• No replies
dwight s (IBM)
dwight s (IBM)
3 Posts

Pinned topic QRadar Flow FAQ

‏2016-03-28T17:13:27Z |


This post haas been moved to



What is a flow?

In QRadar's terms, a flow represents a report, generated/updated minute by minute, of a session between two endpoints connected to network.  Rather than the concept of bytes & packets, which flow from 1 host, to the other, and back, the concept of a flow represents the entire session, a count of the bytes and packets generated in the communication, the flags, protocol used, and the time that it is active.