Central Management System Peer Distributed Correlation

Prev Next

Central Management System Peer Distributed Correlation matches events detected by an appliance with events that are received from a CM peer in another network. CM Peer Distributed Correlation allows two Central Management System networks to share information. Information about a malicious URL found in one Central Management System network is shared with other Central Management System networks.

A typical correlation matches malicious URL events detected by the Network Security appliance with email events detected by the Email Security — Server appliance. URL events and email events are linked to each other in the Web UI after they have been matched. For example, when a malicious URL is detected by the Network Security appliance, the URL is correlated by the Central Management System appliance with the originating email on the Email Security — Server appliance. For details about Network Security and Email Security — Server event correlation, see and Event Correlation .

Alert notifications from a Central Management System peer are missing the missing product and version attributes in the <alert> tag of the notification. When the malware-object notification setting is enabled on the Central Management System appliance, Distributed Cross- Central Management System alert notifications that contain information about the sender, intended recipients, and malicious URL are sent from the Central Management System appliance or managed appliances. For details about how to manage the distribution of alert notifications for the Central Management System appliance and managed appliances, see Managing the Distribution of Alert Notifications .

Prerequisites
  • Admin access to the Central Management System appliance.

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud.

  • Network connectivity over SSH (port 22) and HTTPS (port 443) must be allowed on each of the participating Central Management System appliances.

  • CM Peer Service must be enabled on each of the participating Central Management System appliances.

  • Authentication tokens must be exchanged for communication between the CM peers.

  • The malware-object notification setting must be enabled on all the CM peers. For details about how to configure event notifications, see Event Notifications .