для Cisco Cisco Firepower Management Center 4000

Скачать
Страница из 1844
 
39-4
FireSIGHT System User Guide
 
Chapter 39      Configuring Correlation Policies and Rules 
  Creating Rules for Correlation Policies
When you create either correlation rule trigger criteria, host profile qualifications, user qualifications, 
or connection trackers, the syntax varies but the mechanics remain consistent. For more information, See 
.
To create a correlation rule:
Access: 
Admin/Discovery Admin
Step 1
Select 
Policies > Correlation
,
 
then select the 
Rule Management
 tab.
The Rule Management page appears.
Step 2
Click 
Create Rule
.
The Create Rule page appears.
Step 3
Provide basic rule information, such as the rule name, description, and group.
See 
.
Step 4
Specify the basic criteria on which you want the rule to trigger.
See 
.
Step 5
Optionally, add a host profile qualification to the rule.
See 
.
Step 6
Optionally, add a connection tracker to the rule.
See 
.
Step 7
Optionally, add a user qualification to the rule.
See 
.
Step 8
Optionally, add an inactive period or snooze period (or both) to the rule.
See 
.
Step 9
Click 
Save Rule
.
The rule is saved. You can now use the rule within correlation policies or within other correlation rules 
that trigger on the same event type.
trigger a correlation rule on a connection event with URL data, or build 
a connection tracker using URL data
Note that neither Series 2 devices nor the DC500 Defense Center 
support URL filtering by category or reputation, and Series 2 devices do 
not support URL filtering by literal URL or URL group.
URL Filtering
trigger a correlation rule on a malware event based on network-based 
malware data or retrospective network-based malware data
Note that neither Series 2 devices nor the DC500 Defense Center 
support network-based malware protection.
Malware
Table 39-1
License Requirements for Building Correlation Rules (continued)
To...
You need this license...