Splunk SIEM / Vectra integration guide (start here for QUX)
This article serves as the starting point for Vectra's various integrations with Splunk. Read this prior to any other articles regarding Splunk integration.
Data sources
Detection Data and Entity Scoring from Vectra Detect
Network Metadata from Vectra Stream
Log Output from Vectra Match
Vectra Add-ons and Apps for Splunk
Vectra Detect
Name
Type
Supported Splunk Version
CIM Compatibility
Splunk Cloud
Vectra Platform
Data Structure
Vectra Stream
Name
Type
Supported Splunk Version
CIM Compatibility
Splunk Cloud
Data structure
Splunkbase Link
Preferred
Dependencies
Installation and Configuration
Installation Matrix
Splunk Node
What to install
Prerequisites
Installation and Configuration Guides
Splunk - Vectra Detect Integration Steps - Go here 1st if integrating Splunk with Vectra Detect, then use either or both of the below depending on if you are integrating Splunk with Vectra SaaS and/or using the Vectra Platform with a Brain based installation
Splunk - Vectra Stream Integration Steps - Go here if integrating Splunk with Vectra Stream.
PreviousSplunk SIEM / Vectra integration guide (start here for RUX)NextSplunk - Vectra Detect Add-On and Syslog Configuration (QUX)
Last updated
Was this helpful?