Mapping Flows to Applications in QRadar, Part 1

preview_player
Показать описание

Link to Box Folder with files and pdf with links to other videos:
ERRATA: Where I said 1500 (fifteen hundred) I meant to say 15000 (fifteen thousand)
Рекомендации по теме
Комментарии
Автор

Thanks
I have passed your comment to one of the developers, let us see what he says.

jbravovideos
Автор

Hola, Jose.
Thanks for the series. this is something I have been working on recently. Quick question, the docs suggest the the apps.conf entries should be in alphabetical order, yet you put the new entry at the top. Any issues with that? It doesn't look like it causes any problems. I would prefer to put my new entries at the top, where I can track the changes better.
And an observation. Regarding the link for the long list of default Application Types, it would be very helpful to also be able to see the actual port definition for each line, not just the ID. We use a LOT of custom ports, but I can't tell if there will be a collision between my new add and one of the default listings, without the additional details.
Thanks again for the great series of videos you provide!
Saludos!

markg.
Автор

Hi Jose,
I have a question about Qradar on the Cloud. can you please send me your contact to discuss it in details?

worooddabbas