirects to the Detections dashboard

Click a bar in the Top 10 Detections by Type chart

Redirects to the Detections dashboard

Click a bar in the Top 10 Detections by Category chart

Redirects to the Detections dashboard

Entities Dashboard

The Entities dashboard provides visibility into entity severity, account activity, and account lockout events.

This dashboard includes the following panels:

Panel
Description

Entity Severity Quadrant

Scatter chart that plots unique entities based on Threat and Certainty values

Entities List

Table panel showing the top 1000 logs for unique entities

Accounts List

Table panel showing account-related events

Accounts Currently Locked

Table panel showing accounts that are currently locked, based on the last 30 days of history

Accounts Locked During Selected Time Range

Table panel showing accounts that were locked during the selected dashboard time range

The Accounts Currently Locked panel uses a fixed last 30 days time range and is independent of the dashboard Time Range filter.

Dashboard Filters

The Entities dashboard supports the following filters:

Filter
Description

Time Range

Filters dashboard data based on the selected time period

Entity Type

Filters results by entity type

Search Filter

Allows users to search for specific entities or accounts

Severity

Filters table results by severity

Detections Dashboard

The Detections dashboard provides visibility into detection activity over time and allows users to review detailed detection events received from Vectra Detect.

This dashboard includes the following panels:

Panel
Description

Detection Type Activity Over Time

Area chart showing detection activity over the selected time range, grouped by detection type

Detections List

Table panel showing detailed detection events

Dashboard Filters

The Detections dashboard supports the following filters:

Filter
Description

Time Range

Filters detection data based on the selected time period

Detection Categories

Filters detections by category. This filter is dynamically populated based on the selected Time Range

Behavior

Filters detections by behavior. This dropdown is populated based on the selected Detection Category and Time Range

Type

Filters detections by detection type

Search Filter

Allows users to search for specific detection details

The Detection Categories filter is dynamically populated based on the selected Time Range. The Behavior filter is then populated based on both the selected Detection Category and the selected Time Range.

Campaigns Dashboard

The Campaigns dashboard provides visibility into campaign-related activity received from Vectra Detect.

This dashboard includes the following panels:

Panel
Description

Top 10 Campaign Activity

Bar chart showing the top 10 campaigns based on activity during the selected time range

Last Campaign Events

Table panel showing the most recent campaign-related events

Dashboard Filters

The Campaigns dashboard supports the following filters:

Filter
Description

Time Range

Filters campaign data based on the selected time period

Campaign Name

Filters events by campaign name. This filter is dynamically populated based on the selected Time Range

Type

Filters events by campaign type. This filter is dynamically populated based on the selected Time Range

The Campaign Name and Type filters are dynamically populated based on the selected Time Range.

Health Dashboard

The Health dashboard provides visibility into health-related logs received from Vectra Detect.

This dashboard includes the following panel:

Panel
Description

Last Health Logs

Table panel showing the most recent health-related logs

Dashboard Filters

The Health dashboard supports the following filters:

Filter
Description

Time Range

Filters health logs based on the selected time period

Result

Filters health logs by result status

Search Filter

Allows users to search within health log details

Audit Dashboard

The Audit dashboard provides visibility into audit-related logs received from Vectra Detect.

This dashboard includes the following panel:

Panel
Description

Last Audit Logs

Table panel showing the most recent audit-related logs

Dashboard Filters

The Audit dashboard supports the following filters:

Filter
Description

Time Range

Filters audit logs based on the selected time period

Result

Filters audit logs by result status

User

Filters audit logs by user

Search Filter

Allows users to search within audit log details

Notes for All Dashboards

The following notes apply to all dashboards in the Vectra Detect App for QRadar:

Item
Description

Search Filter

The Search Filter is case-sensitive across all dashboards.

Search behavior

The entered search value is searched against the raw event payload.

Table result limit

Most table panels are limited to 1000 records.

Worst Offenders and Key Assets limit

The Worst Offenders and Key Assets table panels are limited to 10 records.

Information icon

An information icon is displayed on table panels to indicate the record limit. When users hover over the icon, a message is displayed.

