Go to Configuration > Threat Intelligence > Policy.
Enter a name in the Policy Configuration page.
Configure the conditions that you want the events to match. See Create Policy Conditions for instructions on each field.
Configure what you want to do with the events that have match the conditions. See Create Policy Consequences for instructions on each field.
Click Update Policy.
Click Reload Policies.