> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/configuration/response/siem/splunk-siem-vectra-integration-guide-start-here-for-qux.md).

# Splunk On-Prem SIEM / Vectra integration guide (start here for QUX)

As stated in the summary, this article only applies to customers using Vectra's Respond UX. If you are using the Respond UX please see the [Splunk On-Prem SIEM / Vectra integration guide (start here for RUX)](/configuration/response/siem/splunk-siem-vectra-integration-guide-start-here-for-rux.md) or [Splunk Cloud SIEM / Vectra integration guide (start here for RUX)](/configuration/response/siem/splunk-siem-vectra-integration-guide-start-here-for-rux-1.md) If you are unsure of which UX you are using, please see [Vectra Analyst User Experiences (Respond vs Quadrant)](/deployment/getting-started/analyst-ux-options-rux-vs-qux.md).

## Integration Overview

Vectra AI provides Splunk add-ons and apps to help integrate Vectra data with Splunk and Splunk Enterprise Security.

For Splunk on-prem deployments, Vectra provides integrations for the following main data sources:

* **Detection data and entity scoring from Vectra Cognito Detect**
* **Network metadata from Vectra Stream**
* **Log output from Vectra Match**

These integrations help security teams ingest, search, visualize, and investigate Vectra data directly in Splunk.

### Vectra Cognito Detect Data

Vectra Cognito Detect provides detection, scoring, audit, health, lockdown, and related security event data.

Vectra Cognito Detect uses data science, machine learning, and behavioral analysis to identify malicious threat behavior across enterprise environments. The platform analyzes activity across public cloud, SaaS, federated identity, and data center networks to surface and prioritize threats.

This data can be sent to Splunk and used for:

* Security monitoring
* Threat investigation
* Detection review
* Entity scoring analysis
* Incident response workflows
* Splunk Enterprise Security correlation searches and dashboards

For Splunk on-prem deployments, Vectra Cognito Detect data is commonly forwarded using syslog in JSON format and parsed by the **Technology Add-On for Vectra Detect (JSON)**.

### Vectra Stream Network Metadata

Vectra Stream provides network metadata collected by Vectra Sensors deployed throughout the environment.

This metadata gives security teams deeper visibility into network communications observed across the environment. It can be used in Splunk for investigation, detection engineering, and threat hunting.

Vectra Stream data can help analysts answer questions such as:

* Which systems communicated with each other?
* What protocols were observed?
* What network attributes were extracted?
* Was suspicious communication observed between internal or external systems?

A list of supported protocols and extracted attributes is available [here](https://support.vectra.ai/s/article/KB-VS-1245).

### Vectra Match Log Output

Vectra Match uses the open-source Suricata IDS engine to generate signature-based match events.

Vectra Sensors are designed to process high-performance network data and produce the metadata required by Vectra’s behavioral detection models. Vectra Match allows these same sensors to also run Suricata-based detection logic using the same packet capture buffers that feed the existing Vectra processing pipeline.

When a match is generated, the event flows from the sensors to the Vectra Brain and then to Splunk or another SIEM.

The **Technology Add-On for Vectra Detect (JSON)** and **Vectra Cognito Detect App** support parsing and visualizing Vectra Match log output. The Splunk app also includes dashboards for Vectra Match data.

### Vectra Cognito Detect Add-On and Apps for Splunk

#### Vectra Cognito Detect

| Name                                       | Type   | Supported Splunk Version                                   | CIM Compatibility | Splunk Cloud | Vectra Platform         | Data Structure |
| ------------------------------------------ | ------ | ---------------------------------------------------------- | ----------------- | ------------ | ----------------------- | -------------- |
| Technology Add-On for Vectra Detect (JSON) | Add-on | 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0      | Yes               | Yes          | Brain based deployments | JSON           |
| Vectra Cognito Detect                      | App    | 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0, 8.2 | n/a               | Yes          | Any                     | n/a            |

