> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/configuration/response/siem/qradar-siem-integration-qux.md).

# QRadar SIEM Integration (QUX)

As stated in the summary, this article only applies to customers using Vectra's Quadrant UX. If you are using the Respond UX please see the [QRadar Integration Guide for Vectra XDR (Respond UX)](/configuration/response/siem/qradar-siem-integration-rux.md) . If you are unsure of which UX you are using, please see [Vectra Analyst User Experiences (Respond vs Quadrant)](/deployment/getting-started/analyst-ux-options-rux-vs-qux.md).

## Introduction

The Vectra Detect App for IBM QRadar enables QRadar analysts to ingest, view, and investigate Vectra signals from **Vectra QUX / Vectra Detect**.

This guide focuses on the **Syslog-based source** integration. In this deployment model, Vectra QUX sends Vectra signals to QRadar using the **syslog protocol**, and QRadar processes the events using the Vectra Detect App.

## Video Demo of Deployment

A companion demo video for this article is available here:

{% hint style="info" %}
**Note:** This video below also includes setup information for Vectra SaaS, which is deprecated and not covered in this guide. Some portions of the video are for the now deprecated Vectra SaaS deployment which has been replaced by the Respond UX (RUX). Some prerequisites still apply in the video for syslog deployment for QUX and specific steps for QUX integration, start at **6:00**.

The UI shown in the video is older and may not match the current Vectra QUX UI. The Brain serial number may not be available in the same path shown in the video. Refer to this document for the updated steps to locate the Brain serial number in the current QUX UI.

The video walks through deployment requirements, required component setup, and configuration steps for bringing Vectra signals into QRadar.

For this guide, use the video only for the **Vectra QUX / Syslog-based source (non-SaaS Deployment)** configuration, where Vectra QUX sends Vectra Detect syslog output to QRadar.
{% endhint %}

{% embed url="<https://vimeo.com/743465615/3d2d7f8e33>" %}

## Requirements

Before deploying the Vectra Detect App for IBM QRadar, ensure the following requirements are met.

#### QRadar Platform Requirements

| Requirement                      | Details                                                                                                                                                                                                                                                            |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| QRadar version                   | QRadar v7.4.3 GA or later is required. If QRadar is running an older version, upgrade QRadar using the appropriate IBM update package before installing the Vectra Detect App.                                                                                     |
| QRadar Log Source Management App | <p>The QRadar Log Source Management App must be installed before configuring Vectra log sources.<br><a href="https://www.ibm.com/docs/en/qradar-common?topic=app-installing-qradar-log-source-management">Installing the QRadar Log Source Management App</a>.</p> |
| Vectra Detect App for QRadar     | <p>Install the <strong>Vectra Detect App for QRadar - QRadar v7.4.3 GA+</strong> from IBM X-Force Exchange.<br><a href="https://apps.xforce.ibmcloud.com/extension/47f3e9afff5e0281d6684bb633d769f2">Vectra Detect App for QRadar - QRadar v7.4.3 GA+</a></p>      |

#### Syslog-Based Source Requirements

The Syslog-based source is used for **Vectra QUX / Vectra Detect** integrations where Vectra signals are sent to QRadar using the **syslog protocol**.

| Requirement         | Details                                                                               |
| ------------------- | ------------------------------------------------------------------------------------- |
| Syslog forwarding   | Configure the Vectra deployment to send Vectra Detect syslog output to QRadar.        |
| Brain serial number | Provide the Brain serial number. This is used as the log source identifier in QRadar. |
| QRadar log source   | Create or configure the QRadar log source to receive Vectra syslog events.            |

## Installation Process

This section provides the overall installation process for deploying or upgrading the **Vectra Detect App for IBM QRadar** for **Vectra QUX / Vectra Detect** integration. Links to the required applications and packages are provided in the Requirements section. Detailed configuration steps are covered in the sections that follow.

#### Common Installation Steps

1. Ensure QRadar is running **v7.4.3 GA or later**.

   Updating QRadar is not covered in this guide. If an upgrade is required, work with IBM or your QRadar support partner.
2. Ensure the **QRadar Log Source Management App** is installed.

