IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
Expand all | Collapse all

Offences without all the flows or events

  • 1.  Offences without all the flows or events

    Posted 08/05/20 07:01 PM

    Hi i have QNI and Qradar 7.4 i am seeing offence without all the flows or events in them.

    For example is get a host port scan offence and when I investigate it has the following in the offense flow records

    Source IP 1.2.3.4

    Source port 53

    Dest ip a.b.c.d (THis is the local ip)

    Dest port (34565)

    Now this looks like DNS requests, just reversed when i carry out a search looking for all the above in the network activity tab, but with out the "Offense is ......" filter i can see both sides of the conversation, DNS request to port 53 from the source followed by the responses(The response is what i see in the offense).

    Why does the offence filter only see half the conversation when the entire conversation is in the network activity tab ?

    It appears that because the custom rules engine only appears to be aware of (or taking into consideration) half the converation it then sees the DNS responses as a scan of the sourse ip addresses

    THis causes multiple false positives.

    Has anyone else seen this, its more common with flows but have seen similar with events.



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: Offences without all the flows or events

    Posted 08/17/20 12:53 PM