IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Flow correlation exclusions not working as expected

    Posted 15 days ago

    Recently I did some tuning around a "Large outbound transfer..." flow rule. For false positive avoidance, I created a rule that does "bypass correlation" - targets the original rule, uses a BB with a list of destination ports I want to avoid, references several local source networks and also references some trusted Remote networks. However, I keep getting the offenses which I believe should not appear. Interestingly, when I bring up the resulting set of flows from the offense and make a search to exclude some records using the tests/criteria in the exclusion rule - the list of flow records clears out (suggesting the rule should have behaved the same as the search). 

    Has anyone noticed something similar? 

    (BTW, it's on 7.5.0UP14IF05)



    ------------------------------
    Dusan VIDOVIC
    ------------------------------


  • 2.  RE: Flow correlation exclusions not working as expected

    Posted 14 days ago

    Hey Dusan,

    If you search for rule hits, do the records show up then, but only as EP events, so the raw flow does not show up?  If so, yes, I have seen this with event and flows, they match the rule and then disappear.  Sometimes searching on the rule will allow you to find them, but it is not very consistent.  



    ------------------------------
    Frank Eargle
    Senior Information Security Architect
    GlassHouse Systems
    Columbia SC
    ------------------------------



  • 3.  RE: Flow correlation exclusions not working as expected

    Posted 14 days ago

    Hi Frank. 

    It's actually that I expected that they would not end up in a offense :)

    When I pull these flows from the offense I see them tagged with some of BBs I used on the false positive rule (to bypass correlation) and I also see the final one actually tagged with the False positive rule (!) If I run a search against these with a test from the false positive rule, the list empties out (as I would generally expect). Interestingly also, accessing these flows from the offense and looking at the list, none have that "part of offense" icon in the most left column (though the CRE event the rule triggers has it). 



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 4.  RE: Flow correlation exclusions not working as expected

    Posted 11 days ago

    Wow, after the FP rule hit, there should have been no other rules as you know.  For the flow to not have the offense flag but be be part of the rule that triggered offense is very strange. 

    I think you are going to have to go to support with this one.  Please keep us posted.  



    ------------------------------
    Frank Eargle
    Senior Information Security Architect
    GlassHouse Systems
    Columbia SC
    ------------------------------