For most table panels, the hover message is:

For the Worst Offenders and Key Assets table panels, the hover message is:

Saved Searches

The Vectra Detect App for QRadar also provides a number of saved searches that can be executed. To run a saved search, follow these steps:

  • Go to the "Log Activity" tab in QRadar.

  • Click on the Search dropdown and select "New Search".

  • Click on the "Group" dropdown and select "Vectra Detect".

  • Select a search from the list of Available Saved Searches and click on Load. To run the search in the Log Activity tab, click on the Search button situated at the bottom right corner.

  • The following saved searches are provided in the app and have a default Time Range of the last 30 days.

Worst Offenders

Worst Offenders - 7.4.3+

Key Assets

Key Assets - 7.4.3+

Hosts list

Hosts list - 7.4.3+

Accounts list

Accounts list - 7.4.3+

Accounts Currently Locked (30 days history)

Accounts Currently Locked (30 days history) - 7.4.3+

Accounts locked during the selected time range

Accounts locked during the selected time range - 7.4.3+

Detections list

Detections list - 7.4.3+

Last Campaign events

Last Campaign events - 7.4.3+

Last Health logs

Last Health logs - 7.4.3+

Last Audit logs

Last Audit logs - 7.4.3+

  • The saved searched ending with “-7.4.3+” should be used when using a QRadar instance with version high than 7.4.3.

Troubleshooting

This section describes common issues that may occur during deployment or while using the Vectra Detect App for QRadar, along with recommended troubleshooting steps.

Case 1: Vectra Events Appear as “Vectra Detect Message”

Problem

Vectra Detect events appear in QRadar as Vectra Detect Message instead of being mapped to the expected QRadar event category.

This can be seen in the Log Activity tab when searching for events from the Vectra Detect log source type.

Possible Cause

This issue may occur when:

  • A required field is missing from the raw event.

  • The event payload is larger than the QRadar default payload size.

  • The event payload is truncated before QRadar can parse it correctly.

By default, QRadar uses a payload size of 4096 bytes. If the Vectra event payload is larger than this value, increase the maximum payload size.

Troubleshooting Steps

  1. In QRadar, navigate to the Admin panel.

  2. Open System Settings.

  3. Switch to Advanced mode.

  4. Locate the following settings:

    • Max TCP Syslog Payload Length

    • Max UDP Syslog Payload Length

  5. Increase the values as needed.

    Recommended value:

  1. Click Deploy Changes.


Case 2: UI Issues in the App

Problem

A dashboard panel shows errors, does not load correctly, or displays unintended behavior.

Troubleshooting Steps

  1. Clear the browser cache.

  2. Reload the QRadar webpage.

  3. Reduce the selected dashboard time range and retry.

    QRadar queries may expire if the selected time range returns too much data.

  4. If the issue continues, collect logs and contact support using the steps listed in Case 6.


Case 3: Dashboard Does Not Populate After App Upgrade

Problem

After upgrading the Vectra Detect App from version 1.1.0 to 2.x, the dashboard does not populate even though Vectra data is visible in Log Activity.

Troubleshooting Steps

  1. Go to the QRadar Admin panel.

  2. Click Advanced.

  3. Select Deploy Full Configuration.

  4. After deployment completes, reload the Vectra Detect App dashboard.


Case 4: Other Issues Not Covered in This Document

Problem

The issue is not listed in this troubleshooting section, or the previous troubleshooting steps did not resolve the issue.

Troubleshooting Steps

Collect QRadar logs and provide them to support.

  1. In QRadar, navigate to the Admin panel.

  2. Open System and License Management.

  3. Select the host where the Vectra Detect App for QRadar is installed.

  4. Click Actions in the top panel.

  5. Select Collect Log Files.

  6. In the Log File Collection window, click Advanced Options.

  7. Select the following options:

    • Include Debug Logs

    • Application Extension Logs

    • Setup Logs (Current Version)

  8. Select 2 days as the data input range.

  9. Click Collect Log Files.

  10. Click Click here to download files.

This downloads the collected logs as a single ZIP file to your local machine.

Contact support and attach the downloaded ZIP file for further investigation.

Last updated

Was this helpful?