Hello,
thanks for your explanation.
We already have a flow source configured on the target machine, it is still not so clear to us what our customer wants to achieve with this..we will be discussing the topic in detail with him.
We have not deployed a QNI or QIF but only an event\flow processor, so I suppose the source .pcap file should already contain netflow\sFlow traffic because this is the only type of traffic that a flow processor can ingest.
B Regards,
Davide
------------------------------
Davide Salardi
------------------------------
Original Message:
Sent: Wed November 29, 2023 05:48 AM
From: Comghall Morgan
Subject: Import pcap files into Qradar
Hello,
My understanding was that tis was to ingest for a production enviornment.
As Karl has stated and thank you Karl, you can utilise tcpreplay to ingest pcaps as a test or within test environments.
Though my issue was that the tcpreplay rpm is not installed by deafult on a QRadar sysyem and why I stated the only supported method is using the additonal appliance for a production environnment.
Though if this is for a test or proof of concept then yes I see this as a valid method.
Regards,
------------------------------
Comghall Morgan
QRadar Support Architect
IBM
Original Message:
Sent: Tue November 28, 2023 11:34 AM
From: Karl Jaeger
Subject: Import pcap files into Qradar
Davide,
ingesting pcap is very easy and part of our bootcamp. No extra appliance needed at all.
You may have to install tcpreplay on your testmachine. An AIO may do the trick, just configure a monitor flow source. Here is a sample output from one of our labs:
![](https://dw1.s81c.com//IMWUC/MessageImages/1d2767b1e4e244ca9013d688f471aed9.png)
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
Original Message:
Sent: Fri November 24, 2023 11:58 AM
From: Davide Salardi
Subject: Import pcap files into Qradar
Hello,
one of our customers asked if it is possible to ingest traffic data from a pcap file into Qradar.
We have an event\flow processor so he is expecting to see this data in the flow activity; is it possible to import this kind of data into Qradar without Network Packet Capture or Qradar Incident Forensics? We are running Qradar 7.5.0.3 (soon we will update to 7.5.0.7).
B Regards,
Davide
------------------------------
Davide Salardi
------------------------------