USM Anywhere provides several kinds of scans that can be done in different ways. This page gives you clearer information about scans, types of scans, the specific ways of doing a scan, the right order for doing scans and avoid asset duplicity, and so on. See USM Anywhere Scheduler Best Practices for more information.

Discovery Methods

The following table shows the types of scans that you can run using USM Anywhere. Types of Scans in USM Anywhere
Types of ScansInformation Collected From Where You Can Do ItSensorsReferences
Active directory (AD)Inventory Information
  • Setup Wizard during your sensor’s deployment
  • At any time from the sensor details page
  • Job Scheduler page
Microsoft Azure, Microsoft Hyper-V, and VMwareComplete the Azure Sensor Setup, Complete the Hyper-V Sensor Setup, and Complete the VMware Sensor Setup
Asset discoveryDiscovers assets in your environment, detects changes in assets, and discovers malicious assets in the network
  • Setup Wizard
  • Adding new assets both in a quick and in an advanced way
  • Job Scheduler page
AllComplete the Hyper-V Sensor Setup, Complete the VMware Sensor Setup, Adding Assets
Asset group scansAssets
  • Asset groups
  • Job Scheduler page
AllRunning Asset Groups Scans
Asset scansAssets
  • Assets
  • Job Scheduler page
AllRunning Asset Scans
Authenticated asset group scansAssets
  • Asset Groups
  • Job Scheduler page
AllRunning Authenticated Asset Groups Scans
Authenticated asset scansAssets
  • Assets
  • Job Scheduler page
AllRunning Authenticated Asset Scans
Log collection scansLog files from an external data sourceJob Scheduler page: log collection jobs are initially preset at installation and can’t be modified by a userAllUSM Anywhere Scheduler
Scheduled AD scan jobsInventory InformationJob Scheduler pageMicrosoft Azure, Microsoft Hyper-V, and VMwareScheduling Active Directory Scans from the Job Scheduler Page
Scheduled API scansAssetsJob Scheduler pageGCP, Microsoft Azure, Microsoft Hyper-V, and VMwareUSM Anywhere Scheduler
Scheduled asset scansAssetsJob Scheduler pageAllScheduling Asset Scans from the Job Scheduler Page
Scheduled asset group scansAssetsJob Scheduler pageAllScheduling Asset Groups Scans from the Job Scheduler Page
Scheduled Authenticated Asset ScansAssetsJob Scheduler pageAllScheduling Asset Scans from the Job Scheduler Page
Scheduled authenticated asset group scansAssetsJob Scheduler pageAllScheduling Asset Groups Scans from the Job Scheduler Page
User scansScheduled user behavior monitoring scan jobsJob Scheduler PageAllScheduling User Discovery Jobs from the Job Scheduler Page

Performance Issues Associated with Scans

When running a scan, keep the following in mind:
  • Run API scans first to avoid duplicates and discover the most assets in your environment, and then run asset discovery/asset (group) scans with the Asset Scanner to update the asset. When an asset is discovered through a network scan, and then that asset is discovered through an APIs method, the asset will be duplicated.
  • After deploying an agent, link it to existing assets.
  • When an AD scan discovers an asset, any asset discovery/asset (group) scan updates the existing asset created by the AD scan.
  • Enabling vulnerability events will generate System Events for each newly discovered vulnerability. Be prepared for an influx of System Events when enabling this feature. It is recommended to run a few initial vulnerability scans to get a baseline prior to enabling this feature.
  • Assets discovered by API methods contain far more information than assets discovered by network scans and greatly reduce the risk of having duplicate assets. For example, assets discovered by API methods can include information such as the asset state (powered on, powered off, terminated, and so on), the resources allocated to the asset, or the asset operating system.
  • If multiple API methods return the same assets, then use only the method that provides the most assets to prevent duplicate assets. The other API methods can be disabled in the Job Scheduler page. See USM Anywhere Scheduler for more information.
  • The following table gives you information about the use of some scan types over other: Scans Differences
    Discovery TypeAD ScanVMware ScanAWS ScanAzure ScanGCP ScanAgentNetwork ScanManually Created
    APIYesYesYesYesYesNoNoNo
    Asset OSYesYesYesYesYesYesDepends on information gatheredNo
    Host resourcesYesYesYesYesYesNoNoNo
    Asset info updatesYesYesYesYesYesYesDepends on information gatheredDepends on information gathered
    Asset stateNoYesYesYesYesNo only agent stateNoNo