QRadar SIEM Integration (QUX)
Install and configure the QRadar integration for QUX, including the Vectra Detect app, syslog log source setup, dashboards, saved searches, and troubleshooting.
As stated in the summary, this article only applies to customers using Vectra's Quadrant UX. If you are using the Respond UX please see the QRadar Integration Guide for Vectra XDR (Respond UX) . If you are unsure of which UX you are using, please see Vectra Analyst User Experiences (Respond vs Quadrant).
Introduction
The Vectra Detect App for IBM QRadar enables QRadar analysts to ingest, view, and investigate Vectra signals from Vectra QUX / Vectra Detect.
This guide focuses on the Syslog-based source integration. In this deployment model, Vectra QUX sends Vectra signals to QRadar using the syslog protocol, and QRadar processes the events using the Vectra Detect App.
Video Demo of Deployment
A companion demo video for this article is available here:
Note: This video below also includes setup information for Vectra SaaS, which is deprecated and not covered in this guide. Some portions of the video are for the now deprecated Vectra SaaS deployment which has been replaced by the Respond UX (RUX). Some prerequisites still apply in the video for syslog deployment for QUX and specific steps for QUX integration, start at 6:00.
The UI shown in the video is older and may not match the current Vectra QUX UI. The Brain serial number may not be available in the same path shown in the video. Refer to this document for the updated steps to locate the Brain serial number in the current QUX UI.
The video walks through deployment requirements, required component setup, and configuration steps for bringing Vectra signals into QRadar.
For this guide, use the video only for the Vectra QUX / Syslog-based source (non-SaaS Deployment) configuration, where Vectra QUX sends Vectra Detect syslog output to QRadar.
Requirements
Before deploying the Vectra Detect App for IBM QRadar, ensure the following requirements are met.
QRadar Platform Requirements
QRadar version
QRadar v7.4.3 GA or later is required. If QRadar is running an older version, upgrade QRadar using the appropriate IBM update package before installing the Vectra Detect App.
QRadar Log Source Management App
The QRadar Log Source Management App must be installed before configuring Vectra log sources. Installing the QRadar Log Source Management App.
Vectra Detect App for QRadar
Install the Vectra Detect App for QRadar - QRadar v7.4.3 GA+ from IBM X-Force Exchange. Vectra Detect App for QRadar - QRadar v7.4.3 GA+
Syslog-Based Source Requirements
The Syslog-based source is used for Vectra QUX / Vectra Detect integrations where Vectra signals are sent to QRadar using the syslog protocol.
Syslog forwarding
Configure the Vectra deployment to send Vectra Detect syslog output to QRadar.
Brain serial number
Provide the Brain serial number. This is used as the log source identifier in QRadar.
QRadar log source
Create or configure the QRadar log source to receive Vectra syslog events.
Installation Process
This section provides the overall installation process for deploying or upgrading the Vectra Detect App for IBM QRadar for Vectra QUX / Vectra Detect integration. Links to the required applications and packages are provided in the Requirements section. Detailed configuration steps are covered in the sections that follow.
Common Installation Steps
Ensure QRadar is running v7.4.3 GA or later.
Updating QRadar is not covered in this guide. If an upgrade is required, work with IBM or your QRadar support partner.
Ensure the QRadar Log Source Management App is installed.
Installation of this app is not covered in this guide. Refer to the IBM documentation linked in the Requirements section.
Install or upgrade the Vectra Detect App for QRadar - QRadar v7.4.3 GA+.
Deploy the QRadar configuration after the app installation or upgrade is complete.
Syslog-Based Source Configuration
The Syslog-based source is used for Vectra QUX / Vectra Detect deployments that send Vectra signals to QRadar using syslog.
Copy the Vectra Brain serial number for later use as the QRadar Log Source Identifier.
Configure syslog output from Vectra QUX / Vectra Detect to QRadar.
Configure the Vectra Detect syslog log source in QRadar.
Deploy the QRadar configuration.
Installation of the Vectra Detect App for QRadar
This section describes how to install or upgrade the Vectra Detect App for QRadar for the Vectra QUX integration.
Upgrades from Prior Versions
The Vectra Detect App can be upgraded from a prior supported version when the existing app is installed on a supported QRadar version with App Framework v2 support.
For this guide, QRadar must be running v7.4.3 GA or later before installing or upgrading the app.
The same steps below can be used for both new installations and upgrades.
Installation Steps
Log in to the QRadar console.
Navigate to Admin > Extension Management.
Click Add to upload and add a new extension.

Select the Vectra Detect App for QRadar - QRadar v7.4.3 GA+ package.
QRadar displays a list of changes that will be made by the app. Review the changes and click Install.

