Documentation Center
AlienVault® USM Anywhere™

Evidence on Investigations

  Role Availability   Read-Only   Analyst   Manager

This section displays the alarms, events, and files associated to the investigation.

Evidence section on the details of a case investigation

You can click an alarm or an event to go to the alarm or event.

The asset name includes a chevron icon that can be grey () if the asset is not in the system, or blue () if the asset has been added to the system.

Click the grey chevron icon () to access these options:

  • Add to current filter — Use this option to add the asset name as a search filter, see Searching Events for more information.
  • Find in events — Use this option to execute a search of the asset name in the Events page, see Searching Events for more information.
  • Look up in OTX — This option searches the IP address of the source asset in the Open Threat Exchange page, see Using OTX in USM Anywhere for more information.
  • Add asset to system — Use this option to create the asset in the system, see Adding Assets for more information.

Click the blue chevron icon () to access these options: