USM Anywhere has a modular and scalable two-tier architecture.

USM Anywhere Architecture Diagram

Tier 1 — USM Anywhere Sensors and Agents

USM Anywhere deploy natively into each environment and help you gain visibility into all of your on-premises and environments. Sensors collect and normalize logs, monitor networks, and collect information about the environments and assets deployed in your hybrid environments. Sensors are a key component of the USM Anywhere solution. They operate either on-premises or in the cloud, performing the following tasks:
  • Discovering your
  • Scanning assets for
  • packets on your networks and collecting data
  • Collecting log data and it before securely sending it to USM Anywhere
USM Anywhere Agents deploy on your network host and provide the following:
  • Endpoint detection and response
  • Network asset monitoring
  • File integrity monitoring (FIM)
  • Log collection

Tier 2 — USM Anywhere Cloud

The USM Anywhere cloud instance is deployed in one of the Amazon Web Services (AWS) endpoint regions based on your location. The following table lists the available AWS regions. AWS Regions where USM Anywhere Instance Is Available
CodeName
ap-northeast-1Asia Pacific (Tokyo)
ap-south-1Asia Pacific (Mumbai)
ap-southeast-1Asia Pacific (Singapore)
ap-southeast-2Asia Pacific (Sydney)
ca-central-1Canada (Central)
eu-central-1Europe (Frankfurt)
eu-west-1Europe (Ireland)
eu-west-2Europe (London)
me-central-1Middle East (UAE)
sa-east-1South America (São Paulo)
us-east-1US East (N. Virginia)
us-west-2US West (Oregon)
us-gov-west-1AWS GovCloud (US-West)
USM Anywhere receives data from USM Anywhere Sensors and uses it to provide essential security capabilities in a single SaaS platform:
  • Centralized system security management
  • Log data analysis and
  • Detection
  • Alerting
  • Log management
  • Reporting
USM Anywhere also retains raw logs long-term for forensic investigations and compliance mandates.