Reviewing Your Network Hierarchy
A well-defined and maintained network hierarchy can help prevent the generation of false positive offenses. The network hierarchy is used to define which IP addresses and subnets are part of your network. Ensure that all internal address spaces, both routable and non-routable, are defined within your QRadar network hierarchy. QRadar can then distinguish your local network from the remote network. Event and flow context is based on whether the source and destination IPs are local or remote. Event and flow context, and data from your network hierarchy are used in rule tests.