AlienVault® USM Anywhere™

Raw Logs in Events

Role Availability Read-Only Analyst Manager

USM Anywhere archives raw eventAny traffic or data exchange detected by AT&T Cybersecurity products through a sensor, or through external devices such as a firewall. data as logs. Raw logs are an invaluable assetAn IP-addressable host, including but not limited to network devices, virtual servers, and physical servers. for forensic analysis and compliance mandates. You can download raw logs for review and find details about specific incidents, search the logs for instances using a specific IP address, or analyze the patterns of multiple attacks.

USM Anywhere enables you to filter events by raw logs, download raw logs, and configure the raw log column.

Filtering Events by Raw Logs

To filter events by raw logs

  1. Go to Activity > Events.
  2. In the upper left corner of the page, click the Configure Filters link.

  3. In the Filter Configuration dialog box, search raw in the available filters column.
  4. Filters Configuration popup window: raw log search

  5. Use the icon to pass the Raw Log filter from one column to the other.
  6. Click Apply.
  7. Scroll down the list of filters and verify that the configured filter is displaying.
  8. Click the filter that you need to search the events. If you want to select more than one value per filter at the same time, you need to activate the Advanced Mode. See Searching Events for more information.

Downloading Raw Logs

To download Raw Logs

  1. Go to Activity > Events.
  2. Use the raw log filter to limit the download.
  3. In the upper right corner of the page, click Generate Report to open the Create Report dialog box.
  4. Click the Download Raw Logs tab.
  5. Download Raw Logs txt file

  6. Choose a date range. You can select a predefined range between Last Hour, 24 Hours, 7 Days, 30 Days, or 90 Days. You can also set your own date range by clicking the icon. Click the boxes having a date to set your own date range.
  7. Choose the number of records to download.
  8. Click Download Logs.

Configuring Raw Logs Columns

To configure the raw logs columns

  1. From the Events List view, click the icon to open the Columns Configuration dialog box.
  2. Search raw in the in the search box of the available columns.
  3. Use the icon to pass the Raw Log column from one side to the other.
  4. Click Apply.
  5. Your browser downloads a .txt file automatically.

Important: If you want to keep your configuration, you need to save it by selecting Save View > Save as. Otherwise, your custom view will not be kept when you move to another feature.