When the Central Management System appliance manages both Network Security appliances and Email Security — Server appliances, malicious Web events detected by the Network Security appliances are correlated with email events detected by the Email Security — Server appliances, and malicious email events detected by the Email Security — Server appliances are correlated with Web events detected by the Network Security appliances.
Note
For information about allowing two Central Management System networks to share information about malicious events, see CM peer distributed correlation.
Correlated events are displayed with the following icons in the Web UI:
Web Correlation — This icon in an email alert indicates that the alert is correlated with a Web alert. It is typically in the URL column, depending on the tab selected in Alerts > Email > eAlerts.
Email Correlation — This icon in a Web alert indicates that the alert is correlated with an email alert. It is in the Total column or the Alert Type column, depending on the tab selected in Alerts > NX > Alerts.
Correlated events are displayed with the following badges:
Correlated NX Alert — This badge in an email alert indicates that the alert is correlated with a Web alert. It is shown in the Badges column in the Alerts > Email > eAlerts page. You can select it as a filter to find correlated Network Security events.
Correlated EX Alert — This badge in a Web alert indicates that the alert is correlated with an email alert. It is shown in the Badges column in Alerts > NX > Alerts page. You can select it as a filter to find correlated Email Security — Server events.