AlienVault® USM Anywhere™

Configure Log Collection Using Templates

For your USM Anywhere Sensor to receive logs from your Google Cloud Platform (GCP) environment, you must have: an export sink to define which logs are exported, a topic to receive those logs, and a subscription to deliver those exported logs to the sensor. The easiest way to create and configure all of these disparate pieces is by using the templates AT&T Cybersecurity provides.

See Manually Create a Cloud Pub/Sub Topic or Manually Create and Configure an Export Sink if you would like to perform these steps manually rather than using these templates.

Important: Since these templates are deployed using the Deployment Manager, you must ensure that both the user executing the deployment and the service account associated with the Deployment Manager have the required permissions:

  • The user executing the deployment must be assigned the role "Deployment Manager Editor" for the project in which they will perform the deployment.
  • The Deployment Manager's service account must have the "Logging Admin" and "Pub/Sub Admin" roles for the project or organization from which you will be exporting logs.

To configure log collection using templates

  1. Download the template files from AT&T Cybersecurity:
  2. Create a Type Registry to deploy the templates by going to the Type Registry page under Deployment Manager.
  3. Click Add Composite Type.
  4. Import the templates you previously downloaded.
  5. Provide the following information:
    1. Deployment Name: A name for this deployment
    2. source_id: The ID of the project exporting these logs.

    Use the provided deployment manager template files to make enabling Pub/Sub log collection easy.

  6. If you are executing this deployment at the project level, use the list to select the log types to export.
  7. Note: See the Log Export Filters table to see how these log queries are formatted.

  8. (Optional.) Specify the name of an existing topic to use instead of creating a new one.
  9. If you choose to use an existing topic, you must ensure that you grant the Writer Identity service account "Pub/Sub Publisher" permissions.
  10. Click Deploy.
    You can verify that your topic and subscription have been created by checking the Topics page under Pub/Sub.
  11. Go to your sensor's user interface (UI) and click the Log Subscriptions tab.
  12. Click Enable to enable the subscription you just created.