Skip to main content
To ensure that you can successfully deploy USM Anywhere in your Microsoft Azure subscription and monitor all of your Azure resources, make sure you have the following available in your Azure environment:
  • An Azure account with privileges in the resource group or subscriptions that you want to install the USM Anywhere Sensor.
    Note: You can deploy a single USM Anywhere Sensor to monitor all of your Azure resource groups. To do this, you must assign the application you create to the entire subscription.
  • Administrative access to Active Directory (AD) within Azure. This AD access enables you to create an application required to install resource groups or a subscription for monitoring.
  • A virtual network inside the resource group.
  • A subnet inside the virtual network.
  • A storage account.
Important: USM Anywhere does not support Azure Classic accounts.
Important: Because the needs of a sensor differ based on the varying demands of different deployment environments and the complexity of events being processed, the number of events per second (EPS) a sensor can process varies.Depending on your environment, you may need to deploy additional sensors to ensure that all events are processed.
Warning: Be sure not to install any application outside of those already provided within your image where you are deploying your Azure Sensor.You may want to check your system for automatically installed applications, such as OMIAgent, which must be uninstalled. Left uninstalled, such applications may make your environment or your sensor unstable.

Sensor Ports and Connectivity

Note: To launch the USM Anywhere Sensor web UI during the initial setup, you need to allow inbound traffic to the sensor IP address through TCP port 80. You can remove access to this port after the sensor successfully connects to USM Anywhere. You do not need to allow inbound traffic to this port from the Internet.
The following tables list the inbound and outbound ports. Sensor Ports and Connectivity (Outbound Ports) Sensor Ports and Connectivity (Inbound Ports)

USM Anywhere IP Addresses for Allowlisting

Your sensor is connected to a USM Anywhere instance deployed in one of the Amazon Web Services (AWS) endpoint regions based on your location. If you need to configure your firewall to allow communication between the sensor and the USM Anywhere instance, refer to the following table with the reserved IP address ranges for each region.
Important: The Update Server and the AlienVault Agent always use the 3.235.189.112/28 range no matter where your USM Anywhere is deployed. The LevelBlue TDR for Gov Update Server uses the 3.32.190.224/28 range.
Note: The regional IP ranges listed in this table are limited to the control nodes (subdomain). You must also meet all requirements provided in the Sensor Ports and Connectivity (Outbound Ports) table.
AWS Regions Where USM Anywhere Instance Is Available

Azure Portal URLs for Proxy Bypass

The URL endpoints to allowlist on your Azure portal are specific to the Azure cloud where your environment is deployed. To allow network traffic to reach these endpoints, select your cloud environment, and then add the following list of URLs to your proxy server or firewall.