After the installation completes, QRadar displays a confirmation message indicating that the app was installed successfully. The confirmation window also lists the components installed as part of the app.

Validate the Installation
To confirm that the installation was successful:
Navigate to Admin > Extension Management.
Locate Vectra Detect App for QRadar - QRadar v7.4.3 GA+.
Confirm that the application status shows Installed.
After the app is installed, deploy the QRadar configuration before continuing with the Vectra QUX syslog log source configuration.
Vectra QUX Integration Configuration
This section applies to Vectra QUX / Vectra Detect deployments that send Vectra signals to QRadar.
Find and Copy the Log Source Identifier
In the Vectra UI, navigate to Configuration > Data Sources > Network > Brain Setup and copy the Brain serial number.
The Brain serial number will be used later as the Log Source Identifier when configuring the Vectra Detect log source in QRadar.


Configure Vectra Output to QRadar
In the Vectra UI, navigate to Settings > Notifications > Syslog.

Click the pencil icon or Edit > Add Destination to update the syslog settings.
Configure the following required settings:
Destination IP
Enter the IP address of the QRadar server or syslog listener
Destination Port
Enter the QRadar syslog listener port used in your environment
Protocol
TCP
Format
JSON
Log Types
Include all log types
Enhanced Detail
Enabled
Note: In the example screenshot, port 5141 is used. The default QRadar syslog listener port is 514. Use the port that matches your QRadar environment.

The following options can be selected based on your environment and reporting requirements:
Include filtered
Includes detections that have been triaged by AI or filtered by rules created in Vectra
Include detections in info
Controls whether Info category detections are forwarded
Include host/account score decreases
Controls whether host and account score decreases are forwarded
The Enhanced Detail option should be enabled. This provides additional event detail in the syslog output. The ability to disable enhanced detail is mainly intended for environments where a downstream tool is not configured to process the additional fields.
After completing the syslog configuration, save the settings and open the QRadar console to continue the QRadar-side log source configuration.
Configure the Vectra Detect Log Source in QRadar
This section describes how to configure the QRadar log source for Vectra QUX / Vectra Detect. This configuration allows QRadar to receive Vectra signals from the Vectra Brain.
Create a New Log Source
In the QRadar console, navigate to Admin > Apps > Log Source Management.

Select Log Sources.
Click + New Log Source.
Select Single Log Source.

On the Select a Log Source Type screen, search for Vectra Detect.
Select Vectra Detect, then click Step 2: Select Protocol Type.

Select Syslog as the protocol.
Click Step 3: Configure Log Source Parameters.

Configure Log Source Parameters
On the Configure Log Source Parameters screen, configure the required fields listed below. Fields not listed here are optional unless required by your QRadar environment.
Name
Enter a name for the log source, such as Vectra Brain
Extension
Select VectraDetectCustom_ext for post-processing of events after parsing
Coalescing Events
Uncheck this option to prevent QRadar from grouping events based on source and destination IP
After completing the required fields, click Step 4: Configure Protocol Parameters.

Configure Protocol Parameters
On the Configure Protocol Parameters screen, paste the Vectra Brain serial number into the Log Source Identifier field.
Use the same serial number that was copied earlier from Configuration > Data Sources > Network > Brain Setup in the Vectra Brain UI.
After entering the Log Source Identifier:
Click Finish.
Close the Log Source Management app.
Deploy the QRadar configuration changes.

After the configuration is deployed, the Syslog-based Vectra Detect integration with QRadar is complete.
Supplemental Information
QRadar Deployment Guidance
The configuration steps in this guide assume that users are familiar with deploying configuration changes in QRadar.
If you are not familiar with the process, use the following steps:
Navigate to the Admin panel in QRadar.
Click Deploy Changes.
From the Advanced dropdown, select Deploy Full Configuration.
A full configuration deployment is recommended after installing the required components, adding log sources, or making protocol-related configuration changes.

