The Job Scheduler page provides a list of all jobs that are defined in your USM Anywhere environment. Many jobs are predefined (out-of-the-box) items for log collection and asset scans, and some of these require enablement in order to run according to the defined schedule. You can also define your own custom jobs to schedule automatic log collection, asset scans, and asset group scans, as well as jobs to perform AlienAppAlienApps extend the threat detection and security orchestration capabilities of the USM Anywhere platform to other security tools that your IT team uses, providing a consolidated approach to threat detection and response. functionality.
The Job Scheduler Page
The Job Scheduler page includes navigation and filtering elements to help you locate the jobs you want to review. When you go to Settings > Scheduler, the page displays All Jobs by default. You can select one of the job types in the left navigation to display only the jobs of that type:
- Log Collection: Select this display option to review the list of scheduled log collection jobs. These jobs collect log files from an external data source.
- Asset Scans: Select this option to review the list of scheduled asset scan jobs. This option displays both asset scan, authenticated asset scan, and asset discovery jobs.
- Asset Group Scans: Select this option to review the list of scheduled asset group scan jobs. This option displays both asset group scan and authenticated asset group scan jobs.
- User Scans: Select this option to review the list of scheduled user behavior monitoring scan jobs. See Scheduling User Discovery Jobs from the Job Scheduler Page.

To change the sort order of the displayed list, click the column label for the field that you want to use to sort the list. Use the filters at the top of the list to change the displayed list so that it includes only the jobs you want to see.
- Filter by: Enter a search string for the name of the app or the job name to display only matching jobs.
- Sensor: If you have more than one deployed USM Anywhere Sensor, select a sensor to display only the jobs that are configured for it.
-
Job Type: Set this option to display only the jobs of the selected type. The available items are based on the jobs currently displayed on the page:
- Configuration
- Collection
- Scan
- Asset Discovery
- Group Scan
- User Scan
- Task Status: Set this option to display only jobs for the selected status, either Enabled or Disabled. You also have the option All Tasks.
- Clear Filters: Click this button to remove filtering options and display all items for the category selected in the left navigation.
When you locate a scheduled job in the list, you can select it to expand the details for the job and review its history.

When most logs in your AWS or Azure account are enabled, USM Anywhere automatically discovers them and they can start generating events, based on CloudTrail, Amazon S3, ELB Access, Azure Security Event logs, and others. But, because these out-of-box log collection and asset scan jobs deploy disabled initially, you must decide which jobs you want to activate and enable them.
You can disable or enable a predefined or custom job in the Job Scheduler page.
To enable scheduled jobs
- Go to Settings > Scheduler to open the Job Scheduler page.
- Locate the jobs with which you want to enable to collect events or asset information, and click the
icon.
This turns the icon green. To disable an already-enabled job, toggle the icon to its original status.

USM Anywhere includes defined jobs to perform many of the standard log collection and scanning actions that you will need to monitor your networks. These jobs are predefined to run using a recurrence according to industry best practices. However, if you need to define a scheduled job to perform log collection, asset scans, or asset group scans, you can add a new job directly on the Job Scheduler page.
To create a new job
- Select Settings > Scheduler to open the Job Scheduler page.
-
In the upper right of the page, click New Job.
- If you have selected Log Collection in the left navigation panel, this button is labeled Create Log Collection Job. This limits the options in the dialog to those that define a log collection job.
- If you have selected Asset Scans or Asset Group Scans in the left navigation panel, this button is labeled Create Scan Job. This limits the options in the dialog to those that define an asset scan, asset group scan, or asset discovery job.
- If you have selected User Scans in the left navigation panel, this button doesn't display because this option is used to review the list of scheduled user behavior monitoring scan jobs.
-
Enter the name and description for the job.
The description is optional, but it is a best practice to provide this information so that others can easily understand what it does.
- Select an Action Type, see Standard Job Apps for more information.
- Active Directory Scanner
- Amazon Web Services
- Asset Scanner
- Authenticated Asset Scanner
- Azure
- Forensics and Response App
- Select a sensor if you have more than one installed in your environment.
- Use the App Action option to select the job to run. The selected app determines the actions that are available.
-
In the Schedule section, specify when USM Anywhere runs the job:
- Select the increment as Minute, Hour, Day, Week, Month, or Year.
-
Set the interval options for the increment.
The selected increment determines the available options. For example, on a weekly increment you can select the days of the week to run the job.
Or on a monthly increment, you can specify a date or a day of the week that occurs within the month.
-
Set the Start time.
This is the time that the job starts at the specified interval. It uses the time zone configured for your USM Anywhere instance (default is Coordinated Universal Time [UTC]).
- Click Save.

