Communicating with is based on communication over a number of scan runs. The communication will be aged and if not seen for a period of time removed.
Observed communication is what was seen on the last scan.
So can we conclude that basic algorithm/command to check Communicating Hosts is same for both. The only difference is that "Communicating Hosts" field has historic data as well as, whereas "Observed Communication" just has last scan data.
If this is true, request you to please share the command/algorithm which decides the value for these fields.
No - you cannot conclude that.
Request you to please let us know that what is difference between the 2 in terms of discovery. Aren't the data is gathered from "netstat" or some other similar command in both the cases?