   Installation of this app is not covered in this guide. Refer to the IBM documentation linked in the Requirements section.
3. Install or upgrade the **Vectra Detect App for QRadar - QRadar v7.4.3 GA+**.
4. Deploy the QRadar configuration after the app installation or upgrade is complete.

#### Syslog-Based Source Configuration

The Syslog-based source is used for **Vectra QUX / Vectra Detect** deployments that send Vectra signals to QRadar using syslog.

1. Copy the Vectra Brain serial number for later use as the QRadar **Log Source Identifier**.
2. Configure syslog output from Vectra QUX / Vectra Detect to QRadar.
3. Configure the Vectra Detect syslog log source in QRadar.
4. Deploy the QRadar configuration.

## Installation of the Vectra Detect App for QRadar

This section describes how to install or upgrade the **Vectra Detect App for QRadar** for the Vectra QUX integration.

#### Upgrades from Prior Versions

The Vectra Detect App can be upgraded from a prior supported version when the existing app is installed on a supported QRadar version with App Framework v2 support.

For this guide, QRadar must be running **v7.4.3 GA or later** before installing or upgrading the app.

The same steps below can be used for both new installations and upgrades.

#### Installation Steps

1. Log in to the QRadar console.
2. Navigate to **Admin > Extension Management**.
3. Click **Add** to upload and add a new extension.

![](/files/MRNSCgrT8rWldh0rR5SB)

4. Select the **Vectra Detect App for QRadar - QRadar v7.4.3 GA+** package.
5. QRadar displays a list of changes that will be made by the app. Review the changes and click **Install**.

![](/files/vctIbX7Qvf2f576WCkTm)

6. After the installation completes, QRadar displays a confirmation message indicating that the app was installed successfully. The confirmation window also lists the components installed as part of the app.

![](/files/9qaPuFyLkwyJgDANqnYw)

#### Validate the Installation

To confirm that the installation was successful:

1. Navigate to **Admin > Extension Management**.
2. Locate **Vectra Detect App for QRadar - QRadar v7.4.3 GA+**.
3. Confirm that the application status shows **Installed**.

After the app is installed, deploy the QRadar configuration before continuing with the Vectra QUX syslog log source configuration.

## Vectra QUX Integration Configuration

This section applies to **Vectra QUX / Vectra Detect** deployments that send Vectra signals to QRadar.

#### Find and Copy the Log Source Identifier

In the Vectra UI, navigate to ***Configuration > Data Sources > Network > Brain Setup*** and copy the Brain serial number.

The Brain serial number will be used later as the **Log Source Identifier** when configuring the Vectra Detect log source in QRadar.

<figure><img src="/files/eag24mtjAkS3ZxeZTDWO" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/BgQlUsKfPuBSi2kz05V7" alt=""><figcaption></figcaption></figure>

#### Configure Vectra Output to QRadar

In the Vectra UI, navigate to ***Settings > Notifications > Syslog**.*

<figure><img src="/files/PjOO893Ajz0O6j9x6Y1M" alt=""><figcaption></figcaption></figure>

Click the pencil icon or ***Edit > Add Destination*** to update the syslog settings.

Configure the following required settings:

| Setting          | Recommended value                                              |
| ---------------- | -------------------------------------------------------------- |
| Destination IP   | Enter the IP address of the QRadar server or syslog listener   |
| Destination Port | Enter the QRadar syslog listener port used in your environment |
| Protocol         | TCP                                                            |
| Format           | JSON                                                           |
| Log Types        | Include all log types                                          |
| Enhanced Detail  | Enabled                                                        |

{% hint style="info" %}
**Note:** In the example screenshot, port `5141` is used. The default QRadar syslog listener port is `514`. Use the port that matches your QRadar environment.
{% endhint %}

<figure><img src="/files/heDHcdkqc2wJJ4LVT2Fo" alt=""><figcaption></figcaption></figure>

The following options can be selected based on your environment and reporting requirements:

| Option                               | Description                                                                             |
| ------------------------------------ | --------------------------------------------------------------------------------------- |
| Include filtered                     | Includes detections that have been triaged by AI or filtered by rules created in Vectra |
| Include detections in info           | Controls whether Info category detections are forwarded                                 |
| Include host/account score decreases | Controls whether host and account score decreases are forwarded                         |

The **Enhanced Detail** option should be enabled. This provides additional event detail in the syslog output. The ability to disable enhanced detail is mainly intended for environments where a downstream tool is not configured to process the additional fields.

