Vectra AI
Create an API Client (Cloud Deployment)



Create an API Token (On-Premise Deployment)




Enable Vectra AI
Dropzone Field
Source








Last updated
Was this helpful?
The Dropzone AI Platform integrates with Vectra AI, an AI-driven NDR platform for automated threat detection and response across hybrid networks, including public clouds, SaaS, identity systems, and data centers. Dropzone supports both Cloud and On-premise deployments of Vectra AI.
If you have a Cloud deployment, Vectra AI requires an API Client and Secret Key to enable.
To obtain these, do the following:
Log in to your Vectra AI console
In the left sidebar, navigate to Manage > API Clients
Click "Add API Client"

Name the client something memorable, such as "Dropzone AI"
Assign the client the Read-Only role
Click "Generate Credentials"

Copy the Client ID and Secret Key generated for use later in the Dropzone UI, where they are called "OAuth2 Client ID" and "OAuth2 Client Secret," respectively

Log in to your Vectra AI console
In the left sidebar, navigate to My Profile

Click "View API Token"

Input your password, then click "Continue"

Copy the API token shown for use later in the Dropzone UI, where it is called "API Token"

Click "Close"
To enable the Alert Source integration, you'll need the following information:
Deployment Type
Your Vectra AI deployment type, e.g. Cloud or On-premise
Vectra AI URL
The base URL of your Vectra instance, e.g. https://api.vectra.ai or https://10.20.1.5
OAuth2 Client ID
The Client ID value you copied earlier. Only necessary for Cloud deployments
OAuth2 Client Secret
The Secret Key value you copied earlier. Only necessary for Cloud deployments
Vectra AI Server
The server hostname of your on-premise deployment, e.g. 10.20.1.5
Vectra AI Port
The API port of your on-premise deployment
To enable the Alert Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Library"
If you have previously integrated this application, click "Configured"

In the Search bar, search Vectra AI then click "Configure"

Under the Alert Source header, if your Vectra AI integration is behind an On-premise Dropzone Connector, select your connector from the dropdown
Input your Deployment Type and Vectra AI URL

If you have a Cloud deployment, input the OAuth2 Client ID and Secret

If you have an On-premise deployment, input the Vectra AI Server, Port, and API Token

Input your desired poll interval and lookback

If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"
Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
Contact your Dropzone AI support representative for more information about this feature

Click "Test & Save" to finish
If you have any errors or questions, engage your Dropzone AI support representative.
Last updated
Was this helpful?
Was this helpful?