Follow these steps to verify that the QRadar® Network
Insights appliance is sending IPFIX
records to the flow collector or flow processor in your deployment.
Procedure
- Verify that the flow source is added and enabled in QRadar.
- Log in to the QRadar console as an admin
user.
- On the Admin tab, click
.
- Verify the flow source settings and ensure that the Enabled
column is set to true.
- Repeat the procedure for each QRadar Network
Insights managed host.
- If you changed the flow source configurations, on the Admin
tab, click Deploy Changes.
- Verify that the flows are being received.
- Use SSH to log in to the QRadar Console.
- Type the following command:
tailf /var/log/qradar.log | grep qflow
Messages like this one indicate that the
Flow Processor is not receiving any flows
from
QRadar Network
Insights:
IPFIX Flow Source Stats for <my_dtls_flow_source_name>: received and processed 0 packets
Messages like this one indicate that flows are being
received:
IPFIX Flow Source Stats for <my_dtls_flow_source_name>: received and processed 12345 packets
- If flows are not being received, check that the QRadar Network
Insights managed host is configured
correctly.
- On the Admin tab, click System and License
Management.
- Select the QRadar Network
Insights
managed host that is not sending flow data.
- Click .
- Select the flow processor that you want your QRadar Network
Insights appliance to send flow data
to, and click Save.
- Configure the QRadar Network
Insights managed host, and then click Save.
- On the Admin tab, click
.
- Repeat the previous steps to verify that the flows are being received.
What to do next
On the QRadar
Console, click the
Network Activity tab to see the flow records.