cancel
Showing results for 
Search instead for 
Did you mean: 

Correlation Engine

Hi,

the filter field "Contex" in the rule on the "Correlation Engine", what does it mean? How does it mean the Context's values: "internal to external", "internal to internal" and so on... They depend on the HOME_NET/EXTERNAL_NET variables?

Thank you.

Rgds,

6 Replies
Highlighted

Re: Correlation Engine

Yes, "context" depends on the Homenet configuration, however, not the one in the Policy Editor. 

There are 2 places to configure "home net".  There is a variable in the policy editor, which is used by legacy Nitro IPS rules, and can be safely ignored by most customers.  The "real" Homenet is found under Asset Manager -> Network Discovery -> Homenet.

Any IP addresses that fall into ranges specified here are considered "internal".   This is used to drive the context as seen in many correlation rules. 

Scott 

Re: Correlation Engine

Hi Scott,

thank you.

Rgds,

jp87
Level 9
Report Inappropriate Content
Message 4 of 7

Re: Correlation Engine

Hi Scott,

has this been changed in more recent versions(e.g 9.5.0)? I can't see the Homenet under the search path thar you mentioned? Is the new path Asset Manager -> Network Discovery -> Local network?

/JP

Re: Correlation Engine

Yes, "Homenet" was renamed "Local Networks" a couple versions back, to eliminate the confusion between the two different ones.

Scott

Re: Correlation Engine

Hi Scott,

If running the ESM with multiple separate customers, each having different local networks, is it possible to still use "context" within correlation rules?

Cheers

Re: Correlation Engine

With the existing pre-built rules, no.  In a service provider environment like you're describing, it would be more common to set up separate context variables for each customer, and implement unique rules (typically on separate correlation engines) for each customer referencing the relevant variables, watchlists, etc.

Scott

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community