I understand you do not know, how exactly enable Correlation Engine and how to prepare own correlation rules?
I yes, you should begin from adding correlation engine(s). I see, you have not dedicated ACE machine, so you have to use the ERC to correlate events. You can add Correlation Engine to all ERCs or chose one of the ERC - it depends to the performance of the ERCs, ERC's utilization and required scopes of events, that should be correlated. Enabling of Correlation Engine on the ERC will decrease its performance (30-50%).
How to enable Correlation Engine: you should to add new data source - McAfee\Correlation Engine and enable or disable option in thet data source "Correlate only events from this Receiver", as you want.
How to learn, how to build the correlation rules? - Please go to Policy, Correlation, and then copy and paste one of standard correlation rule. Then you can open this copied rule and see, how it is configured.
Here you can read an articles, regarding correlation: