Document toolboxDocument toolbox

ndr.vectra

Introduction

The tags beginning with ndr.vectra identify events generated by Vectra.

Valid tags and data tables 

The full tag must have at least 3 levels. The first two are fixed as ndr.vectra. The third level identifies the type of events sent. The fourth level indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Vectra Cognito Stream

ndr.vectra.cognito_stream

ndr.vectra.cognito_stream

ndr.vectra.cognito_stream.dcerpc

ndr.vectra.cognito_stream.dcerpc

ndr.vectra.cognito_stream.dhcp

ndr.vectra.cognito_stream.dhcp

ndr.vectra.cognito_stream.dns

ndr.vectra.cognito_stream.dns

ndr.vectra.cognito_stream.httpsessioninfo

ndr.vectra.cognito_stream.httpsessioninfo

ndr.vectra.cognito_stream.isession

ndr.vectra.cognito_stream.isession

ndr.vectra.cognito_stream.kerberos_txn

ndr.vectra.cognito_stream.kerberos_txn

ndr.vectra.cognito_stream.ldap

ndr.vectra.cognito_stream.ldap

ndr.vectra.cognito_stream.ntlm

ndr.vectra.cognito_stream.ntlm

ndr.vectra.cognito_stream.rdp

ndr.vectra.cognito_stream.rdp

ndr.vectra.cognito_stream.smbfiles

ndr.vectra.cognito_stream.smbfiles

ndr.vectra.cognito_stream.smbmapping

ndr.vectra.cognito_stream.smbmapping

ndr.vectra.cognito_stream.smtp

ndr.vectra.cognito_stream.smtp

ndr.vectra.cognito_stream.ssl

ndr.vectra.cognito_stream.ssl

ndr.vectra.cognito_stream.x509

ndr.vectra.cognito_stream.x509

Vectra platform

ndr.vectra.platform.detection

ndr.vectra.platform.detection

For more information, read more About Devo tags.

How is the data sent to Devo?

Logs generated by Vectra must be sent to the Devo platform via the Devo Relay to secure communication. See the required relay rule below:

  • Source data - \"metadata_([^\"]+)

  • Target tag - ndr.vectra.cognito_stream.\\D1

  • Stop processing -

  • Sent without syslog tag -

No 3rd-party mechanism is used. No collector is needed.

Table structure

These are the fields displayed in these tables: