Vectra RUX Security Data Connector (via Codeless Connector Framework)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID VectraRUXConnector
Publisher Vectra AI
Used in Solutions Vectra XDR
Collection Method CCF
Connector Definition Files VectraRUX_ConnectorDefinition.json
DCR Definition Files VectraRUX_DCR.json
CCF Configuration VectraRUX_PollingConfig.json
CCF Capabilities OAuth2, Paging

The Vectra RUX data connector enables you to ingest security data from the Vectra AI platform into Microsoft Sentinel through the REST API using the Codeless Connector Framework (CCF). This connector supports 3 data streams using OAuth2 client credentials:

The connector is built on the Microsoft Sentinel Codeless Connector Platform and supports DCR-based ingestion time transformations for optimized query performance.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
Detections_Data_CCF_CL ? ✓ ?
Entities_Data_CCF_CL ? ✓ ?
Lockdown_Data_CCF_CL ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Configure Vectra RUX Connection

Connect to Vectra RUX and select data stream

Vectra RUX Data Connector Configuration

Configure your Vectra RUX connection and select the data stream you want to collect. Each stream provides different types of security data from your Vectra AI platform. Connector Management Interface

This section is an interactive interface in the Microsoft Sentinel portal that allows you to manage your data collectors.

📊 View Existing Collectors: A management table displays all currently configured data collectors with the following information:

➕ Add New Collector: Click the "Add new collector" button to configure a new data collector (see configuration form below).

🔧 Manage Collectors: Use the actions menu to delete or modify existing collectors.

💡 Portal-Only Feature: This configuration interface is only available when viewing the connector in the Microsoft Sentinel portal. You cannot configure data collectors through this static documentation.

Add Vectra RUX Data Stream Connection

Configure Vectra RUX API connection and select data stream

When you click the "Add Connection" button in the portal, a configuration form will open. You'll need to provide:

Base Configuration

Base API Configuration

OAuth2 Client Credentials

Data Stream Configuration

💡 Portal-Only Feature: This configuration form is only available in the Microsoft Sentinel portal.

ℹ️ Note: After adding a connection, the Detections stream polls every 5 minutes using a persistent checkpoint cursor (PersistentToken) — position-based, not time-based. The cursor survives pod restarts and long pagination runs; no events will be silently skipped due to clock drift or slow pages. First poll seeding: Provide the detectionsStartingCheckpoint value when creating the connection to start ingestion at your current event position rather than from the beginning of history.

ℹ️ Troubleshooting Rate Limits (HTTP 429 Errors) when adding connections:

2. Monitor and Validate Data Collection

Monitor data ingestion and validate connectivity

Post-Configuration Steps

  1. Monitor Connection Status: Check the connector status in the Data connectors page.

  2. Validate Data Flow: Use the sample queries provided to verify data is being collected.

  3. Review Connector Health (Optional): The SentinelHealth table provides per-poll-cycle status for each data stream, including failure reasons for authentication, network, and ingestion errors. It is not enabled by default.

    To enable: Go to Microsoft Sentinel → Settings → Settings tab → Health and Audit and toggle on health monitoring for data connectors. See Enable health monitoring for Microsoft Sentinel for full instructions.

    Once enabled, run the following query to check connector poll status:

    SentinelHealth | where TimeGenerated > ago(24h) | where SentinelResourceType == "Data connector" | project TimeGenerated, SentinelResourceName, Status, Description, Reason | order by TimeGenerated desc

Stream-Specific Notes

ℹ️ PersistentToken Checkpoint Mode (Detections)

The Detections poller uses PersistentToken — the next_checkpoint value returned by the Vectra API is stored by CCF and passed back as from=<checkpoint> on the next poll cycle. This is position-based (monotonic id-based), not time-based, so slow pagination or pod restarts cannot cause silent data gaps.

Cold-start behaviour: On the very first poll after deployment, CCF sends from=<detectionsStartingCheckpoint> as the starting cursor. Ingestion begins at this cursor position, ensuring no historical backlog is ingested. Once the first poll completes, PersistentToken persists the returned next_checkpoint and all subsequent polls use the stored value automatically.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index