LevelBlue provides a VMware Sensor to monitor your virtual and physical on-premises infrastructure. When this USM Anywhere Sensor is deployed and configured for your USM Anywhere instance, security-related data is collected and sent to the LevelBlue Secure Cloud for security analysis, threat correlation, and secure, compliance-ready data storage. You can also create jobs to collect log data through VMware, including operating system (OS) and database-level logs. Through VMware, you can deploy a USM Anywhere Sensor in any of the virtual networks that you want to instrument for a network-based intrusion detection system (NIDS), including standard sensor features:Documentation Index
Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
Use this file to discover all available pages before exploring further.
- Log data collection
- Authenticated asset scans
- Unauthenticated asset discovery scans
Note: If your organization uses multiple subnets to enable communication between headquarters and remote offices, you do not need a sensor for each subnet. However, you will need a deployed VMware Sensor for each physical location that you want to monitor.
Deployment Process Overview
The deployment process for an initial USM Anywhere Sensor on VMware consists of these primary tasks:- Review requirements for a VMware Sensor deployment.
- Deploy a VMware Sensor by executing the USM_sensor-node.ovf file.
- Configure the sensor on the VM.
- Register the new sensor with your sensor authentication code to provision the USM Anywhere instance and connect the deployed sensor.
- Complete your VMware Sensor configuration, including initial asset discovery.
