cancel
Showing results for 
Search instead for 
Did you mean: 
jon286
Level 9
Report Inappropriate Content
Message 1 of 4

ESM virtual combo box - official line on no support for correlation?

Can I find an official line that you do not support the use of correlation running on the combo VM itself written/confirmed somewhere, i.e. in the product documentation or knowledgebase?

This was mentioned in during a remote session with a McAfee engineer to fix an issue, though I didn't think to ask for anything in an email before the ticket was closed.

3 Replies
sssyyy
Level 12
Report Inappropriate Content
Message 2 of 4

Re: ESM virtual combo box - official line on no support for correlation?

Why can't you add a correlation engine on the receiver device?

jon286
Level 9
Report Inappropriate Content
Message 3 of 4

Re: ESM virtual combo box - official line on no support for correlation?

Adding and running correlation engine on the receiver isn't the issue, it's when there's a fault it causes serious problems (it tries to keep correlating and can't cope leading to massive backlogs etc.).

We have effectively been told we shouldn't be running correlation on a combo VM.

sssyyy
Level 12
Report Inappropriate Content
Message 4 of 4

Re: ESM virtual combo box - official line on no support for correlation?

OH really? We've got a GEN3 combo box appliance, it commits suicide when too much correlation rules are enabled.