A USM Anywhere plugin is a software component that provides logic specific to producing normalized event data from the raw log data received from an external data source. The plugin parses the raw data and converts it into common event fields, such as user, date and time, and source or destination IP address, so that USM Anywhere can manage the information as a security event. With a normalized event, USM Anywhere can display information uniformly and correlate events from various individual systems to generate alarmsAlarms provide notification of an event or sequence of events that require attention or investigation..

USM Anywhere provides numerous plugins that translate log data from common devices, operating systems, and applications. When USM Anywhere receives the raw log data, it must identify a plugin to use for normalization. Many data sources produce syslog messages that contain information that can be used to identify the device or application that produced the message. Others data sources produce log data that requires more guidance to identify a match for the data.