You cannot change or delete the parameters of the out-of-the-box jobs in USM Anywhere. You can only enable or disable the predefined jobs. However, you can make changes to the scheduled jobs that you have defined, such as changing the schedule parameters to run the job more or less frequently. If a custom job is no longer needed, you can delete it.
To make changes to a custom job
- Locate the job in the Job Scheduler list.
-
In the row for the job, click
.
-
In the Edit Job dialog box, change the parameters for the job as needed.
See Add a New Custom Job for more information about these options.
- Click Save.
To delete a custom job
Standard Job Apps
There are a number of apps in USM Anywhere that support the creation of scheduled jobs for the assets and networks monitored by your USM Anywhere Sensors:

If you have a deployed AWS Sensor, this app provides support for the predefined log collection jobs that USM Anywhere uses to monitor your AWS account. You can also use the app to define custom jobs, such as collecting third-party logs stored in an S3 bucket.
For more information about jobs for this app, AWS Log Discovery and Collection in USM Anywhere.

If you have a deployed Azure Sensor, this app provides support for the predefined log collection jobs that USM Anywhere uses to monitor your Azure subscription. You can also use the app to define custom jobs, such as collecting Azure web app logs.
For more information about jobs for this app, Collect Azure Resource Logs .

Use this app to define an Active Directory scan job for a specified asset in order to query Microsoft Active Directory for information about the currently registered computers.
For more information about jobs for this app, see Running Active Directory Scans.

Use this app to run basic asset discovery scans in order to collect basic information about the assets in your monitored networks and cloud environments.
For more information about jobs for this app, see Scheduling Asset Scans from Assets.

Use this app to run deeper scans of monitored assets using administrative credentials in order collect data about the installed services and programs, as well as vulnerabilitiesA known issue or weakness in a system, procedure, internal control, software package, or hardware that could be used to compromise security. and configuration issues.
For more information about jobs for this app, see Scheduling Authenticated Asset Scans from Assets.
AlienApp Job Apps
Some AlienApps provide support for scheduled data collection functions through API integrations. If you have one or more of these AlienApps enabled and configured, these job apps provide support for scheduled data collection:

Use this app to define custom AlienApp for McAfee ePO jobs that connect to the ePO server SQL database and retrieve and ingest data for analysis in USM Anywhere.
For more information, see AlienApp for McAfee ePO.

Use this app to collect Windows or Linux system data from monitored assets or execute system-level enforcement functions on Windows hosts using administrative credentials.
For more information about jobs for this app, see Scheduling a Forensics and Response Job in the USM Anywhere AlienApps Guide.

This app runs predefined jobs to support the AlienApp for Cloudflare. For each deployed sensor, USM Anywhere includes an out-of-the-box log collection job to support data collection from your Cloudflare environment.
For more information, see AlienApp for Cloudflare.

This app runs predefined jobs to support the AlienApp for SpyCloud Dark Web Monitoring. For each deployed sensor, USM Anywhere includes an out-of-the-box log collection job to support the collection of new records from SpyCloud every 24 hours for all validated watchlist items.
For more information, see AlienApp for SpyCloud Dark Web Monitoring.

This app runs predefined jobs to support the AlienApp for Okta. For each deployed sensor, USM Anywhere includes an out-of-the-box log collection job to support data collection from your Okta environment.
For more information, see AlienApp for Okta.

This app runs predefined jobs to support the AlienApp for Sophos Central. For each deployed sensor, USM Anywhere includes an out-of-the-box log collection job to support data collection from your Sophos Central environment.
For more information, see AlienApp for Sophos Central.

This app runs predefined jobs to support the AlienApp for G Suite. For each deployed sensor, USM Anywhere includes a collection of out-of-the-box log collection jobs to support data collection from you Google G Suite environment.
For more information, see AlienApp for G Suite.

This app runs predefined jobs to support the AlienApp for Office 365. For each deployed sensor, USM Anywhere includes a collection of out-of-the-box log collection jobs to support data collection from your Microsoft Office 365 environment.
For more information, see AlienApp for Office 365.

This app runs predefined jobs to support the AlienApp for ConnectWise. For each deployed sensor, USM Anywhere includes two out-of-the-box jobs that generate new ConnectWise service tickets from alarmsAlarms provide notification of an event or sequence of events that require attention or investigation. and vulnerabilitiesA known issue or weakness in a system, procedure, internal control, software package, or hardware that could be used to compromise security. and synchronize assets with the Configurations catalog.
For more information, see AlienApp for ConnectWise.