QRadar: What is the meaning of the letter (C) diplayed on flow data for the Source Bytes or Destination Bytes Column?

Question & Answer


A flow is a record of the communication between two machines. In these flows, they have a start and end time, or a life of multiple seconds. For example, when you connect to a website, the communication includes HTML files, images, flash files, or other and might take some time to transfer the data.


In this case, the (C) letter indicates that the flow contains a content capture from the first 64 or 96 bytes of the flow payload.

Modified date:

Modified date:
31 October 2022