Configuring the Flow Collector format
Flow collectors can export data to flow processors in either TLV (type-length-value) or Payload format.
The TLV format stores the content metadata properties in the flow record, and can be searched without extra configuration in QRadar®.
The payload format stores the content metadata properties in the payload field of the flow record. To run searches on the data, you must use custom properties to extract the data from the payload.
Before you begin
Before you configure the format that the Flow Collector uses, ensure that you complete the following tasks:
Install a QRadar Console with a QRadar Network Insights appliance attached as a managed host.
Perform a full deployment after you attach the IBM® QRadar Network Insights appliance as a managed host.
Important: Content extension v1.3.0 introduced support for TLV fields, which supersedes
earlier content extensions that were based on custom properties. If you are using content extension
v1.3.0 or later, you must set the flow collector format to TLV; otherwise the rules in the content
pack don't work.