IBM Support

QRadar: Flows missing from Network Activity

Troubleshooting


Problem

All routers are configured to send network traffic to QRadar, but seeing a fraction of expected flows in Network Activity.

Symptom

A good sign there are missing flows, is that the system is nowhere near the licensed Flow capacity and all flows are configured.
  1. From the web UI Console, go to Admin > System and License Management.
  2. View the Flow Rate Limit, and make a note of it.
    NOTE: The first number is the license limit per minute and the second number is the hardware limit.
  3. Go to Network Activity.
  4. Process a one minute search.
  5. Expand Current Statistics.
  6. The Total Results is your current rate.
  7. If the value from step 6 is less than 30% of the value from step 2, then your flows might not be configured correctly.

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwsuAAA","label":"Flow Source"}],"ARM Case Number":"TS001173344","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.3.3;7.4.3;7.5.0"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
25 August 2022

UID

ibm16586970