Skip to main content
The Vectra M365 - Incident Detection source plugin (name: http_loader, alias: vectra-m365-incident-detection) lets you retrieve data from Vectra and ingest it into a telemetry pipeline. This is a pull-based source plugin.
This plugin doesn’t support the use of a descriptive metadata name in the Pipeline Builder interface.
This plugin doesn’t support duplicates of itself within the same pipeline. Additionally, this plugin can’t be used in combination with these source plugins within the same telemetry pipeline:

Supported telemetry types

The for Chronosphere Telemetry Pipeline supports these telemetry types:
LogsMetricsTraces

Configuration parameters

Use the parameters in this section to configure the . The Telemetry Pipeline web interface uses the items in the Name column to describe these parameters. Pipeline configuration files use the items in the Key column as YAML keys.

General

NameKeyDescriptionDefault
Vectra Portal URLoauth2_token_urlRequired. Your Vectra portal URL.none
OAuth2 Client IDoauth2_client_idRequired. Your OAuth2 client ID for accessing the Vectra portal.none
OAuth2 Client Secretoauth2_client_secretRequired. The OAuth2 secret key for accessing the Vectra portal.none

Advanced

NameKeyDescriptionDefault
Memory Buffer Limitmem_buf_limitFor pipelines with the Deployment or DaemonSet workload type only. Sets a limit for how much buffered data the plugin can write to memory, which affects backpressure. This value must follow Fluent Bit’s rules for unit sizes. If unspecified, no limit is enforced.none