Vectra AI Platform Investigate FAQ
!! In addition to this KB article, please see the Vectra AI Platform Advanced Investigation QuickStart Guide for additional details and query examples for using Advanced Investigation. That KB article also discusses how to launch into Advanced Investigation from Instant Investigation.
FAQ
1. What is Vectra AI Platform Investigation?

2. Do I need a separate license to deploy Investigations?
3. Is there a limit in the number of results that will be rendered in the investigations?
4. Is there a limit in the number of results that will be downloaded in the .csv file in the Advanced Investigation UI?
5. What is the retention period?
6. What is the search window?
7. Where can I find more information about purchasing extended retention periods for the metadata?
8. What ways are there to begin and drill into an investigation?
9. Do you have examples of searching across different M365 and Azure AD data streams. How can it be done?
10. How do I filter my network metadata using a sensor?

11. How do the filters for CIDR notation work?

12. Where can I see the network metadata available in Advanced Investigation?
13. What is a Vectra enriched field?
14. Where can I see the AWS metadata available in Investigation?
15. Are there Vectra enriched fields for AWS metadata?
16. Where can I see the Azure AD (AD) and M365 metadata available in Investigation?
17. Which Microsoft license do I need to collect all the metadata needed for AAD and M365 Instant Investigation?
18. Why do I get an error message in Instant Investigation for Azure AD and M365 that says I may not have the required Microsoft license?
19. Are there Vectra enriched fields for AAD and M365 metadata?
20. Why is it I don’t see the Instant Investigation tab in my tenants’ UI?
21. What search period is selected by default after I click the Instant Investigation tab?
22. How is Instant Investigation different from the Chaos Dashboard? When should I use one vs the other?
Last updated
Was this helpful?