When you review the information in the Alarm Details or Event Details, you can easily launch a Forensics and Response action. If you want to apply the action to similar items that occur in the future, you can also create an orchestration rule directly from the executed action.
Review the information in Supported Actions to determine the action that you want to launch.
To launch a Forensics and Response action from an alarm or event
- Navigate to ACTIVITY > ALARMS or ACTIVITY > EVENTS.
- Click the alarm or event to open the details.
Click Select Action.
In the Select Action dialog, select the Get Forensics Information tile.
This displays the options for the selected action type.
- If you have more than one deployed USM Anywhere Sensor, select the Sensor associated with the asset that you want to use as the target for the action.
Click the App Action list and select the action you want to run for the asset(s).
Specify the Asset that you want to use as a target for the action.
You can start typing the name or IP address of the asset in the field to display matching items that you can select. Or you can click the Browse Assets link to open the Select Asset dialog and browse the asset list to make your selection.
After USM Anywhere initiates the action, it displays a confirmation dialog.
If you want to create a rule to apply the action to similar items that occur in the future, click Create rule for similar alarms or Create rule for similar eventsand define the new rule. If not, click OK.