If you want to correlate network traffic between multiple ESAs, you can enable cross-site correlation and add more than one ESA to a deployment. When you deploy rules in a cross-site correlation deployment, a central ESA service runs the rule set on forwarded events from other ESA services. Multiple ESA services cover a larger network footprint and, therefore, provide greater coverage for threat detection.
By default cross-site correlation is not enabled. To enable cross-site correlation, you must consult with RSA Professional Services to take part in the Cross-Site Correlation Field Trial Program.