Cisco Cisco Firepower Management Center 2000

Seite von 1844
 
39-35
FireSIGHT System User Guide
 
Chapter 39      Configuring Correlation Policies and Rules
  Creating Rules for Correlation Policies
To build the host profile qualification in the example above:
Access: 
Admin/Discovery Admin
Step 1
Build a correlation rule that triggers on an discovery event.
For more information, see 
.
Step 2
On the Create Rule page, click 
Add Host Profile Qualification
.
The Host Profile Qualification section appears.
Step 3
Under 
Host Profile Qualification
, in the first condition, specify the host whose host profile you want to use 
to constrain your correlation rule.
Because this host profile qualification is part of a correlation rule based on an discovery event, the only 
available category is 
Host
.
Step 4
Begin specifying the details of the operating system of the host by choosing the 
Operating System
 
category.
Three subcategories appear: 
OS Vendor
OS Name
, and 
OS Version
Step 5
To specify that the host can be running any version of Microsoft Windows, use the same operator for all 
three subcategories: 
is
.
Step 6
Finally, specify the values for the subcategories.
Select 
Microsoft
 as the value for 
OS Vendor
Windows
 as the value for 
OS Name
, and leave 
any
 as the value 
for 
OS Version
.
Note that the categories you can choose from depend on whether you are building correlation rule 
triggers, a host profile qualification, a connection tracker, or a user qualification. Within correlation rule 
triggers, the categories further depend on what kind of event is the basis for your correlation rule. 
In addition, a condition’s available operators depend on the category you choose. Finally, the syntax you 
can use to specify a condition’s value depends on the category and operator. Sometimes you must type 
the value in a text field. Other times, you can pick a value from a drop-down list.