Updating the network baseline manually
The network baseline process is automatically triggered when you configure the app with an authorized service token. After the initial baseline is created, the app updates the baseline at regular intervals to keep up to date with new traffic that is found on your network.
Follow these steps to view the status of the current network baseline or to restart the process to re-create it.
Before you begin
To successfully create the network baseline, your IBM® QRadar deployment must have at least one week of continuous flow data. When your deployment has lots of flow records, the app creates a baseline that is more representative of the types of flow traffic that is typically observed on your network.
- In QRadar, click the Network Threat Analytics tab.
- Click the icon to open the
The status of the baseline creation process is shown in the Network baseline section.
- To re-create the network baseline, click Update baseline.