Uninstalling the Application
To uninstall the Vectra Detect App for QRadar, complete the following steps:
Navigate to the Admin panel in QRadar.
Open Extension Management.
Select Vectra Detect App for QRadar - QRadar v7.4.3 GA+.
Click Uninstall.
Follow the QRadar prompts to complete the uninstallation.
After the application is removed, deploy the QRadar configuration changes if prompted.
Steps to Check Application Logs
This section describes how to check logs for the Vectra Detect App for QRadar.
Check Data Collection Logs
To check data collection logs, log in to the QRadar appliance using SSH as the root user.
Run the following command:
This command monitors QRadar logs and filters entries related to the Vectra Detect App for QRadar.
Check Dashboard Logs from the Application Container
Dashboard-related logs can be checked from inside the application container.
Log in to the QRadar appliance using SSH as the root user.
Run the following command to list the installed QRadar applications:
From the output, locate the application named Vectra Detect App for QRadar and copy its App-ID.
Connect to the application container using the App-ID:
After connecting to the container, navigate to the application log directory:
List the available log files:
Review the required log file. For dashboard-related logs, check:
The app.log file contains logs related to the Vectra Detect App dashboard.
Visualizations
The Vectra Detect App for QRadar includes dashboards made up of individual panels. Each panel displays specific metrics based on Vectra signals received in QRadar.
All dashboards allow users to filter events by time range.
Overview Dashboard
The Overview dashboard provides high-level visibility into host scoring and detection events received from Vectra Detect.
This dashboard includes:
Critical, High, Medium, and Low
Single-value panels showing event counts by severity. These panels use a Last 30 Days time range, regardless of the selected dashboard time filter.
Worst Offenders
Table panel showing entities with the highest level of activity or risk.
Key Assets
Table panel showing activity related to key assets.
Top 10 Detections by Type
Bar chart showing the most common detection types.
Top 10 Detections by Category
Bar chart showing the most common detection categories.
Dashboard Navigation
Users can drill down from the Overview dashboard into more detailed dashboards:
Click a Critical, High, Medium, or Low single-value panel
Redirects to the Entities dashboard
Click a row in the Worst Offenders table
Redirects to the Detections dashboard
Click a row in the Key Assets table
Redirects to the Detections dashboard
Click a bar in the Top 10 Detections by Type chart
Redirects to the Detections dashboard
Click a bar in the Top 10 Detections by Category chart
Redirects to the Detections dashboard

Entities Dashboard
The Entities dashboard provides visibility into entity severity, account activity, and account lockout events.
This dashboard includes the following panels:
Entity Severity Quadrant
Scatter chart that plots unique entities based on Threat and Certainty values
Entities List
Table panel showing the top 1000 logs for unique entities
Accounts List
Table panel showing account-related events
Accounts Currently Locked
Table panel showing accounts that are currently locked, based on the last 30 days of history
Accounts Locked During Selected Time Range
Table panel showing accounts that were locked during the selected dashboard time range
The Accounts Currently Locked panel uses a fixed last 30 days time range and is independent of the dashboard Time Range filter.
Dashboard Filters
The Entities dashboard supports the following filters:
Time Range
Filters dashboard data based on the selected time period
Entity Type
Filters results by entity type
Search Filter
Allows users to search for specific entities or accounts
Severity
Filters table results by severity

Detections Dashboard
The Detections dashboard provides visibility into detection activity over time and allows users to review detailed detection events received from Vectra Detect.
This dashboard includes the following panels:
Detection Type Activity Over Time
Area chart showing detection activity over the selected time range, grouped by detection type
Detections List
Table panel showing detailed detection events
Dashboard Filters
The Detections dashboard supports the following filters:
Time Range
Filters detection data based on the selected time period
Detection Categories
Filters detections by category. This filter is dynamically populated based on the selected Time Range
Behavior
Filters detections by behavior. This dropdown is populated based on the selected Detection Category and Time Range
Type
Filters detections by detection type
Search Filter
Allows users to search for specific detection details
The Detection Categories filter is dynamically populated based on the selected Time Range. The Behavior filter is then populated based on both the selected Detection Category and the selected Time Range.

Campaigns Dashboard
The Campaigns dashboard provides visibility into campaign-related activity received from Vectra Detect.
This dashboard includes the following panels:
Top 10 Campaign Activity
Bar chart showing the top 10 campaigns based on activity during the selected time range
Last Campaign Events
Table panel showing the most recent campaign-related events
Dashboard Filters
The Campaigns dashboard supports the following filters:
Time Range
Filters campaign data based on the selected time period
Campaign Name
Filters events by campaign name. This filter is dynamically populated based on the selected Time Range
Type
Filters events by campaign type. This filter is dynamically populated based on the selected Time Range
The Campaign Name and Type filters are dynamically populated based on the selected Time Range.

