# How to handle network.direction:unknown?

**URL:** <https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143>\
**Category:** SIEM\
**Created:** [April 2, 2020, 12:15am UTC](https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143 "2020-04-02T00:15:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [April 2, 2020, 12:15am UTC](https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143/1 "2020-04-02T00:15:44Z")

</div>

I'm getting detections where the network.direction is "unknown". Upon investigation this is just the source port from a vulnerability scanner (Detectify) :

```auto
  "destination": {
    "bytes": 4128,
    "ip": "52.17.98.131",
    "port": 5802,
    "packets": 33},
  "source": {
    "port": 80,
    "packets": 19,
    "bytes": 7590,
    "ip": "10.128.0.2"
  }

```

Obviously this looks like a false positive - if the engine isn't sure whether the source is destination or vice-versa there are going to be a lot of false positives. Is it correct to assume this is being alerted out of caution so that a human can investigate?

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 4, 2020, 4:25pm UTC](https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143/2 "2020-04-04T16:25:43Z")

</div>

> Is it correct to assume this is being alerted out of caution so that a human can investigate?

I'd have to ask @Craig_Chamberlain if that is for sure the reasoning, but I can say for sure that if you do not want to see detections for direction unknown you can copy -\> and then edit the rule to make changes to remove that case or even make it more strict to only pay attention to that use case when it's a particular IP range or set of hosts (for example).

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 4, 2020, 4:29pm UTC](https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143/3 "2020-04-04T16:29:14Z")

</div>

This conversation might be useful:

> [@SIEM detections false positive](https://discuss.elastic.co/t/siem-detections-false-positive/219287/5):
>
> Hi, yes, you can remove the network.direction test when using these on endpoint data. This field is more useful when it has been populated by a Suricata, Snort or Zeek network list. It is not a super reliable layer three context in endpoint pipelines because these typically have no network lists or maps. The rule needs more branching logic to confine evaluation of the network.direction field to appropriate event types. Such a modified version of the search for endpoint events would look like t…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2020, 4:29pm UTC](https://discuss.elastic.co/t/how-to-handle-network-direction-unknown/226143/4 "2020-05-02T16:29:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