| Name                                        | Type   | Supported Splunk Version | CIM Compatibility | Splunk Cloud | Data structure | Splunkbase Link                                     | Preferred                  | Dependencies                                                                                                                                 |
| ------------------------------------------- | ------ | ------------------------ | ----------------- | ------------ | -------------- | --------------------------------------------------- | -------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Technology Add-on for Vectra Cognito Stream | Add-on | 8.1, 8.2, 9.0            | Yes               | Yes          | Standard       | [APP-4437](https://splunkbase.splunk.com/app/4437/) | No - *would be deprecated* |                                                                                                                                              |
| Technology Add-on for Vectra Stream (JSON)  | Add-on | 8.1, 8.2, 9.0            | Yes               | Yes          | JSON           | [APP-6637](https://splunkbase.splunk.com/app/6367/) | Yes                        | [Vectra Cognito Stream](https://splunkbase.splunk.com/app/4739/) >= 1.3                                                                      |
| Vectra Cognito Stream                       | App    | 8.1, 8.2, 9.0            | n/a               | Yes          | n/a            | [APP-4739](https://splunkbase.splunk.com/app/4739/) | n/a                        | <p><a href="https://splunkbase.splunk.com/app/3118/">Treemap</a></p><p><a href="https://splunkbase.splunk.com/app/2734/">URL Toolbox</a></p> |

| Splunk Node         | What to install |
| ------------------- | --------------- |
| Search Head         | Add-on and App  |
| Indexer             | Add-on only     |
| Heavy Forwarder     | Add-on only     |
| Universal Forwarder | None            |

{% hint style="info" %}
**Please Note!!** The add-on for Vectra Detect using CEF format has been deprecated and the recommendation is to use JSON format add-on.
{% endhint %}

#### Vectra Stream

| Name                                       | Type   | Supported Splunk Version                              | CIM Compatibility | Splunk Cloud | Data structure | Dependencies                                                                                                                                 |
| ------------------------------------------ | ------ | ----------------------------------------------------- | ----------------- | ------------ | -------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| Technology Add-on for Vectra Stream (JSON) | Add-on | 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1      | Yes               | Yes          | JSON           | N/A                                                                                                                                          |
| Vectra Stream                              | App    | 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0 | n/a               | Yes          | n/a            | <p><a href="https://splunkbase.splunk.com/app/3118/">Treemap</a></p><p><a href="https://splunkbase.splunk.com/app/2734/">URL Toolbox</a></p> |

### Prerequisites

* Valid Splunk account to be able to access & download apps in [Splunkbase](https://splunkbase.splunk.com/).
* Supported version of Splunk or Splunk Enterprise.
* Applications dependencies listed in the Add-ons and apps table must be fulfilled.
* **Create index(es)**.
  * Vectra recommends having a dedicated index for Vectra Cognito Detect and another dedicated index if also using Vectra Stream.

### Index Recommendations

Vectra recommends creating dedicated indexes for Vectra data.

Recommended index usage:

| Vectra Cognito Detect | Create a dedicated index for Vectra Detect data, such as `vectra_detect`.          |
| --------------------- | ---------------------------------------------------------------------------------- |
| Vectra Stream         | Create a separate dedicated index for Vectra Stream data, such as `vectra_stream`. |

Using separate indexes helps with data management, retention policies, access control, search performance, and troubleshooting.

#### Create the Required Index

Create a dedicated Splunk index for Vectra Detect data before configuring data ingestion.

Vectra recommends using a dedicated index for Vectra Detect events. This helps with data organization, search performance, access control, retention management, and troubleshooting.

Example index name:

```
vectra_detect
```

## Integration of Splunk with Vectra Cognito Detect

Integrating Splunk with Vectra Cognito Detect requires three main steps:

1. Configuring Vectra Detect to send JSON-formatted event data to Splunk.
2. Installing and configuring the **Technology Add-On for Vectra Detect (JSON)**.
3. Installing the **Vectra Cognito Detect App for Splunk**.

#### Configure Vectra Detect Event Forwarding

Configure Vectra Detect to forward JSON-formatted events to Splunk. These events provide visibility into detections, entities, scoring, and related security activity observed by the Vectra platform.

#### Install and Configure the Technology Add-On for Vectra Detect (JSON)

The **Technology Add-On for Vectra Detect (JSON)** enables Splunk to parse and normalize JSON-formatted data from Vectra Detect.

The add-on helps Splunk process Vectra Detect data so it can be searched, analyzed, and used by the Vectra Cognito Detect App dashboards. It also supports field extraction and mapping required for effective investigation and reporting in Splunk.

#### Install the Vectra Cognito Detect App

The **Vectra Cognito Detect App for Splunk** provides dashboards and visualizations based on the data processed by the **Technology Add-On for Vectra Detect (JSON)**.

These dashboards help security teams monitor Vectra detections, review entity activity, and investigate threats directly within Splunk.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/configuration/response/siem/splunk-siem-vectra-integration-guide-start-here-for-qux.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
