Cisco Cisco Firepower Management Center 2000
39-35
FireSIGHT System User Guide
Chapter 39 Configuring Correlation Policies and Rules
Creating Rules for Correlation Policies
To build the host profile qualification in the example above:
Access:
Admin/Discovery Admin
Step 1
Build a correlation rule that triggers on an discovery event.
For more information, see
.
Step 2
On the Create Rule page, click
Add Host Profile Qualification
.
The Host Profile Qualification section appears.
Step 3
Under
Host Profile Qualification
, in the first condition, specify the host whose host profile you want to use
to constrain your correlation rule.
Because this host profile qualification is part of a correlation rule based on an discovery event, the only
available category is
available category is
Host
.
Step 4
Begin specifying the details of the operating system of the host by choosing the
Operating System
category.
Three subcategories appear:
OS Vendor
,
OS Name
, and
OS Version
.
Step 5
To specify that the host can be running any version of Microsoft Windows, use the same operator for all
three subcategories:
three subcategories:
is
.
Step 6
Finally, specify the values for the subcategories.
Select
Microsoft
as the value for
OS Vendor
,
Windows
as the value for
OS Name
, and leave
any
as the value
for
OS Version
.
Note that the categories you can choose from depend on whether you are building correlation rule
triggers, a host profile qualification, a connection tracker, or a user qualification. Within correlation rule
triggers, the categories further depend on what kind of event is the basis for your correlation rule.
triggers, a host profile qualification, a connection tracker, or a user qualification. Within correlation rule
triggers, the categories further depend on what kind of event is the basis for your correlation rule.
In addition, a condition’s available operators depend on the category you choose. Finally, the syntax you
can use to specify a condition’s value depends on the category and operator. Sometimes you must type
the value in a text field. Other times, you can pick a value from a drop-down list.
can use to specify a condition’s value depends on the category and operator. Sometimes you must type
the value in a text field. Other times, you can pick a value from a drop-down list.