To ensure that your NetFlow
configuration is working correctly, you must validate your QRadar
NetFlow data.
About this task
Configure NetFlow to send data to the
nearest QRadar Flow Collector
or QRadar
Flow
Processor appliance.
By default, QRadar listens
on the management interface for NetFlow
traffic on port 2055 (UDP). If you need more NetFlow ports, you can assign more ports.
Procedure
-
Click the Network Activity tab.
-
From the Network Activity toolbar, click .
-
In the Search Parameters pane, add a flow source search filter.
-
From the first list, select Flow Source.
-
From the third list, select your NetFlow router's name or IP address.
If your NetFlow router is
not displayed in the third list, QRadar might not detect traffic
from that router.
-
Click Add Filter.
-
In the Search Parameters pane, add a protocol search filter.
-
From the first list, select Protocol.
-
From the third list, select TCP.
-
Click Add Filter.
-
Click Filter.
-
Locate the Source Bytes and Destination Bytes
columns to verify data collection.
If either column displays many results that have zero bytes, your configuration might be
incomplete. You must verify your NetFlow
configuration.