cms peer <peer_hostname> interaction dist-correlation enable

Prev Next

Enables the Central Management System Peer Distributed Correlation feature on each Central Management System peer. Central Management System Peer Distributed Correlation matches events detected by an appliance with events that are received from a Central Management System peer in another network. Central Management System Peer Distributed Correlation allows two Central Management System networks to share information. Information about a malicious URL found in one Central Management System network is shared with other Central Management System networks.

A typical correlation matches malicious URL events detected by the Network Security appliance with email events detected by the EX Series appliance. URL events and email events are linked to each other in the Web UI after they have been matched. For example, when a malicious URL is detected by the Network Security appliance, the URL is correlated by the Central Management System appliance with the originating email on the EX Series appliance. For details about Network Security and EX Series event correlation, refer to the Central Management System Administration Guide.

Syntax

[no] cms peer <peer_hostname> interaction dist-correlation enable

Parameters

no

Use the no form of this command to disable the Central Management System Peer Distributed Correlation feature on a Central Management System peer.

Example

The following example enables Central Management System Peer Distributed Correlation on a specified Central Management System peer.

hostname (config) # cms peer IE-CM4400 interaction dist-correlation enable

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.8