Flow direction
The QFlow process analyzes each flow to determine the direction of the network communication.
In some cases, the flow traffic is bidirectional where the client communicates with the server and the server responds to the client. In this scenario, both the client and the server operate as though they are the source and the other is the destination. To address this, QRadar® sets the flow direction to ensure that the source and destination devices are reported consistently throughout the entire communication session. The flow data is normalized and all flows follow the same convention, where Destination always refers to the server, and Source always refers to the client.
- If the destination port does not match the list of common destination ports, reverse the
flow direction if either of the following conditions are true:
- The source port is a common destination port.
- The source port is less than 1024 and the destination port is greater than 1024.
- If the destination port does match the list of common destination ports, reverse the flow
direction if both of the following conditions are true:
- The source port is a common destination port.
- The source port is less than 1024 and the destination port is greater than 1024.
If the flow does not match any of the flow direction criteria, QRadar uses the flow arrival time to determine the flow direction.
Example: Flow direction reversed by QRadar
On the Flow Information window, you can see the flow direction algorithm that was used to set the direction.