After completing the syslog configuration, save the settings and open the QRadar console to continue the QRadar-side log source configuration.

### Configure the Vectra Detect Log Source in QRadar

This section describes how to configure the QRadar log source for **Vectra QUX / Vectra Detect**. This configuration allows QRadar to receive Vectra signals from the Vectra Brain.

#### Create a New Log Source

1. In the QRadar console, navigate to ***Admin > Apps > Log Source Management**.*

![](/files/ZU715MU6IIvEKGTtr6rK)

* Select **Log Sources**.
* Click **+ New Log Source**.
* Select **Single Log Source**.

![](/files/ZU715MU6IIvEKGTtr6rK)

* On the **Select a Log Source Type** screen, search for **Vectra Detect**.
* Select **Vectra Detect**, then click **Step 2: Select Protocol Type**.

![](/files/hcaYBzXcgSUVIrJH5gtA)

* Select **Syslog** as the protocol.
* Click **Step 3: Configure Log Source Parameters**.

![](/files/SeA4qRyADbZmdBNzM1OM)

#### Configure Log Source Parameters

On the **Configure Log Source Parameters** screen, configure the required fields listed below. Fields not listed here are optional unless required by your QRadar environment.

| Field             | Required value                                                                                |
| ----------------- | --------------------------------------------------------------------------------------------- |
| Name              | Enter a name for the log source, such as `Vectra Brain`                                       |
| Extension         | Select `VectraDetectCustom_ext` for post-processing of events after parsing                   |
| Coalescing Events | Uncheck this option to prevent QRadar from grouping events based on source and destination IP |

After completing the required fields, click **Step 4: Configure Protocol Parameters**.

![](/files/hnwJhJf8V44MU92KG9z6)

#### Configure Protocol Parameters

On the **Configure Protocol Parameters** screen, paste the Vectra Brain serial number into the **Log Source Identifier** field.

Use the same serial number that was copied earlier from ***Configuration > Data Sources > Network > Brain Setup*** in the Vectra Brain UI.

After entering the Log Source Identifier:

1. Click **Finish**.
2. Close the Log Source Management app.
3. Deploy the QRadar configuration changes.

![](/files/HHo9SzoG6M59fSjVADij)

After the configuration is deployed, the Syslog-based Vectra Detect integration with QRadar is complete.

## Supplemental Information

#### QRadar Deployment Guidance

The configuration steps in this guide assume that users are familiar with deploying configuration changes in QRadar.

If you are not familiar with the process, use the following steps:

1. Navigate to the **Admin** panel in QRadar.
2. Click **Deploy Changes**.
3. From the **Advanced** dropdown, select **Deploy Full Configuration**.

A full configuration deployment is recommended after installing the required components, adding log sources, or making protocol-related configuration changes.

![](/files/qkhEIsOcy29zd3KIFWt2)

## Uninstalling the Application

To uninstall the **Vectra Detect App for QRadar**, complete the following steps:

1. Navigate to the **Admin** panel in QRadar.
2. Open **Extension Management**.
3. Select **Vectra Detect App for QRadar - QRadar v7.4.3 GA+**.
4. Click **Uninstall**.
5. Follow the QRadar prompts to complete the uninstallation.

After the application is removed, deploy the QRadar configuration changes if prompted.

## Steps to Check Application Logs

This section describes how to check logs for the Vectra Detect App for QRadar.

#### Check Data Collection Logs

To check data collection logs, log in to the QRadar appliance using SSH as the **root** user.

Run the following command:

```bash
tail -f /var/log/qradar.log /var/log/qradar.error | grep Vectra_Detect_App_for_QRadar
```

This command monitors QRadar logs and filters entries related to the Vectra Detect App for QRadar.

#### Check Dashboard Logs from the Application Container

Dashboard-related logs can be checked from inside the application container.

1. Log in to the QRadar appliance using SSH as the **root** user.
2. Run the following command to list the installed QRadar applications:

```bash
/opt/qradar/support/recon ps
```

3. From the output, locate the application named **Vectra Detect App for QRadar** and copy its **App-ID**.
4. Connect to the application container using the App-ID:

```bash
/opt/qradar/support/recon connect <App-ID>
```

5. After connecting to the container, navigate to the application log directory:

```bash
cd /opt/app-root/store/log
```

6. List the available log files:

```bash
ls
```

7. Review the required log file. For dashboard-related logs, check:

```bash
app.log
```

The `app.log` file contains logs related to the Vectra Detect App dashboard.

