<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Correlation Events in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/correlation-events/m-p/3864743#M17631</link>
    <description>&lt;P&gt;Is it possible to setup a correlation event that will temporarily blacklist an IP address based on receiving a # of intrusion events against a destination IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is there another way in the FP to do something like this?&amp;nbsp; The appliance is sitting inline.&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2019 21:02:32 GMT</pubDate>
    <dc:creator>rsharp001</dc:creator>
    <dc:date>2019-05-29T21:02:32Z</dc:date>
    <item>
      <title>Correlation Events</title>
      <link>https://community.cisco.com/t5/network-security/correlation-events/m-p/3864743#M17631</link>
      <description>&lt;P&gt;Is it possible to setup a correlation event that will temporarily blacklist an IP address based on receiving a # of intrusion events against a destination IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or is there another way in the FP to do something like this?&amp;nbsp; The appliance is sitting inline.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 21:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/correlation-events/m-p/3864743#M17631</guid>
      <dc:creator>rsharp001</dc:creator>
      <dc:date>2019-05-29T21:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: Correlation Events</title>
      <link>https://community.cisco.com/t5/network-security/correlation-events/m-p/3865255#M17632</link>
      <description>&lt;P&gt;Adding more information:&lt;/P&gt;&lt;P&gt;- This is a physical appliance, not an ASA running FTD, running 6.3.0.&amp;nbsp; It is inline.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What I'm wanting to do is have the box auto blacklist and remove from that list(if possible from correlation events) any IPs that are blocked multiple times over a period of time.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 16:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/correlation-events/m-p/3865255#M17632</guid>
      <dc:creator>rsharp001</dc:creator>
      <dc:date>2019-05-30T16:24:55Z</dc:date>
    </item>
  </channel>
</rss>

