Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Vectra Networks Vectra Sample Event Messages

Use these sample event messages to verify a successful integration with JSA.

Note:

Due to formatting issues, paste the message format into a text editor and then remove any carriage return or line feed characters.

Vectra Networks Vectra Sample Messages when you use the Syslog Protocol

Sample 1: The following sample event message shows when samba is exploited.

Table 1: Highlighted Values in the Vectra Networks Vectra Sample Event

JSA field name

Highlighted values in the event payload

Event ID

SMB Brute-Force

Event Category

LATERAL MOVEMENT

Source IP

10.125.64.136

Destination IP

10.160.0.145

Destination Port

445

Sample 2: The following sample event message shows that there is suspicious activity.

Table 2: Highlighted Values in the Vectra Networks Vectra Sample Event

JSA field name

Highlighted values in the event payload

Event ID

Suspicious Kerberos Account

Event Category

LATERAL MOVEMENT

Source IP

10.97.48.6

Destination IP

10.160.0.90

Destination Port

80