The most common issue is that you need to manually enable your new rule on the Correlation Engine policy. Enabling it on the "Default" policy won't do the trick...you need to ensure it's turned on in the end device policy.
If you select your Correlation Engine in the device tree, then click the Policy Ediitor icon in the top left (above the device tree) you'll be taken directly to the proper policy for verification.
Thank you, Scott, that seems to have done the trick. Do you know of any documents or resources that might have more examples of correlation rules or that might explain them in a bit more detail? Thanks!
Congratulations. You are now a McAfee ESM grizzled veteran. This one bites everyone the first time they creaete a new rule. The best resource for correlation examples is in the product itself. Each correlation rule can be opened in the policy editor (double-click) and you can review the complete logic and documentation there.