The Vectra AI Platform provides coverage, clarity, and control across the entire modern network. Coverage for attackers’ moves across all of your network, identity, and cloud threat surfaces. AI signal clarity prioritizes attacks with AI assistants to automatically triage, correlate, and prioritize threats across domains. We put you in control with context to discover, hunt, investigate, and stop attacks early in their progression - all while spending less time prioritizing alerts.
Software updates, including new threat intelligence and detection algorithms, are included with your license. They are delivered to your system on a regular basis to ensure continuous protection from the latest threats. Vectra Match customers can also choose to enable automated curated ruleset updates that provide signature updates.
Vectra appliances are supported in traditional physical on-prem, virtual hypervisor, and IaaS cloud environments. Vectra supports AWS, Azure, and GCP clouds along with VMware, Hyper-V, Nutanix, and KVM hypervisors. Vectra continually evaluates customer demand for support of new environments. Please check with your account team for questions on future plans.
X-Series and S-Series appliances can perform “Sensor” duties, passively capturing network traffic out-of-band and forwarding a metadata stream to the“Brain” appliance for further processing. B-Series and X-Series appliances can serve as the Brain for your deployment. They run network detection models locally and serve as customer side integration point for added coverage, response, and context enhancement options. The Brain appliance is connected to the Vectra cloud where the Respond UX provides the UI along with advanced features such as Instant Investigation and AI-Assisted Search. In Quadrant UX deployments, the Brain appliance serves the classic Vectra UI locally.
Network traffic can be directed to appliances through physical SPAN/Copy/Mirror ports, TAPs, and packet brokers. Native cloud packet forwarding options are supported such as VPC Traffic Mirroring (AWS), VTAP (Azure), and NSI (GCP). Hypervisor based packet forwarding options are also supported. Vectra Sensors support a variety of encapsulation methods such as VXLAN andGENEVE. For additional detail, please see the Vectra NDR (Detect) and Network Identity Architecture Overview.
Specifiche fisiche del dispositivo
X3
X29/M29*
X47/M47*
Management Interfaces (MGT)
2 x 1GbE Copper
2 x 1 GbE in rame
2 x 1 GbE in rame
Capture Interfaces†
2 x 1 GbE Copper 2 x 10 GbE SFP+
2 x 1 GbE Copper 2 x 10 GbE SFP+
2 x 1 GbE Copper 2 x 10/25 GbE SFP28
Alternate Interface Configuration
N/D
Yes, see footnote
Yes, see footnote
Paired Sensors††
150
150
150
Tracked Hosts1
100,000
150,000
150,000
Prestazioni in modalità sensore
9 Gbps
15 Gbps
20 Gbps
Prestazioni in modalità mista
8 Gbps
8 Gbps
15 Gbps
Prestazioni in modalità cervello
14 Gbps
20 Gbps
30 Gbps
Match Throughput
Sensor 3 Gbps Mixed 1 Gbps
Sensor 9 Gbps Mixed 4.6 Gbps
Sensor 13 Gbps Mixed 6 Gbps
Tensione di ingresso
Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz
Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz
Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz
Potenza
Normal: 277 W (945 BTU/h) Max: 392 W (1338 BTU/h)
Normal: 296 W (10010 BTU/h) Max: 337 W (1150 BTU/h)
Normal: 602 W (2204 BTU/h) Max: 866 W (2966 BTU/h)
Attuale
3.5 A at 110 VAC 1.7 A at 220 VAC
2.9 A at 110 VAC 1.5 A at 220 VAC
8.0 A at 110 VAC 3.9 A at 220 VAC
Dimensioni
42.8 mm (1.685 inches) H 482 mm (18.976 inches) W 662.19 mm (26.070 inches) D
42.8 mm (1.685 inches) H 482 mm (18.976 inches) W 787.04 mm (30.99 inches) D
42.8 mm (1.685 inches) H 482 mm (18.976 inches) W 787.04 mm (30.99 inches) D
Peso
16,6 kg (36,6 lb)
17.5 kg (38.6 lb)
20,3 kg (44,8 lb)
Ambiente
Operating temperature 10° to 35° C (50° to 95° F) Non-operating temperature -40° to 65° C (-40° to 149° F) Airflow: Front to back, 26 CFM = 12.3 l/s Sound Power 3.8 bels
Operating temperature 10° to 35° C (50° to 95° F) Non-operating temperature -40° to 65° C (-40° to 149° F) Airflow: Front to back, 35.8 CFM = 16.9 l/s Sound Power 7.2 bels
Operating temperature 10° to 35° C (50° to 95° F) Non-operating temperature -40° to 65° C (-40° to 149° F) Airflow: Front to back, 111.8 CFM = 52.8 l/s Sound Power 8.4 bels
MTBCF
45,700 hours
87,600 hours
97,300 hours
Alternate Interface Configuration: *For the X29/M29 and X47/M47 appliances, one of the 10 GbE SFP+ ports that are normally used for capture traffic can be configured to be used as a management interface. When configured as such, the original MGT1 copper port would be unused.
