IBM Security QRadar

 View Only
Expand all | Collapse all

why is the offending IP from flows not displaying in Offence Type field

  • 1.  why is the offending IP from flows not displaying in Offence Type field

    Posted 30 days ago

    Rules looking for IPs in reference sets, i.e. malicious IPs/BotNet etc. sometimes populate the first IP in a flow rather then the actual offending IP down further in the flow records, the Offense Type field will not get populated with the actual offending IP?



    ------------------------------
    Thomas Fillmore
    ------------------------------


  • 2.  RE: why is the offending IP from flows not displaying in Offence Type field

    Posted 29 days ago

    Is it a superflow record? In such case you could have one "leading" IP and a number of others below it in the same field in the flow record. 



    ------------------------------
    Dusan VIDOVIC
    ------------------------------