After you initialize a new USM Anywhere Sensor, you must configure it in the Setup Wizard. As part of configuration, you can enable scheduled jobs to perform specific actions, such as running an asset discovery scan or collecting security eventsInformation collected and displayed that describes a single system or user level activity that took place. from a predefined cloud storage location.
Accessing the Setup Wizard
The Setup Wizard is accessible under the following circumstances:
- When you first log into the USM Anywhere web UI and see the WELCOME TO USM ANYWHERE page, click Get Started.
If you registered a first sensor, but did not complete the setup and then logged out, the USM ANYWHERE SENSOR CONFIGURATION page launches automatically at your next login to remind you to finalize configuration of the Sensor.
Click Configure to launch the Setup Wizard and complete the Sensor configuration.
If you registered an additional Sensor, but did not complete the setup, the Sensors page displays the Error () icon in the CONFIGURED column.
Click the Configure () icon on the right to launch the Setup Wizard and complete the Sensor configuration.
Configuring the Azure Sensor in the Setup Wizard
The first time you log in from the WELCOME TO USM ANYWHERE web page, the Setup Wizard prompts you to complete the configuration of the first deployed Sensor. Thereafter, you can use the Sensors page to configure an additional Sensor or to change the configuration options for a deployed Sensor.
To complete the Azure sensor configuration, you must obtain Azure API credentials for the subscription that you want USM Anywhere to monitor. Select the option on the AZURE CREDENTIALS page that matches your current Azure credential creation status:
- If you already generated your Azure credentials, click Yes, I have my Azure credentials and am ready to enter them.
- If you don't yet have your Azure credentials, click No, I don't have my Azure credentials and need to create them.
- If you're not sure, click I am not sure. Show me how to create my Azure credentials.
If you select No or I am not sure, the page provides options for two creation methods:
If you select Yes, follow the steps in Configuring the Azure Credentials After Manual Credential Generation.
This procedure is for Windows users who want to use the provided Powershell script to automatically generate their credentials for sensor configuration.
Select Create credentials automatically using a Powershell script (Recommended).
The page automatically launches a download of the Powershell script. You can use the browser tools to save the file to the appropriate location on your system.
Run the script as administrator on your Windows operating system.
Note: If you have multiple Azure subscriptions, the script prompts you to identify which one you want USM Anywhere to monitor.
When the script finishes it creates a text file that saves to your Desktop.
In USM Anywhere, drop the Azure credentials text file onto the displayed page or click the select USM_Anywhere_Azure_Credentials.txt from your desktop link to locate, select, and upload the file.
Verify that the status at the top of the page displays the following message
Select Learn how to create Azure credentials manually.
This opens the Creating an Application and Obtaining Azure Credentials page in a new browser tab or window.
- Follow the instructions for creating the needed credentials.
- Return to USM Anywhere, then click the Back button to display the first AZURE CREDENTIALS page.
This procedure is for non-Windows users who generated their Azure credentials manually and who are ready to configure the sensor.
- Select the Yes option, and in the next page click the Enter previously created Azure credentials manually link at the bottom of the page.
Enter the Azure API credentials you generated in the Azure console into the appropriate fields.
- Click Save Credentials.
Verify that the status at the top of the page displays the following message
When the credentials are configured, click Next.
The wizard displays the next page in the setup process, AZURE CONFIGURATION.
After you've successfully configured the Azure credentials, the AZURE CONFIGURATION page appears. This page summarizes the number of Azure virtual machines (VMs), resource groups, and VM sizes in your environment.
Important: If you are using virtual machine scale sets to provide redundancy and load balancing in your Azure environment, the Azure sensor does not automatically discover the scale set hosts through network scans. It does collect syslog from these hosts, but you must manually add the VMs to the USM Anywhere asset inventory.
The wizard displays the next page in the setup process, AZURE LOG COLLECTION.
The AZURE LOG COLLECTION page displays the following Azure logs that are automatically discovered by USM Anywhere in your environment:
- Azure REST Monitor (formerly Azure Insight)
- Azure Security Alerts
- Azure SQL Server logs
- Azure IIS logs
- Azure Windows logs
Important: USM Anywhere collects SQL Server logs stored as tables only. It does not collect SQL Server logs stored as Binary Large OBjects (BLOB)s.
Microsoft Azure has recently deprecated table storage and recommends that users select the BLOB storage option. However, you must use the Azure Tables storage option for your SQL Server logs to make them available for collection by the USM Anywhere Sensor.
For more information about Azure log discovery and collection, see Azure Log Discovery and Collection in USM Anywhere.
To enable these out-of-box Azure log collection jobs, toggle the gray ENABLE icon so that it turns into a green check mark. When you enable any of these log collection jobs, USM Anywhere starts collecting the log data immediately according to the preconfigured frequency. If you want to add other Azure log collection jobs after the sensor configuration, including jobs for Azure Web Apps, see Creating a New Azure Log Collection Job.
