Log Collection and Scans
The GCP Sensor collects GCP and system log, and generates asset scans and , consisting of the following:- Google Cloud Audit Logs
- Amazon Virtual Private Cloud (VPC) Flow Logs
- Firewall logs
- Syslogs
- Apache Logs
- NGINX logs
- Operational logs for critical software packages deployed, such as HTTP servers and database servers
- Asset scans on your virtual machines (VMs) to inventory installed software packages, running processes, and services
- Periodic vulnerability assessments
Log Analysis
USM Anywhere analyzes these logs in these stages: Stage 1: Collects logs from systems and software running in your environment Stage 2: Configures log line processing and generates events- Includes IP addresses and timestamps culled from extracted log-line data
- Adds other data to the event, such as security context and environmental information
Deployment Overview
LevelBlue distributes the GCP Sensor as a Google Cloud Deployment Manager template specifically for the Google Virtual Private Cloud (VPC). The deployment process for an initial USM Anywhere Sensor in your GCP environment consists of these primary tasks:- Review requirements for a GCP Sensor deployment.
- Prepare your GCP environment for sensor deployment.
- Deploy the USM Anywhere Sensor within your GCP environment.
- Register the sensor with your sensor authentication code to provision the USM Anywhere instance and connect the deployed sensor.
- Complete your GCP Sensor configuration, including initial asset discovery.
- Configure log collection with Google Cloud Pub/Sub.

Related Video Content