Metadata filtering and publishing

How to configure options for metadata filtering and the destination publisher of your choice.

Metadata Filtering Options

Some customers may choose to limit metadata types that are forwarded due to use case requirements or data lake / SIEM scalability issues. Additionally, IPs, Subnets, and Sensor UIDs can also be used as exclusion filters to limit sources of metadata that are forwarded. To enable these filters edit and save in the following areas:

  • Configuration → SETUP → Stream → Metadata Types

  • Configuration → SETUP → Stream → Vectra Stream Metadata Filtering

Destination Publisher Configuration

Stream supports Syslog (over TCP), Elastic, Raw JSON, and Kafka publishers. To configure your publisher choice, edit the Configuration → SETUP → Stream → Destination area. The various publisher types have differing options. The example below shows the syslog over TCP configuration:

Syslog and Kafka support the SSL protocol for secure connectivity from the Vectra Stream VM to your data lake. If SSL is selected, you will have to provide the client certificate, client key and server CA certificate.

Enabling Forwarding, Stream Status, and Metadata Statistics

To enable Metadata forwarding once the configuration of your chosen publisher is completed, turn on forwarding in the Configuration → SETUP → Stream → Vectra Stream Metadata Forwarding area and save.

Health status of Stream can be seen at the bottom of the Configuration → SETUP → Stream page:

A summary of Stream health is also available in the System Health Dashboard at Discover → PLATFORM → System Health.

Stream metadata statistics are available at Network Stats → Stream Metadata.

Last updated

Was this helpful?