IBM Security QRadar

 View Only
Expand all | Collapse all

why is the offending IP from flows not displaying in Offence Type field

  • 1.  why is the offending IP from flows not displaying in Offence Type field

    Posted Wed April 17, 2024 01:58 PM

    Rules looking for IPs in reference sets, i.e. malicious IPs/BotNet etc. sometimes populate the first IP in a flow rather then the actual offending IP down further in the flow records, the Offense Type field will not get populated with the actual offending IP?



    ------------------------------
    Thomas Fillmore
    ------------------------------


  • 2.  RE: why is the offending IP from flows not displaying in Offence Type field

    Posted Thu April 18, 2024 04:56 AM

    Is it a superflow record? In such case you could have one "leading" IP and a number of others below it in the same field in the flow record. 



    ------------------------------
    Dusan VIDOVIC
    ------------------------------