Skip to main content
Role AvailabilityRead-OnlyInvestigatorAnalystManager
With a USM Anywhere license, you can always view your subscription data in one place. Use the My Subscription page to access your license information, data, and raw log data; as well as connect to a instance.

Subscription Data

Go to Settings > My Subscription to open the page.
The table below lists the fields you see on the page. Information on the My Subscription page
FieldDescription
Consumed DataThe amount of data that USM Anywhere has processed every month
Projected Data ConsumptionThe amount of data already stored for the month plus calculated data storage needs for the rest of the month. See Projected Data Consumption for more information.
SensorsThe number of licensed sensors and pending deployment sensors. Click Manage Sensors to open the Sensors page. See Sensors Page Overview for more information.
EPSEvents per second in the last 24 hours
Filtered EPSPercentage of filtered EPS in the last 24 hours
Filtering RulesNumber of filtering rules in your environment. Click Manage Rules to open the Filtering Rules page. See Filtering Rules from the Orchestration Rules Page for more information.
FieldDescription
Data Consumption StatusThe health status of your subscription’s data consumption, reflecting real data consumption rates compared to your subscription tier over time: healthy, caution, warning, violation, or recovery. See Understanding Your Data Consumption Status for more information.
FieldDescription
License TypeRefers to either the trial or subscription license
Service TierRefers to the monthly storage limit. See the LevelBlue pricing page for details or to request a quote.

Important: Tier options do not have unlimited processing power, memory allotment, or disk input/output (I/O) speeds. In addition to storage per month, your deployment size’s impact on any of these factors will influence which tier option is right for your environment. LevelBlue recommends pre-deployment sizing discussions with your sales representative to help select the right tier for you.
License End DateRefers to either the trial expiration date (for trial licenses) or support end date (for subscription licenses). The displayed date depends on your computer’s time zone.
Cold StorageClick Manage Raw Logs to download the raw log files in zip format. See Raw Log Data for more information.

By default, cold storage is unlimited for USM Anywhere customers within their service terms; but limited for LevelBlue Threat Detection and Response for Government (LevelBlue TDR for Gov) customers for three years.

Remember the following:
- You can export raw logs for a 31-day month. However, you are limited to a 31-day span if the range exceeds a single month.
- The start time is 00:00:00 on the selected start date, and the end time is 23:59:59 on the selected end date. Example: If you select 1/1/2020 to 2/1/2020, the logs start at 00:00:00 1/1/2020 and end at 23:59:59 2/1/2020.
EmailRefers to the email address associated with your license.
MSSP StatusIndicates whether the USM Anywhere deployment has been successfully connected to a USM Central or not. See Connecting a USM Anywhere to a USM Central for more information.
MSSP ServiceName of the connected USM Central deployment
Historical Data ConsumptionRefers to a list of data consumption by month. Click Download CSV to download a file with this information.
Top Data SourcesDisplays a list of the top data sources. Click Download CSV to download a file with this information.
Top Event NamesList of the top event names related to their data source. Click Download CSV to download a file with this information.
Top Reporting DevicesList of top reporting devices. Click Download CSV to download a file with this information.

Raw Log Data

Raw log data is data that has been forwarded and collected through your sensors, agents, and Cloud Connectors. USM Anywhere stores this data and enables you to extract raw log data for audit purposes or further forensic analysis.
LevelBlue recommends that you download the raw log data on a monthly basis.When requesting raw log files, the date range cannot exceed 31 days. To download more than 31 days’ worth of data, you must make multiple requests. Refrain from making all requests at the same time, which may tie up your USM Anywhere instance. You can make two or three requests, wait for the emails to arrive, and then make your next requests.
To request and extract raw log data
  1. Go to Settings > My Subscription.
  2. Click Manage Raw Logs in the License Information section.
The Manage Cold Storage Raw Logs dialog box opens.
  1. Click Request Cold Storage Raw Logs.
    You may also download any of the previously requested cold storage raw logs, if any. Simply click the download icon.
  2. Click the dropdown to select a date range to download the raw log files (dates are in UTC). Once you have set the date, click Apply.
The start date cannot be earlier than your first day of storage. Furthermore, the date range cannot exceed 31 days.
  1. Click Request Cold Storage Raw Log. A message will be displayed indicating that a new request has been triggered, and the request will be displayed among the list of requests made. As the user who requested the raw logs, you will be sent an email to download the logs.
In the Manage Cold Storage Raw Logs dialog box, you can see your (latest) request at the top of the list with a Processing status. This changes to a download icon once it is ready for downloading.
  1. Click the link in the email to navigate to the Raw Logs Management page. Your list of log requests (as well as those of the other users if you are logged in as a Manager) is displayed.
    You need to be logged into USM Anywhere prior to clicking the link in your email. If you are not logged in, you will be prompted to log into the portal to navigate to the Raw Logs Management page.
  2. Click the download icon to download the log files. Select the path in which to save the logs, and the download process starts.
  3. Extract the zipped bundle, and you will see the files listed as forensics-YYYY-MM-DD.hh.log.gz, where YYYY-MM-DD.hh refers to the date and hour.
    Requested raw logs are only available for 72 hours from the time the logs are available. Any expired log will be removed from the list after an additional 72 hours from the time it expires. Should you click on the link after it has expired, you will be prompted to make a new request for the raw log.

Email Notifications Concerning Your License

USM Anywhere sends the following emails to the email address associated with your license. Typically, this is the email address used to register the trial or your subscription:
  • A license is changed from trial to subscription.
  • A license tier is upgraded.
  • A license expiration date is updated.
  • The number of sensors allowed is updated.
  • An activated license has expired.
  • An activated license is deleted.