Using the LevelBlue Agent
The LevelBlue Agent provides simple installation, configuration, and management for host monitoring in USM Anywhere. When you install the LevelBlue Agent on a Linux host, it communicates over an channel to send data directly to USM Anywhere. The agent installation script configures a default set of folders and files to automatically support file integrity monitoring (FIM). You can set the configuration profile to manage the queries that USM Anywhere runs for an asset associated with a deployed agent. Using LevelBlue Agents is the best choice for monitoring endpoints outside of the network, in remote locations, or where deploying a sensor is impractical. Additionally, it provides the ability to query the for additional forensic data as part of your investigation activities. See The LevelBlue Agent for more information about the LevelBlue Agent and how you can use it to simplify your endpoint detection and response (EDR), FIM, and rich endpoint telemetry capabilities.Collecting Logs from Cloud Environments
USM Anywhere provides USM Anywhere Sensors for different cloud environments and collect logs using their native tools:- AWS Log Discovery and Collection in USM Anywhere
- Azure Log Discovery and Collection in USM Anywhere
- GCP Log Discovery and Collection in USM Anywhere