## Visualizations

The Vectra Detect App for QRadar includes dashboards made up of individual panels. Each panel displays specific metrics based on Vectra signals received in QRadar.

All dashboards allow users to filter events by time range.

### Overview Dashboard

The Overview dashboard provides high-level visibility into host scoring and detection events received from Vectra Detect.

This dashboard includes:

| Panel                           | Description                                                                                                                                         |
| ------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| Critical, High, Medium, and Low | Single-value panels showing event counts by severity. These panels use a Last 30 Days time range, regardless of the selected dashboard time filter. |
| Worst Offenders                 | Table panel showing entities with the highest level of activity or risk.                                                                            |
| Key Assets                      | Table panel showing activity related to key assets.                                                                                                 |
| Top 10 Detections by Type       | Bar chart showing the most common detection types.                                                                                                  |
| Top 10 Detections by Category   | Bar chart showing the most common detection categories.                                                                                             |

#### Dashboard Navigation

Users can drill down from the Overview dashboard into more detailed dashboards:

| User action                                               | Destination                           |
| --------------------------------------------------------- | ------------------------------------- |
| Click a Critical, High, Medium, or Low single-value panel | Redirects to the Entities dashboard   |
| Click a row in the Worst Offenders table                  | Redirects to the Detections dashboard |
| Click a row in the Key Assets table                       | Redirects to the Detections dashboard |
| Click a bar in the Top 10 Detections by Type chart        | Redirects to the Detections dashboard |
| Click a bar in the Top 10 Detections by Category chart    | Redirects to the Detections dashboard |

![](/files/r9qR8fpSvNbm0u5zIJx4)

### Entities Dashboard

The Entities dashboard provides visibility into entity severity, account activity, and account lockout events.

This dashboard includes the following panels:

| Panel                                      | Description                                                                                  |
| ------------------------------------------ | -------------------------------------------------------------------------------------------- |
| Entity Severity Quadrant                   | Scatter chart that plots unique entities based on Threat and Certainty values                |
| Entities List                              | Table panel showing the top 1000 logs for unique entities                                    |
| Accounts List                              | Table panel showing account-related events                                                   |
| Accounts Currently Locked                  | Table panel showing accounts that are currently locked, based on the last 30 days of history |
| Accounts Locked During Selected Time Range | Table panel showing accounts that were locked during the selected dashboard time range       |

The **Accounts Currently Locked** panel uses a fixed **last 30 days** time range and is independent of the dashboard Time Range filter.

#### Dashboard Filters

The Entities dashboard supports the following filters:

| Filter        | Description                                              |
| ------------- | -------------------------------------------------------- |
| Time Range    | Filters dashboard data based on the selected time period |
| Entity Type   | Filters results by entity type                           |
| Search Filter | Allows users to search for specific entities or accounts |
| Severity      | Filters table results by severity                        |

<figure><img src="/files/t0qeq7LXWpeizcxf80pw" alt=""><figcaption></figcaption></figure>

### Detections Dashboard

The Detections dashboard provides visibility into detection activity over time and allows users to review detailed detection events received from Vectra Detect.

This dashboard includes the following panels:

| Panel                             | Description                                                                                   |
| --------------------------------- | --------------------------------------------------------------------------------------------- |
| Detection Type Activity Over Time | Area chart showing detection activity over the selected time range, grouped by detection type |
| Detections List                   | Table panel showing detailed detection events                                                 |

#### Dashboard Filters

The Detections dashboard supports the following filters:

| Filter               | Description                                                                                                        |
| -------------------- | ------------------------------------------------------------------------------------------------------------------ |
| Time Range           | Filters detection data based on the selected time period                                                           |
| Detection Categories | Filters detections by category. This filter is dynamically populated based on the selected Time Range              |
| Behavior             | Filters detections by behavior. This dropdown is populated based on the selected Detection Category and Time Range |
| Type                 | Filters detections by detection type                                                                               |
| Search Filter        | Allows users to search for specific detection details                                                              |

The **Detection Categories** filter is dynamically populated based on the selected **Time Range**. The **Behavior** filter is then populated based on both the selected **Detection Category** and the selected **Time Range**.

