Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update VectraAI Data Integration to new Add-On (currrent one used by SC4S is deprecated) #2669

Open
LennardMa opened this issue Jan 10, 2025 · 2 comments
Assignees
Labels
documentation Improvements or additions to documentation enhancement New feature or request

Comments

@LennardMa
Copy link

LennardMa commented Jan 10, 2025

Note: If your issue is not a bug or a feature request, please raise a support ticket through our support portal (Splunk.com > Support > Support Portal). This will help us resolve your issue more efficiently and provide you with better assistance. For more information on how to work with the Splunk Support, please refer to this guide.

What is the sc4s version?

3.33.1

Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?

What the vendor name?

Vectra

What's the product name?

Cognito

If you're requesting support for a new vendor, do you have any preferences regarding the default index and sourcetype for their events?

Do you have syslog documentation or a manual for that device??

Feature Request description:

Currently SC4S uses the old and deprecated "Technology Add-On for Vectra Cognito" instead of the current "Technology Add-On for Vectra Detect (JSON)" at https://splunkbase.splunk.com/app/5271 Please either disable the old add-on or update to the new vendor supported add-on.

Do you want to have it for local usage or prepare a github PR?

@cwadhwani-splunk cwadhwani-splunk self-assigned this Jan 13, 2025
@cwadhwani-splunk cwadhwani-splunk added documentation Improvements or additions to documentation enhancement New feature or request labels Jan 16, 2025
@LennardMa
Copy link
Author

@cwadhwani-splunk Hello, I now have a pcap that i captured and the custom syslog parser that Splunk AE build, where should I send it to?

@cwadhwani-splunk
Copy link
Collaborator

cwadhwani-splunk commented Jan 21, 2025

Could you please create a Splunk support ticket and attach the details there? Once done you can provide the support ticket number/ID here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants