McAfee SIEM - How to use the New Correlation Rules Details of version 9.4
ESM comes with a number of correlation rules in the category of "policy." These roll up to Normalization rules like "FTP Policy" and "Gaming Policy." I'm curious to know under what kind of events would end up with these normalization IDs. I searched on a few of them and found no events. Are these designed specifically to work with other McAfee products?