Role Availability | Read-Only | Investigator | Analyst | Manager |
- By assigning one or more assets to the BlueApp. See Assign Assets to BlueApps for details.
- By adding one or more BlueApps to the asset (this document).
Assigning an BlueApp to an asset disables the usage of hints for the logs coming from this asset; therefore, USM Anywhere only uses the assigned BlueApps to parse and normalize those logs.If you use a log-forwarding software (such as Splunk or Loggly) to send logs to USM Anywhere, LevelBlue recommends that you use at least two such forwarders: one forwarder for all the auto-discoverable BlueApps, and the other for the non-auto-discoverable BlueApps. In the latter case, you must create an asset in USM Anywhere to denote the forwarder and assign it to the non-auto-discoverable BlueApps. This ensures that USM Anywhere uses the correct BlueApp to parse your logs.
- Go to Environment > Assets.
- (Optional.) Use the Search & Filters option to filter the list and help you locate the asset you want. See Searching Assets for more information.
-
Click the icon next to the asset name and then select Full Details.
This displays the Asset Details.
-
At the bottom of the expanded page, select the BlueApps tab and click Add BlueApp.
-
In the dialog box, select the BlueApp you want to assign to the asset. Enter full or part of the name in the Set a New BlueApp field and select one from the displayed list.
The system displays this message at the top of the page: BlueApp added successfully.
- (Optional.) Repeat the previous step to add another BlueApp.
-
Click the
icon to close the dialog box. On the BlueApps tab, you can see the list of BlueApps added.
LevelBlue Generic Data Source Events
LevelBlue Generic Data Source Events
For logs where a matching BlueApp is not identified, USM Anywhere parses it using a generic data source. You can review the generated events in the LevelBlue Generic Data Source events view. If the reporting device for the event is defined in the USM Anywhere asset inventory, you can manually assign an BlueApp directly from this view.See LevelBlue Generic Data Source for more information about the information and tools available in this view.To assign an BlueApp from a LevelBlue Generic Data Source event
- Go to Activity > Events.
- Click View > Saved views > LevelBlue Generic Data Source.
- Click Apply.
- Review the listed events and locate an event where the reporting device is displayed in blue and you want to manually assign a known BlueApp to the asset.
-
In the Reporting Device column, click the
icon next to the asset name and select Assign BlueApp.
The Add BlueApp to an asset dialog box opens. -
In the dialog box, select the BlueApp to use for log data from the asset.
Enter part of the BlueApp name in the Set a New BlueApp field and select the BlueApp from the displayed list.
- (Optional.) Repeat the previous step to add another BlueApp for the asset.
-
Click the
icon to close the dialog box.