Hi i have QNI and Qradar 7.4 i am seeing offence without all the flows or events in them.
For example is get a host port scan offence and when I investigate it has the following in the offense flow records
Source IP 1.2.3.4
Source port 53
Dest ip a.b.c.d (THis is the local ip)
Dest port (34565)
Now this looks like DNS requests, just reversed when i carry out a search looking for all the above in the network activity tab, but with out the "Offense is ......" filter i can see both sides of the conversation, DNS request to port 53 from the source followed by the responses(The response is what i see in the offense).
Why does the offence filter only see half the conversation when the entire conversation is in the network activity tab ?
It appears that because the custom rules engine only appears to be aware of (or taking into consideration) half the converation it then sees the DNS responses as a scan of the sourse ip addresses
THis causes multiple false positives.
Has anyone else seen this, its more common with flows but have seen similar with events.
#QRadar#Support#SupportMigration