Please see the quick start guides for these appliances for full details and how to configure the alternate interface configurations.
S1**
S11
S101
Management Interfaces (MGT)†
2 x 1 GbE in rame
2 x 1 GbE in rame
2 x 10 GbE SFP+
Capture Interfaces†
4 x 1 GbE Copper 2 x 10 GbE SFP+
2 x 1 GbE in rame
2 x 10 GbE SFP+ 2 configurable to: 10/25 GbE SFP28, 40 GbE QSFP, 100 GbE QSFP28
Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz
Potenza
Normal: Not available Max: 45W (154 BTU/h)
Normal: 152 W (519 BTU/h) Max: 186 W (635 BTU/h)
Normal: 615 W (2098 BTU/h) Max: 868 W (2962 BTU/h)
Attuale
2.0 A at 100 VAC 1.0 A at 240 VAC
1.7 A at 110 VAC 0.8 A at 220 VAC
7.9 A at 110 VAC 3.8 A at 220 VAC
Dimensioni
52 mm (2.04 in) H 208 mm (8.18 in) W - 200 mm (7.87 in) D
42.8 mm (1.685 inches) H 434 mm (17.1 inches) W 535 mm (22.6 inches) D
42.8 mm (1.685 inches) H 482 mm (18.976 inches) W 808.5 mm (31.8 inches) D
Peso
Without power supply unit (PSU): 1.4 kg (3.1 lb) Including power supply and packaging: 4.9 kg (10.8 lb)
12.2 kg (26.9 lb)
21 kg (46.3 lb)
Ambiente
Operating temperature 0° to 40° C (32° to 104° F) Non-operating temperature -40° to 70° C (-40° to 158° F) Airflow: In bottom, out sides and back, 10 CFM = 4.7 l/s Sound Power 4.8 bels
Operating temperature 0° to 40° C (32° to 104° F) Non-operating temperature -40° to 70° C (-40° to 158° F) Airflow: Front to back, 11.4 CFM = 5.4 l/s Sound Power 5.7 bels
Operating temperature 10° to 35° C (50° to 95° F) Non-operating temperature -40° to 65° C (-40° to 149° F) Airflow: Front to back, 61.6 CFM = 29.1 l/s Sound Power 7.6 bels
MTBCF
445,000 hours
109,000 hours
107,000 hours
Alternate Interface Configuration:
**For the S1 appliance, both management and capture ports can be configured to use one of the 10 GbE SFP+ ports for either management or capture use. In the default configuration, only the cooper interfaces are used. This results in4 different potential interface configurations for the S1 appliance.
Please see the quick start guides for these appliances for full details and how to configure the alternate interface configurations.
B101
B127
Management Interfaces (MGT)†
2 x 10 GbE SFP+
2 x 10/25 GbE SFP28
Capture Interfaces
N/D
N/D
Alternate Interface Configuration
N/D
N/D
Paired Sensors††
500
500
Tracked Hosts1
300,000
300,000
Prestazioni in modalità sensore
N/D
N/D
Prestazioni in modalità mista
N/D
N/D
Prestazioni in modalità cervello
75 Gbps
75 Gbps
Match Throughput
N/D
N/D
Tensione di ingresso
Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz
Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz
Potenza
Normal: 604 W (2061 BTU/h) Max: 846 W (2887 BTU/h)
773 W (2638 BTU/h) Max: 1149 W (3920 BTU/h)
Attuale
7.7 amps at 110 VAC 3.7 amps at 220 VAC
10.7 amps at 110 VAC 5.3 amps at 220 VAC
Dimensioni
42.8 mm (1.685 inches) H 482 mm (18.976 inches) W 808.5 mm (31.8 inches) D
42.8 mm (1.685 inches) H 482 mm (18.976 inches) W 787.04 mm (30.99 inches) D
Peso
21 kg (46.3 lb)
20,3 kg (44,8 lb)
Ambiente
Operating temperature 10° to 35° C (50° to 95° F) Non-operating temperature -40° to 65° C (-40° to 149° F) Airflow: Front to back, 61.6 CFM = 29.1 l/s Sound Power 7.6 bels
Operating temperature 10° to 35° C (50° to 95° F) Non-operating temperature -40° to 65° C (-40° to 149° F) Airflow: Front to back, 111.8 CFM = 52.8 l/s Sound Power 8.4 bels
MTBCF
109,000 hours
132,000 hours
† SFP Options : For any appliance that supports SFP interface (SFP+, SFP28, QSFP, QSFP28, etc), please see the SFPs and QSFPs supported in Vectra appliances article on the Vectra support site for additional details and note the following regarding which can be included free as part of your order, or added to your order for an additional cost:
Up to 2 (if supported by your appliance model), SFP, SFP+, or SFP28 modules can be included at no additional cost in your appliance order.
