McAfee SIEM - How to use the New Correlation Rules Details of version 9.4
ESM comes with a number of correlation rules in the category of "policy." These roll up to Normalization rules like "FTP Policy" and "Gaming Policy." I'm curious to know under what kind of events would end up with these normalization IDs. I searched on a few of them and found no events. Are these designed specifically to work with other McAfee products?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.