Health Dashboard
The Health dashboard provides visibility into health-related logs received from Vectra Detect.
This dashboard includes the following panel:
Last Health Logs
Table panel showing the most recent health-related logs
Dashboard Filters
The Health dashboard supports the following filters:
Time Range
Filters health logs based on the selected time period
Result
Filters health logs by result status
Search Filter
Allows users to search within health log details

Audit Dashboard
The Audit dashboard provides visibility into audit-related logs received from Vectra Detect.
This dashboard includes the following panel:
Last Audit Logs
Table panel showing the most recent audit-related logs
Dashboard Filters
The Audit dashboard supports the following filters:
Time Range
Filters audit logs based on the selected time period
Result
Filters audit logs by result status
User
Filters audit logs by user
Search Filter
Allows users to search within audit log details

Notes for All Dashboards
The following notes apply to all dashboards in the Vectra Detect App for QRadar:
Search Filter
The Search Filter is case-sensitive across all dashboards.
Search behavior
The entered search value is searched against the raw event payload.
Table result limit
Most table panels are limited to 1000 records.
Worst Offenders and Key Assets limit
The Worst Offenders and Key Assets table panels are limited to 10 records.
Information icon
An information icon is displayed on table panels to indicate the record limit. When users hover over the icon, a message is displayed.
For most table panels, the hover message is:
For the Worst Offenders and Key Assets table panels, the hover message is:
Saved Searches
The Vectra Detect App for QRadar also provides a number of saved searches that can be executed. To run a saved search, follow these steps:
Go to the "Log Activity" tab in QRadar.
Click on the Search dropdown and select "New Search".

Click on the "Group" dropdown and select "Vectra Detect".

Select a search from the list of Available Saved Searches and click on Load. To run the search in the Log Activity tab, click on the Search button situated at the bottom right corner.

The following saved searches are provided in the app and have a default Time Range of the last 30 days.
Worst Offenders
Worst Offenders - 7.4.3+
Key Assets
Key Assets - 7.4.3+
Hosts list
Hosts list - 7.4.3+
Accounts list
Accounts list - 7.4.3+
Accounts Currently Locked (30 days history)
Accounts Currently Locked (30 days history) - 7.4.3+
Accounts locked during the selected time range
Accounts locked during the selected time range - 7.4.3+
Detections list
Detections list - 7.4.3+
Last Campaign events
Last Campaign events - 7.4.3+
Last Health logs
Last Health logs - 7.4.3+
Last Audit logs
Last Audit logs - 7.4.3+
The saved searched ending with “-7.4.3+” should be used when using a QRadar instance with version high than 7.4.3.
Troubleshooting
This section describes common issues that may occur during deployment or while using the Vectra Detect App for QRadar, along with recommended troubleshooting steps.
Case 1: Vectra Events Appear as “Vectra Detect Message”
Problem
Vectra Detect events appear in QRadar as Vectra Detect Message instead of being mapped to the expected QRadar event category.
This can be seen in the Log Activity tab when searching for events from the Vectra Detect log source type.
Possible Cause
This issue may occur when:
A required field is missing from the raw event.
The event payload is larger than the QRadar default payload size.
The event payload is truncated before QRadar can parse it correctly.
By default, QRadar uses a payload size of 4096 bytes. If the Vectra event payload is larger than this value, increase the maximum payload size.
Troubleshooting Steps
In QRadar, navigate to the Admin panel.
Open System Settings.
Switch to Advanced mode.
Locate the following settings:
Max TCP Syslog Payload Length
Max UDP Syslog Payload Length
Increase the values as needed.
Recommended value:
Click Deploy Changes.

Case 2: UI Issues in the App
Problem
A dashboard panel shows errors, does not load correctly, or displays unintended behavior.
Troubleshooting Steps
Clear the browser cache.
Reload the QRadar webpage.
Reduce the selected dashboard time range and retry.
QRadar queries may expire if the selected time range returns too much data.
If the issue continues, collect logs and contact support using the steps listed in Case 6.
Case 3: Dashboard Does Not Populate After App Upgrade
Problem
After upgrading the Vectra Detect App from version 1.1.0 to 2.x, the dashboard does not populate even though Vectra data is visible in Log Activity.
Troubleshooting Steps
Go to the QRadar Admin panel.
Click Advanced.
Select Deploy Full Configuration.
After deployment completes, reload the Vectra Detect App dashboard.
Case 4: Other Issues Not Covered in This Document
Problem
The issue is not listed in this troubleshooting section, or the previous troubleshooting steps did not resolve the issue.
Troubleshooting Steps
Collect QRadar logs and provide them to support.
In QRadar, navigate to the Admin panel.
Open System and License Management.
Select the host where the Vectra Detect App for QRadar is installed.
Click Actions in the top panel.
Select Collect Log Files.
In the Log File Collection window, click Advanced Options.
Select the following options:
Include Debug Logs
Application Extension Logs
Setup Logs (Current Version)
Select 2 days as the data input range.
Click Collect Log Files.
Click Click here to download files.
This downloads the collected logs as a single ZIP file to your local machine.
Contact support and attach the downloaded ZIP file for further investigation.
Last updated
Was this helpful?
