- Create a scheduled Forensics and Response job
- Launch a Forensics and Response action from an alarm or event
- Create a Forensics and Response orchestration rule
- Run an action from the BlueApp for LevelBlue Forensics and Response page
- In USM Anywhere, go to Data Sources > BlueApps.
- Click the Available Apps tab.
- Search for the BlueApp, and then click the tile.
- Click the Actions tab.
- Locate the Launch Query action and click Run. This opens the Select Action dialog box.
- If needed, select the sensor on which the BlueApp is enabled to display more options.
- Specify the asset that you want to use as a target for the action. You can enter the name or IP address of the asset in the field to display matching items that you can select. Or you can click Browse Assets to open the Select Asset dialog box and browse the asset list to make your selection.
-
In the Query field, enter the function to perform.
- (Optional) If the function requires parameters, use the Parameter fields to enter the values in order.