{
    "Name": "Vectra AI Stream",
    "Author": "Vectra TME Team - tme@vetcra.ai",
    "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/AIVectraDetect.svg\"width=\"75px\"height=\"75px\">",
    "Description": "**Note:** Please refer to the following before installing the solution: \n\n• There may be [known issues](https://aka.ms/sentinelsolutionsknownissues) pertaining to this Solution, please refer to them before installing.\n\nThe [Vectra AI Stream](https://www.vectra.ai/products/platform) solution allows you to easily connect your Vectra Platform with Microsoft Sentinel, to ingest network metadata collected at scale throughout your environment by Vectra sensors (On-premise or Cloud). This gives you deep insight into your organization's network traffic and improves your security operation capabilities. For a complete list of protocols and attributes supported, check out our [Network Metadata reference guide]( https://support.vectra.ai/s/article/KB-VS-1245)\n\r\n1. ** Vectra AI Stream (Network Enriched Metadata) via AMA** - This data connector helps ingest Vectra AI Stream events into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here]( https://learn.microsoft.com/en-us/azure/sentinel/connect-cef-syslog-ama). **Microsoft recommends using this Data Connector**.\n\r\n2. ** Vectra AI Stream (Network Enriched Metadata) via Legacy Agent** - This data connector helps ingest Vectra AI Stream events into your Log Analytics Workspace using the legacy Log Analytics agent.\n\n**NOTE:** Microsoft recommends installation of ** Vectra AI Stream (Network Enriched Metadata) via AMA Connector. Legacy connector uses the Log Analytics agent which is about to be deprecated by **Aug 31, 2024,** and thus should only be installed where AMA is not supported. Using MMA and AMA on same machine can cause log duplication and extra ingestion cost [more details](https://learn.microsoft.com/en-us/azure/sentinel/ama-migrate).",
    "Data Connectors": [
      "Vectra AI Stream/Data Connectors/Connector_VectraAI_Stream.json",
      "Vectra AI Stream/Data Connectors/template_VectraStreamAma.json"
    ],
    "Parsers": [
      "Vectra AI Stream/Parsers/VectraStream_function.yaml",
      "Vectra AI Stream/Parsers/vectra_beacon.yaml",
        "Vectra AI Stream/Parsers/vectra_dcerpc.yaml",
        "Vectra AI Stream/Parsers/vectra_dhcp.yaml",
        "Vectra AI Stream/Parsers/vectra_dns.yaml",
        "Vectra AI Stream/Parsers/vectra_http.yaml",
        "Vectra AI Stream/Parsers/vectra_isession.yaml",
        "Vectra AI Stream/Parsers/vectra_kerberos.yaml",
        "Vectra AI Stream/Parsers/vectra_ldap.yaml",
        "Vectra AI Stream/Parsers/vectra_ntlm.yaml",
        "Vectra AI Stream/Parsers/vectra_radius.yaml",
        "Vectra AI Stream/Parsers/vectra_rdp.yaml",
        "Vectra AI Stream/Parsers/vectra_smbfiles.yaml",
        "Vectra AI Stream/Parsers/vectra_smbmapping.yaml",
        "Vectra AI Stream/Parsers/vectra_smtp.yaml",
        "Vectra AI Stream/Parsers/vectra_ssh.yaml",
        "Vectra AI Stream/Parsers/vectra_ssl.yaml",
        "Vectra AI Stream/Parsers/vectra_stream.yaml",
        "Vectra AI Stream/Parsers/vectra_x509.yaml",
        "Vectra AI Stream/Parsers/vectra_match.yaml"
    ],
    
    "Metadata": "SolutionMetadata.json",
    "BasePath": "C:\\Users\\fguillot\\Documents\\GitHub\\Azure-Sentinel\\Solutions\\Vectra AI Stream",
    "Version": "3.0.1",
    "TemplateSpec": true,
    "Is1Pconnector": false
  }