Cisco Cisco Firepower Management Center 4000

Page of 1844
 
39-50
FireSIGHT System User Guide
 
Chapter 39      Configuring Correlation Policies and Rules 
  Working with Correlation Events
The Policy Management page appears.
Step 2
Click the delete icon (
) next to the policy you want to delete.
The policy is deleted.
Working with Correlation Events
License: 
Any
When a correlation rule within an active correlation policy triggers, the Defense Center generates a 
correlation event and logs it to the database. For information on configuring the number of correlation 
events saved in the database, see 
.
Note
When a compliance white list within an active correlation policy triggers, the Defense Center generates 
a white list event. For more information, see 
For more information, see the following sections:
  •
  •
  •
Viewing Correlation Events
License: 
Any
You can view a table of correlation events, then manipulate the event view depending on the information 
you are looking for.
The page you see when you access correlation events differs depending on the workflow you use. You 
can use the predefined workflow, which includes the table view of correlation events. You can also create 
a custom workflow that displays only the information that matches your specific needs. For information 
on creating a custom workflow, see 
.
The following table describes some of the specific actions you can perform on an correlation events 
workflow page. 
Table 39-16
Correlation Event Actions 
To...
You can...
view the host profile for an IP 
address
click the host profile icon that appears next to the IP address.
view user profile information
click the user icon (
) that appears next to the user identity. For more information, 
see 
sort and constrain events on the 
current workflow page
find more information in 
navigate within the current workflow 
page
find more information in