Role Availability | Read-Only | Investigator | Analyst | Manager |
USM Anywhere includes a set of predefined templates based on the classification of event Any traffic or data exchange detected by LevelBlue products through a sensor or external devices such as a firewall. data source types and based on data sources.
You can find these templates on Reports > Event Type Templates.
There are these types of templates:
- Type of Data Source. Event Type Templates enable you to easily run a general firewall Virtual or physical device designed to defend against unauthorized access to data, resources, or a private network. A firewall’s primary purpose is to create segregation between two or more network resources, blocking undesirable traffic between them., authentication, and other types of normalized queries that do not require you to build complex filters based on specific data source or event types. USM Anywhere supports these reports: Anomaly Detection, Antivirus, Application A software program that performs some collection of tasks on a computer or some other programmable device., Application Firewall, Authentication Process used to verify the identity of a user, user device, or other entity, usually through a username and password., Authentication and DHCP Network protocol used to dynamically distribute network configuration parameters, such as IP addresses, for interfaces and services., Cloud The use of many computers connected over a network to run multiple programs or applications at the same time, instead of running them on a local device or network. Application, Cloud Infrastructure, DNS Server, Data Protection, Database, Endpoint Protection, Endpoint Security, Firewall, IDS Network device or program that monitors network traffic and logs and reports suspicious network activity indicative of an intrusion., Infrastructure Monitoring Process of collecting all device status and event information and processing normalized events for evidence of vulnerabilities, possible attacks, and other malicious activity., Intrusion Detection Security system capability that attempts to detect actions that may compromise the confidentiality, integrity, or availability of a resource., Intrusion Prevention, Load Balancer, Mail Security, Mail Server, Management Platform, Network Access Control, Operating System Software that manages computer hardware resources and provides common services for computer programs. Examples include Microsoft Windows, Macintosh OS X, UNIX, and Linux., Other Devices, Proxy, Router, Router/Switch, Server, Switch, Unified Threat Management, VPN, Web Server, Wireless Security/Management.
- Data Sources. You can find templates based on the most commonly used data sources including NIDS Network Intrusion Dectection System (NIDS) monitors network traffic and events for suspicious or malicious activity using the sensors that provide management and network monitoring interfaces to networks and network devices., AWS Suite of cloud computing services from Amazon that make up an on-demand computing platform., Amazon DynamoDB, Amazon S3, AWS VPC Flow Logs, AWS Load Balancers, Azure Microsoft Azure is a cloud computing platform and infrastructure created by Microsoft for building, deploying, and managing applications and services through a global network of Microsoft-managed data centers., Cisco Umbrella, Cylance, FireEye, Fortigate, G Suite, McAfee ePO, Office 365, Okta, Palo Alto, SonicWall, Sophos UTM, Watchguard, VMware, Windows, LevelBlue Agent. There is also a template for the LevelBlue Generic Data Source.