Earlier name/vendor
Vectra Cognito
This is the multi-page printable view of this section. Click here to print.
Vectra Cognito
X-Series: Detects and investigates cyberattacks across cloud, data center, and enterprise networks using AI.
To onboard such an appliance to Axoflow, complete the generic appliance onboarding steps.
Axoflow automatically adds the following labels to data collected from this source:
label | value |
---|---|
vendor | vectra |
product | x-series |
format | cef |
When sending the data collected from this source to Splunk, Axoflow uses the following sourcetype and index settings:
sourcetype | index |
---|---|
vectra:cognito:detect | main |
vectra:cognito:accountdetect | main |
vectra:cognito:accountscoring | main |
vectra:cognito:audit | main |
vectra:cognito:campaigns | main |
vectra:cognito:health | main |
vectra:cognito:hostscoring | main |
vectra:cognito:accountlockdown | main |
When sending the data collected from this source to a dynamic Google SecOps destination, Axoflow sets the following log type: VECTRA_DETECT
.