Configuring the Flow Collector format
Flow collectors can export data to flow processors in either TLV (type-length-value) or Payload format.
The TLV format stores the content metadata properties in the flow record, and can be searched without extra configuration in QRadar®.
The payload format stores the content metadata properties in the payload field of the flow record. To run searches on the data, you must use custom properties to extract the data from the payload.
Before you begin
Before you configure the format that the Flow Collector uses, ensure that you complete the following tasks:
- Install a QRadar Console with a QRadar Network Insights appliance attached as a managed host.
- Perform a full deployment after you attach the IBM® QRadar Network Insights appliance as a managed host.
Log in to QRadar:
The default user name is admin. The password is the password of the root user account.
- On the navigation menu ( ), click Admin.
- In the navigation pane, click System Settings.
Click the QFlow Settings menu, and in the IPFIX Additional
Field Encoding field, choose the format.
Table 1. QFlow format options Flow Collector format Description TLV Default setting for the flow collector format.
Must be used when there is a QRadar Network Insights appliance in the environment.
QRadar Network Insights V7.3.0 or later supports only TLV for content flows.
Can be used when there is no QRadar Network Insights appliance in the environment.
Payload Can be used when there is no QRadar Network Insights appliance in the environment.
- Click Save.
From the menu bar on the Admin tab, click Deploy Full
Configuration and confirm your changes.
Warning: When you deploy the full configuration, QRadar services are restarted. During this time, events and flows are not collected, and offenses are not generated.
- Refresh your web browser.