Note: If you go to ACTIVITY > EVENTS in USM Anywhere post-configuration, you can see all of the events associated with each log type, including its Event ID and many other useful details. You can also review related log collection jobs in the Job Scheduler page (SETTINGS > SCHEDULER).
After you enable each job that you want, click Next.
The wizard displays the next page in the setup process, ACTIVE DIRECTORY.
The optional ACTIVE DIRECTORY setup page configures USM Anywhere to collect information from your Active Directory (AD)Active Directory (AD) is a directory service that Microsoft developed for Windows domain networks. account. To monitor Windows systems effectively, USM Anywhere needs access to AD (Active Directory) server to collect inventory information.
AlienVault recommends that you create a dedicated AD account with membership in the Domain Admins group to be used by USM Anywhere to log in into the Windows systems. You also need to activate WinRM in the domain controller and in all the hosts that you want to scan. You can do this by using a group policy for all the systems in your Active Directory.
Important: Before this feature is fully functional, you must configure access to the USM Anywhere Sensor on the Active Directory server. For more information, see Granting Access to Active Directory for USM Anywhere.
To complete the AD access configuration
Provide the AD credentials for USM Anywhere
- Active Directory IP Address — Enter the IP address for the AD server.
- Username — Enter your username as administrator of the account.
- Password — Enter your administrator's password.
- Domain — Enter the domain for the AD instance.
Click Scan Active Directory.
After a successful launch of the scan, a confirmation dialog appears.
The scan continues in the background.
Upon completion, another dialog appears and provides information about the number of assets USM Anywhere discovered. It also prompts you to decide if you want to scan for hosts and services running in your environment.
Click CANCEL to opt out of this scan.
(Optional) If you want to scan for other hosts and services, click OK.
Click Next after the scan ends.
The wizard displays the next page in the setup process, LOG MANAGEMENT.
On the LOG MANAGEMENT page, you see syslog port numbers. (These ports are the same for all USM Anywhere Sensors.)
USM Anywhere collects third-party device, system, and application data through syslogAn industry standard message logging system that is used on many devices and platforms. over UDP on port 514 and over TCP on port 601 by default. It collects TLS-encryptedTransport layer security. Successor to Secure Sockets Layer (SSL) protocol. Provides security for communication over the Internet between client and server applications. data through TCP on port 6514 by default. To configure any third-party devices to send data to USM Anywhere, you must provide the IP address of your USM Anywhere Sensor and the port number.
Make sure that you've granted the necessary permissions for your operating system to allow USM Anywhere to access its logs. You can also integrate a wide variety of data sources to send log data over syslog to the USM Anywhere Sensor.
To find out how to configure your operating systems and supported third-party devices to forward syslog log data, see the following related topics
- Log collection (UDP, TCP, and TLS-encrypted TCP) from rsyslog — The Syslog Server Sensor App
- Log collection from a Linux System — Collecting Linux System Logs
- Log collection from a Windows System — Collecting Windows System Logs
- Log collection integrations for various data sources — Supported USM Anywhere Plugins for Common Data Sources
Note: Because the log scan can take some time, you might not see all the automatically discovered log sources immediately after deploying the first sensor.
When you've finished the log collection setup and integrated any needed plugins, verify that the data transfer is occurring.
Click Next when this step is complete.
AlienVault Open Threat Exchange® (OTX™) is an open information-sharing and analysis network providing users with the ability to collaborate, research, and receive alerts on emerging threats and indicators of compromise (IoC) such as IPs, file hashes, and domains.
You must have an OTX account to receive alerts based on threats identified in OTX. This account is separate from your USM Anywhere account. Go to The World’s First Truly Open Threat Intelligence Community page to create an OTX account.
Note: If you do not already have an OTX account, click the Sign up link. This opens another browser tab or window that displays the OTX signup page. After you confirm your email address, you can log into OTX and retrieve the unique API key for your account.
For more information about OTX integration in USM Anywhere, see Open Threat Exchange® and USM Anywhere.
- Log into OTX and open the API page (https://otx.alienvault.com/api/).
In the DirectConnect API Usage panel, click the Copy () icon to copy your unique OTX connection key.
Return to the Threat Intelligence page of the USM Anywhere Sensor setup wizard and paste the value in the OTX Key text box.
Click Validate OTX Key.
With a successful validation of the key, the status at the top of the page changes to Valid OTX key.
Click Next when this task is complete.
The Congratulations! page summarizes the status of your configuration.
Click Start Using USM Anywhere, which takes you to the Overview dashboard.
Now's a great time to run a vulnerability scan. For detailed information about running a vulnerability scan, go to Vulnerability Assessment.