This is valid for each appliance in your order.
Additional SFPs above a count of the two per appliance specified above, will incur additional cost.
All 40/100G QSFPs will incur additional cost over the base price of the appliance.
†† Paired Sensors : Refers to how many Sensors (physical, virtual, or cloud) an appliance can pair with. 1 Tracked Hosts : Refers to how many hosts the appliance running in Brain or Mixed mode can track simultaneously (open host sessions). Brains can typically retain and display data for larger numbers of hosts, this only refers to how many hosts the system can process metadata for simultaneously. Performance – Refers to the amount of network traffic observed by Sensors that a Sensor can produce metadata for, or the amount of traffic observed by Sensors that a Brain can process metadata for. The performance numbers are based upon average throughput a given Sensor/Brain can process. Actual performance may vary depending on traffic composition. Please contact Vectra AI to discuss further.
Please see the quick start guides for these appliances for full details and how to configure the alternate interface configurations.
Vectra Match Performance
Elettrodomestici
Modalità
Match Throughput (Detect and Match)
S1
Sensore
400 Mbps
S11
Sensore
1,2 Gbps
S101
Sensore
33 Gbps
X3
Sensore
3 Gbps
X3
Misto
1 Gbps
X29
Sensore
9 Gbps
X29
Misto
4,6 Gbps
X47
Sensore
13 Gbps
X47
Misto
6 Gbps
2 core vSensor (VMware, Hyper-V, KVM, Nutanix)
Sensore
250 Mbps
4 core vSensor (VMware, Hyper-V, KVM, Nutanix)
Sensore
500 Mbps
8 core vSensor (VMware, Hyper-V, KVM, Nutanix)
Sensore
1 Gbps
16 core vSensor (VMware, Hyper-V, KVM, Nutanix)
Sensore
2,5 Gbps
32 core vSensor (VMware)
Sensore
10 Gbps
2 vSensori core (AWS, Azure, GCP)
Sensore
500 Mbps
4 vSensori core (AWS, Azure, GCP)
Sensore
1 Gbps
8 core vSensor (AWS)
Sensore
2 Gbps
16 core vSensor (AWS)
Sensore
4 Gbps
16 core vSensor (GCP)
Sensore
2,5 Gbps
32 core vSensor (GCP)
Sensore
5 Gbps
Virtual Brains - Distribuzione di Hypervisor presso il cliente
Hypervisor
Tipo VM
Nuclei
Memoria
Storage (OS, Data) in GB
Sensori accoppiati
Tracked Hosts
Prestazioni
VMware
vSphere 6.5 o successivo
4
48GB
128,512
5
25,000
150 Mbps
VMware
vSphere 6.5 o successivo
6
48GB
128,512
10
37,500
500 Mbps
VMware
vSphere 6.5 o successivo
8
64GB
128,512
15
50,000
2 Gbps
VMware
vSphere 6.5 o successivo
16
128GB
128,512
25
50,000
4 Gbps
VMware
vSphere 6.5 o successivo
32
256GB
128,512
100
150,000
10 Gbps
Nutanix
AOS 6.8.1 and higher with Prism Central (and v3 API) available
32
256GB
128,512
100
150,000
10 Gbps
Sensori virtuali - Distribuzione di Hypervisor presso il cliente
Hypervisor
Tipo VM
Nuclei
Memoria
Immagazzinamento
Prestazioni
VMware
vSphere 6.5 o successivo
2
8 GB
100 GB
500 Mbps
VMware
vSphere 6.5 o successivo
4
8 GB
150 GB
1 Gbps
VMware
vSphere 6.5 o successivo
8
16 GB
150 GB
2 Gbps
VMware
vSphere 6.5 o successivo
16
64 GB
600 GB*
5 Gbps
VMware
vSphere 6.5 o successivo
32
114 GB
830 GB
20 Gbps
Hyper-V
Windows Server 2016 con HW v8 o superiore
2
8 GB
100 GB
500 Mbps
Hyper-V
Windows Server 2016 con HW v8 o superiore
4
8 GB
150 GB
1 Gbps
Hyper-V
Windows Server 2016 con HW v8 o superiore
8
16 GB
150 GB
2 Gbps
Hyper-V
Windows Server 2016 con HW v8 o superiore
16
64 GB
500 GB
5 Gbps
KVM
PC standard (Q35 + ICH9, 2009)
2
8 GB
100 GB
500 Mbps
KVM
PC standard (Q35 + ICH9, 2009)
4
8 GB
150 GB
1 Gbps
KVM
PC standard (Q35 + ICH9, 2009)
8
16 GB
150 GB
2 Gbps
KVM
