Level Blue home page
Search...
⌘K
Support
Dashboard
Dashboard
Search...
Navigation
Events Management
Events Management
Home
Documentation
API Reference
Blog
Events
Contact Us
USM Anywhere™
Overview
USM Anywhere Architecture
USM Anywhere Data Security
USM Anywhere Log Data Enhancement
USM Anywhere Quick Start Guides
USM Anywhere Deployment Guide
USM Anywhere User Guides
Overview
Getting Started with USM Anywhere
USM Anywhere Best Practices
USM Anywhere Dashboards
Asset Management
Alarms Management
System Events Management
Console User Events on USM Anywhere
Configuration Issues Management
User Behaviour Analytics
Events Management
Overview
Workflow of the USM Anywhere Event Process
Events List View
Searching Events
Viewing Event Details
Create an Events Report
Protecting Your Sensor's Performance with EPS Adaptive Response
Raw Logs in Events
Managing Collected CloudTrail Event Logs
Event Keys
USM Anywhere Scheduler
Rules Management
Vulnerability Assessment
Open Threat Exchange® and USM Anywhere
USM Anywhere Sensor Management
The AWS Cloud Connector in USM Anywhere
Subscription Management
USM Anywhere Reports
Machine Learning
USM Anywhere User Management
Using USM Anywhere for PCI Compliance
USM Anywhere Investigations
System Status within USM Anywhere
USM Anywhere Agents Guide
USM Anywhere BlueApps Guide
USM Central™
Overview
USM Central Web User Interface (UI)
USM Central Deployments
Alarms Management
Vulnerabilities
Configuration Issues
Orchestration Rules Management
Saved Reports
System Events Management
User Management
LevelBlue TDR for Gov Documentation
How to Submit a Security Issue to LevelBlue
Automated Policy Manager
Overview
Navigation Panel
Dashboard
Create
Manage
Tickets
Assets
Dark Mode/Light Mode
Early Access Features
Network Based Firewall Service (NBFW)
Events Management
Events Management
An
event
is a record of activity, which contains information and that resides in a log file. USM Anywhere collects, normalizes, and enriches logs with additional
metadata
, which are called events.
After USM Anywhere is installed in your environment, events start flowing through your system, so you can start gaining visibility into the type of events that are occurring, what natural or non-threatening activity is taking place, and what activity can be a possible attack.
This topic discusses these subtopics:
Workflow of the USM Anywhere Event Process
Events List View
Event Views
Report Templates in Events
LevelBlue Generic Data Source
Searching Events
Searching Events by Using the Search Field
Standard and Advanced Modes on Events
About the No Value Option
Viewing Event Details
Applying Actions to Events
Creating Rules from Events
Adding an Event to an Investigation
Create an Events Report
Protecting Your Sensor’s Performance with EPS Adaptive Response
Raw Logs in Events
Managing Collected CloudTrail Event Logs
Event Keys
Importing Users from a CSV File
Workflow of the USM Anywhere Event Process
Assistant
Responses are generated using AI and may contain mistakes.