IC SunsetThe developerWorks Connections platform will be sunset on December 31, 2019. On January 1, 2020, this forum will no longer be available. More details available on our FAQ.
  • No replies
dwight s (IBM)
dwight s (IBM)
3 Posts

Pinned topic QRadar Flow FAQ

‏2016-03-28T17:13:27Z |


This post haas been moved to https://developer.ibm.com/qradar/2018/01/09/qradar-flow-faq/



What is a flow?

In QRadar's terms, a flow represents a report, generated/updated minute by minute, of a session between two endpoints connected to network.  Rather than the concept of bytes & packets, which flow from 1 host, to the other, and back, the concept of a flow represents the entire session, a count of the bytes and packets generated in the communication, the flags, protocol used, and the time that it is active.