<figure><img src="/files/KvUQnWKEcjMh3Ti6lKKM" alt=""><figcaption></figcaption></figure>

### Campaigns Dashboard

The Campaigns dashboard provides visibility into campaign-related activity received from Vectra Detect.

This dashboard includes the following panels:

| Panel                    | Description                                                                             |
| ------------------------ | --------------------------------------------------------------------------------------- |
| Top 10 Campaign Activity | Bar chart showing the top 10 campaigns based on activity during the selected time range |
| Last Campaign Events     | Table panel showing the most recent campaign-related events                             |

#### Dashboard Filters

The Campaigns dashboard supports the following filters:

| Filter        | Description                                                                                            |
| ------------- | ------------------------------------------------------------------------------------------------------ |
| Time Range    | Filters campaign data based on the selected time period                                                |
| Campaign Name | Filters events by campaign name. This filter is dynamically populated based on the selected Time Range |
| Type          | Filters events by campaign type. This filter is dynamically populated based on the selected Time Range |

The **Campaign Name** and **Type** filters are dynamically populated based on the selected **Time Range**.

![](/files/rxU5GjJzBa6c6IKs2haK)

### Health Dashboard

The Health dashboard provides visibility into health-related logs received from Vectra Detect.

This dashboard includes the following panel:

| Panel            | Description                                             |
| ---------------- | ------------------------------------------------------- |
| Last Health Logs | Table panel showing the most recent health-related logs |

#### Dashboard Filters

The Health dashboard supports the following filters:

| Filter        | Description                                           |
| ------------- | ----------------------------------------------------- |
| Time Range    | Filters health logs based on the selected time period |
| Result        | Filters health logs by result status                  |
| Search Filter | Allows users to search within health log details      |

<figure><img src="/files/8TsQatZW02Iflzr0uo4g" alt=""><figcaption></figcaption></figure>

### Audit Dashboard

The Audit dashboard provides visibility into audit-related logs received from Vectra Detect.

This dashboard includes the following panel:

| Panel           | Description                                            |
| --------------- | ------------------------------------------------------ |
| Last Audit Logs | Table panel showing the most recent audit-related logs |

#### Dashboard Filters

The Audit dashboard supports the following filters:

| Filter        | Description                                          |
| ------------- | ---------------------------------------------------- |
| Time Range    | Filters audit logs based on the selected time period |
| Result        | Filters audit logs by result status                  |
| User          | Filters audit logs by user                           |
| Search Filter | Allows users to search within audit log details      |

<figure><img src="/files/o0RJv2RU4K3IynClQ6ub" alt=""><figcaption></figcaption></figure>

### Notes for All Dashboards

The following notes apply to all dashboards in the Vectra Detect App for QRadar:

| Item                                 | Description                                                                                                                            |
| ------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------- |
| Search Filter                        | The **Search Filter** is case-sensitive across all dashboards.                                                                         |
| Search behavior                      | The entered search value is searched against the raw event payload.                                                                    |
| Table result limit                   | Most table panels are limited to **1000 records**.                                                                                     |
| Worst Offenders and Key Assets limit | The **Worst Offenders** and **Key Assets** table panels are limited to **10 records**.                                                 |
| Information icon                     | An information icon is displayed on table panels to indicate the record limit. When users hover over the icon, a message is displayed. |

For most table panels, the hover message is:

```
Results are limited to 1000 entries.
```

For the **Worst Offenders** and **Key Assets** table panels, the hover message is:

```
Results are limited to 10 entries.
```

## Saved Searches

The Vectra Detect App for QRadar also provides a number of saved searches that can be executed. To run a saved search, follow these steps:

* Go to the "Log Activity" tab in QRadar.
* Click on the Search dropdown and select "New Search".

![](/files/0OSy77O9zrKQfPV4POxJ)

* Click on the "Group" dropdown and select "Vectra Detect".

![](/files/U48VoGzysF9L5GM84t1V)

* Select a search from the list of Available Saved Searches and click on Load. To run the search in the Log Activity tab, click on the Search button situated at the bottom right corner.