PC standard (Q35 + ICH9, 2009)
16
64 GB
500 GB
5 Gbps
Nutanix
Versione AOS: 5.20.3.5 o successiva Versione AHV 2021105.2267 o successiva
2
8 GB
100 GB
500 Mbps
Nutanix
Versione AOS: 5.20.3.5 o successiva Versione AHV 2021105.2267 o successiva
4
8 GB
150 GB
1 Gbps
Nutanix
Versione AOS: 5.20.3.5 o successiva Versione AHV 2021105.2267 o successiva
8
16 GB
150 GB
2 Gbps
Nutanix
Versione AOS: 5.20.3.5 o successiva Versione AHV 2021105.2267 o successiva
16
64 GB
500 GB
5 Gbps
Cloud - Distribuzione IaaS
Dispiegamento del cervello
Cloud
Tipo VM
Nuclei
Memoria
Storage (OS, Data, Data, Data) in GB
Sensori accoppiati
Tracked Hosts
Prestazioni
AWS
r5d.2xlarge
8
64 GB
256, 64, 128, 256
15
50,000
2 Gbps
AWS
r5d.4xlarge
16
128 GB
256, 64, 128, 256
25
50,000
5 Gbps
AWS
r5d.8xlarge
32
256 GB
256, 64, 128, 256
100
150,000
15 Gbps
AWS
r5.16xlarge
64
512 GB
2562, 64, 512, 512
500
500,000
50 Gbps
Azzurro
Standard_E16s_v3
16
128 GB
256, 64, 128, 256
25
50,000
5 Gbps
Azzurro
Standard_E32s_v3
32
256 GB
256, 64, 128, 256
100
150,000
15 Gbps
GCP
n2-highmem-16
16
128 GB
1 TB (single partition)
25
50,000
5 Gbps
GCP
n2-highmem-32
32
256 GB
1 TB (single partition)
100
150,000
15 Gbps
GCP
n2-highmem-64
64
512 GB
1.2 TB (single partition)
100
150,000
50 Gbps
GCP
n2-highmem-96
96
768 GB
4 TB (partizione singola)
100
500,000
85 Gbps
2 This disk has upgraded performance over standard EBS volumes.
Distribuzione di vSensor
Cloud
Tipo VM
Nuclei
Memoria
Storage (OS, Data) in GB
Prestazioni
AWS
r5(n).large3
2
16 GB
50, 128
1 Gbps
AWS
r5(n).large3
4
32 GB
50, 128
2 Gbps
AWS
r5(n).2xlarge3
8
64 GB
50, 512
4 Gbps
AWS
r5(n).4xlarge3
16
128 GB
50, 512
8 Gbps
AWS
c5n.18xlarge3
72
192 GB
50, 128 (No PCAP capability) 3
Up to 10 Gbps3
Azzurro
Standard_DS11_v2
2
14 GB
50, 128
1 Gbps
Azzurro
Standard_DS3_v2
4
14 GB
50, 128
2 Gbps
GCP
e2-standard-2
2
8 GB
50, 128
1 Gbps
GCP
e2-standard-4
4
16 GB
50, 128
2 Gbps
GCP
e2-standard-16
16
64 GB
50, 128
5 Gbps
GCP
e2-standard-32
32
128 GB
50, 128
10 Gbps
3 AWS vSensor configurations include both “n” and non “n” r5 instance types.
Networking performance is quoted as “up to 10Gbps” on the r5 instances by AWS and can be influenced by neighboring instances allocated to the same physical hardware inAWS.
Networking performance is quoted as “up to 25Gbps” on the r5n instances by AWS. These instances are still shared with neighbors but are optimized by AWS to have higher overall network throughput.
Customers can work with AWS to utilize dedicated instances and distribute instances to provide the required networking throughput to their vSensor instances on that dedicated hardware.
Il tipo di istanza vSensor di grandi dimensioni c5n.18x non dispone di un buffer di cattura mobile e pertanto non può supportare la generazione di PCAP per i rilevamenti originati dal traffico elaborato da tali istanze.
A causa della variabilità delle configurazioni di rete cloud dei clienti e delle modalità di configurazione del mirroring, non è possibile garantire le prestazioni su istanze con più di 2 core (i numeri sono approssimativi e si basano su una distribuzione uniforme dei pacchetti tra i thread). Contattare Vectra per ulteriori informazioni.
Vectra monitors instance types available from the supported IaaS vendors for cost, performance, and availability. If you have questions about specific instance types that are not supported, please contact your Vectra account team.
Fiducia da parte di esperti e aziende di tutto il mondo