Overview
Stream enables the Vectra Platform to continuously send enriched network security metadata from a VPC deployment to a private data-lake, where it can be analyzed by security researchers and SOC professionals. Please Note - Vectra Stream requires an operational Vectra install.
Highlights
- Vectra is transforming cybersecurity with AI. Its Cognito platform provides network detection and response in real time while empowering threat hunters to perform highly efficient incident investigations.
Details
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Contact your Vectra sales representative
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Cognito Stream
Stream is a component of the Cognito Platform, required to use the Cognito Stream application. Stream is deployed in the customer's VPC. It receives network metadata from the Cognito Brain, converts it into a standard Bro / Zeek format and forwards it to the customer's data-lake.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
This release is for customers with existing Cognito Brain instances running version 8.7 and above. Please upgrade Brain instances to version 8.7 before continuing.
Additional details
Usage instructions
Verify your Cognito Brain is running version 7.8 or higher. Retrieve the IP Address of your Cognito Brain and the Sensor Registration Token from the Settings page under the Sensor section. Deploy Cognito Stream from AWS Marketplace, and provide the IP address of the Cognito Brain and the Sensor Registration token. The Stream instance's mgtSubnet needs access to ports 22 and 443 on the Cognito Brain. After the instance launches, it will automatically attempt to pair with the Brain IP provided. Log in to the Cognito Brain, browse to Settings page and select the Cognito Stream tab. Check the status and configure the destination for the metadata of the Stream instance. See the "Resources" section in the Cognito Brain UI for a copy of the complete setup documentation.
Resources
Vendor resources
Support
Vendor support
Login, email or call us 24/7
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.