Role AvailabilityRead-OnlyInvestigatorAnalystManager
USM Anywhere includes a set of predefined templates based on the classification of data source types and based on data sources. You can find these templates on Reports > Event Type Templates. There are these types of templates:
  • Type of Data Source. Event Type Templates enable you to easily run a general , authentication, and other types of normalized queries that do not require you to build complex filters based on specific data source or event types. USM Anywhere supports these reports: Anomaly Detection, Antivirus, , Application Firewall, , Authentication and , Application, Cloud Infrastructure, DNS Server, Data Protection, Database, Endpoint Protection, Endpoint Security, Firewall, , Infrastructure , , Intrusion Prevention, Load Balancer, Mail Security, Mail Server, Management Platform, Network Access Control, , Other Devices, Proxy, Router, Router/Switch, Server, Switch, Unified Threat Management, VPN, Web Server, Wireless Security/Management.
  • Data Sources. You can find templates based on the most commonly used data sources including , , Amazon DynamoDB, Amazon S3, AWS VPC Flow Logs, AWS Load Balancers, , Cisco Umbrella, Cylance, FireEye, Fortigate, G Suite, McAfee ePO, Office 365, Okta, Palo Alto, SonicWall, Sophos UTM, Watchguard, VMware, Windows, LevelBlue Agent. There is also a template for the LevelBlue Generic Data Source.