Documentation Center
AlienVault® USM Anywhere™

Raw Logs in Events

  Role Availability   Read-Only   Analyst   Manager

USM Anywhere archives raw eventAny traffic or data exchange detected by AlienVault products through a Sensor, or through external devices such as a firewall. data as logs. Raw logs are an invaluable assetAn IP-addressable host, including but not limited to network devices, virtual servers, and physical servers. for forensic analysis and compliance mandates. You can download raw logs for review and find details about specific incidents, search the logs for instances using a specific IP address, or analyze the patterns of multiple attacks.

USM Anywhere enables you to filter events by raw logs, download raw logs, and configure the raw log column.

Filtering Events by Raw Logs

To filter events by raw logs

  1. Go to Activity > Events.
  2. Click the Configure filters link, which is positioned in the lower right area of the filters.
  3. In the Filter Configuration popup window, search raw in the available filters column.
  4. Filters Configuration popup window: raw log search

  5. Use the icon to pass the Raw Log filter from one column to the other.
  6. Click Apply.
  7. Scroll down the list of filters and check the configured filter is displaying.
  8. Click the filter you need to search the events. If you want to select more than one value per filter at the same time, you need to activate the advanced mode. See Searching Events for more information.

Downloading Raw Logs

To download Raw Logs

  1. Go to Activity > Events.
  2. Use the raw log filter to limit the download.
  3. Click Generate Report in the upper right corner of the page to open the Create Report popup window.
  4. Click the Download Raw Logs tab.
  5. Download Raw Logs txt file

  6. Choose a date range. You can select a predefined range between Last Hour, Last 24 Hours, Last 7 Days, Last 30 Days, or Last 90 Days. You can also set your own date range by clicking the icon. Click the boxes having a date to set your own date range.
  7. Choose the number of records to download.
  8. Click Download Logs.

Configuring Raw Logs Columns

To configure the raw logs columns

  1. From the events list view, click the icon to open the Columns Configuration popup window.
  2. Search raw in the in the search box of the available columns.
  3. Use the icon to pass the Raw Log column from one side to the other.
  4. Click Apply.
  5. Your browser downloads a .txt file automatically.

Important: If you want to keep your configuration, you need to save it by selecting Save View > Save as. Otherwise, your custom view will not be kept when you move to another feature.