![](/files/e7PkeLcFUEY7qJ0iO4dd)

* The following saved searches are provided in the app and have a default Time Range of the last 30 days.

|                                                |                                                                   |
| ---------------------------------------------- | ----------------------------------------------------------------- |
| Worst Offenders                                | Worst Offenders - 7.4.3+                                          |
| Key Assets                                     | Key Assets - 7.4.3+                                               |
| Hosts list                                     | Hosts list - 7.4.3+                                               |
| Accounts list                                  | Accounts list - 7.4.3+                                            |
| Accounts Currently Locked (30 days history)    | <p>Accounts Currently Locked (30 days history)<br>- 7.4.3+</p>    |
| Accounts locked during the selected time range | <p>Accounts locked during the selected time range<br>- 7.4.3+</p> |
| Detections list                                | Detections list - 7.4.3+                                          |
| Last Campaign events                           | Last Campaign events - 7.4.3+                                     |
| Last Health logs                               | Last Health logs - 7.4.3+                                         |
| Last Audit logs                                | Last Audit logs - 7.4.3+                                          |

* The saved searched ending with “-7.4.3+” should be used when using a QRadar instance with version high than 7.4.3.

## Troubleshooting

This section describes common issues that may occur during deployment or while using the Vectra Detect App for QRadar, along with recommended troubleshooting steps.

### Case 1: Vectra Events Appear as “Vectra Detect Message”

**Problem**

Vectra Detect events appear in QRadar as **Vectra Detect Message** instead of being mapped to the expected QRadar event category.

This can be seen in the **Log Activity** tab when searching for events from the Vectra Detect log source type.

**Possible Cause**

This issue may occur when:

* A required field is missing from the raw event.
* The event payload is larger than the QRadar default payload size.
* The event payload is truncated before QRadar can parse it correctly.

By default, QRadar uses a payload size of **4096 bytes**. If the Vectra event payload is larger than this value, increase the maximum payload size.

**Troubleshooting Steps**

1. In QRadar, navigate to the **Admin** panel.
2. Open **System Settings**.
3. Switch to **Advanced** mode.
4. Locate the following settings:
   * **Max TCP Syslog Payload Length**
   * **Max UDP Syslog Payload Length**
5. Increase the values as needed.

   Recommended value:

```
32000
```

6. Click **Deploy Changes**.

![](/files/ORCPAkLPFFEaRxCVGYgk)

***

### Case 2: UI Issues in the App

**Problem**

A dashboard panel shows errors, does not load correctly, or displays unintended behavior.

**Troubleshooting Steps**

1. Clear the browser cache.
2. Reload the QRadar webpage.
3. Reduce the selected dashboard time range and retry.

   QRadar queries may expire if the selected time range returns too much data.
4. If the issue continues, collect logs and contact support using the steps listed in **Case 6**.

***

### Case 3: Dashboard Does Not Populate After App Upgrade

**Problem**

After upgrading the Vectra Detect App from version **1.1.0** to **2.x**, the dashboard does not populate even though Vectra data is visible in **Log Activity**.

**Troubleshooting Steps**

1. Go to the QRadar **Admin** panel.
2. Click **Advanced**.
3. Select **Deploy Full Configuration**.
4. After deployment completes, reload the Vectra Detect App dashboard.

***

### Case 4: Other Issues Not Covered in This Document

**Problem**

The issue is not listed in this troubleshooting section, or the previous troubleshooting steps did not resolve the issue.

**Troubleshooting Steps**

Collect QRadar logs and provide them to support.

1. In QRadar, navigate to the **Admin** panel.
2. Open **System and License Management**.
3. Select the host where the **Vectra Detect App for QRadar** is installed.
4. Click **Actions** in the top panel.
5. Select **Collect Log Files**.
6. In the **Log File Collection** window, click **Advanced Options**.
7. Select the following options:
   * **Include Debug Logs**
   * **Application Extension Logs**
   * **Setup Logs (Current Version)**
8. Select **2 days** as the data input range.
9. Click **Collect Log Files**.
10. Click **Click here to download files**.

This downloads the collected logs as a single ZIP file to your local machine.

Contact support and attach the downloaded ZIP file for further investigation.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/configuration/response/siem/qradar-siem-integration-qux.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
