Topic
  • No replies
dwight s (IBM)
dwight s (IBM)
3 Posts

Pinned topic QRadar Flow FAQ

‏2016-03-28T17:13:27Z |

 

This post haas been moved to https://developer.ibm.com/qradar/2018/01/09/qradar-flow-faq/

 

==== 

What is a flow?

In QRadar's terms, a flow represents a report, generated/updated minute by minute, of a session between two endpoints connected to network.  Rather than the concept of bytes & packets, which flow from 1 host, to the other, and back, the concept of a flow represents the entire session, a count of the bytes and packets generated in the communication, the flags, protocol used, and the time that it is active.    

 

[......]