> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Subscription Management

|                       |               |                  |             |             |
| --------------------- | ------------- | ---------------- | ----------- | ----------- |
| **Role Availability** | **Read-Only** | **Investigator** | **Analyst** | **Manager** |

With a USM Anywhere license, you can always view your subscription data in one place. Use the **My Subscription** page to access your license information, <Tooltip tip="Any traffic or data exchange detected by LevelBlue products through a sensor or external devices such as a firewall.">event</Tooltip> data, and raw log data; as well as connect to a <Tooltip tip="A federation console that enables centralized security monitoring for multiple LevelBlue USM Anywhere and LevelBlue USM Appliance deployments.">USM Central</Tooltip> instance.

## Subscription Data

Go to **Settings > My Subscription** to open the page.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/3onSl9Btf_NxCVCb/images/usm-anywhere/healthy-my-subscription-page.webp?fit=max&auto=format&n=3onSl9Btf_NxCVCb&q=85&s=79ff2f9378633d501e4d7746e91729e2" alt="" width="1738" height="756" data-path="images/usm-anywhere/healthy-my-subscription-page.webp" />
</Frame>

The table below lists the fields you see on the page.

**Information on the My Subscription page**

<AccordionGroup>
  <Accordion title="License Usage" iconType="regular">
    | Field                      | Description                                                                                                                                                                                                                                                        |
    | -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
    | Consumed Data              | The amount of data that USM Anywhere has processed every month                                                                                                                                                                                                     |
    | Projected Data Consumption | The amount of data already stored for the month plus calculated data storage needs for the rest of the month. See [Projected Data Consumption](/documentation/usm-anywhere/user-guide/subscription-management/projected-data-consumption) for more information.    |
    | Sensors                    | The number of licensed sensors and pending deployment sensors. Click **Manage Sensors** to open the **Sensors** page. See [Sensors Page Overview](/documentation/usm-anywhere/user-guide/sensor-management/sensors-navigation) for more information.               |
    | EPS                        | Events per second in the last 24 hours                                                                                                                                                                                                                             |
    | Filtered EPS               | Percentage of filtered EPS in the last 24 hours                                                                                                                                                                                                                    |
    | Filtering Rules            | Number of filtering rules in your environment. Click **Manage Rules** to open the **Filtering Rules** page. See [Filtering Rules from the Orchestration Rules Page](/documentation/usm-anywhere/user-guide/rules-management/filtering-rules) for more information. |
  </Accordion>

  <Accordion title="Data Consumption Status" iconType="regular">
    | Field                   | Description                                                                                                                                                                                                                                                                                                                                                   |
    | ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Data Consumption Status | The health status of your subscription's data consumption, reflecting real data consumption rates compared to your subscription tier over time: healthy, caution, warning, violation, or recovery. See [Understanding Your Data Consumption Status](/documentation/usm-anywhere/user-guide/subscription-management/subscription-status) for more information. |
  </Accordion>

  <Accordion title="License Information" iconType="regular">
    | Field                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
    | --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | License Type                | Refers to either the trial or subscription license                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
    | Service Tier                | Refers to the monthly storage limit. See the LevelBlue pricing page for details or to request a quote.<br /><br />***Important***: Tier options do not have unlimited processing power, memory allotment, or disk input/output (I/O) speeds. In addition to storage per month, your deployment size's impact on any of these factors will influence which tier option is right for your environment. LevelBlue recommends pre-deployment sizing discussions with your sales representative to help select the right tier for you.                                                                                                                                                                                                                                                                                                              |
    | License End Date            | Refers to either the trial expiration date (for trial licenses) or support end date (for subscription licenses). The displayed date depends on your computer's time zone.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
    | Cold Storage                | Click **Manage Raw Logs** to download the raw log files in zip format. See [Raw Log Data](/documentation/usm-anywhere/user-guide/subscription-management/my-subscription) for more information.<br /><br />By default, cold storage is unlimited for USM Anywhere customers within their service terms; but limited for LevelBlue Threat Detection and Response for Government (LevelBlue TDR for Gov) customers for three years. <br /><br />Remember the following:  <br />- You can export raw logs for a 31-day month. However, you are limited to a 31-day span if the range exceeds a single month. <br />- The start time is 00:00:00 on the selected start date, and the end time is 23:59:59 on the selected end date. Example: If you select 1/1/2020 to 2/1/2020, the logs start at 00:00:00 1/1/2020 and end at 23:59:59 2/1/2020. |
    | Email                       | Refers to the email address associated with your license.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
    | MSSP Status                 | Indicates whether the USM Anywhere deployment has been successfully connected to a USM Central or not. See [Connecting a USM Anywhere to a USM Central](/documentation/usm-anywhere/user-guide/subscription-management/connection-usm-central) for more information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
    | MSSP Service                | Name of the connected USM Central deployment                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
    | Historical Data Consumption | Refers to a list of data consumption by month. Click **Download CSV** to download a file with this information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
    | Top Data Sources            | Displays a list of the top data sources. Click **Download CSV** to download a file with this information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
    | Top Event Names             | List of the top event names related to their data source. Click **Download CSV** to download a file with this information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | Top Reporting Devices       | List of top reporting devices. Click **Download CSV** to download a file with this information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
  </Accordion>
</AccordionGroup>

## Raw Log Data

Raw log data is data that has been forwarded and collected through your sensors, agents, and Cloud Connectors. USM Anywhere stores this data and enables you to extract raw log data for audit purposes or further forensic analysis.

<Warning>
  LevelBlue recommends that you download the raw log data on a monthly basis.

  When requesting raw log files, the date range cannot exceed 31 days. To download more than 31 days' worth of data, you must make multiple requests. Refrain from making all requests at the same time, which may tie up your USM Anywhere instance. You can make two or three requests, wait for the emails to arrive, and then make your next requests.
</Warning>

**To request and extract raw log data**

1. Go to **Settings > My Subscription.**
2. Click **Manage Raw Logs** in the **License Information** section.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/kngwAgUImaCaq5lO/images/usm-anywhere/ManageLogs1.png?fit=max&auto=format&n=kngwAgUImaCaq5lO&q=85&s=0711623ff9335438ab6ab33338a487e1" alt="" width="380" height="437" data-path="images/usm-anywhere/ManageLogs1.png" />
</Frame>

The **Manage Cold Storage Raw Logs** dialog box opens.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/qv4Xy092NDazIw22/images/usm-anywhere/ManageColdStorageLogs1.png?fit=max&auto=format&n=qv4Xy092NDazIw22&q=85&s=d0f8dde275d409252ff9d23eea651249" alt="" width="888" height="571" data-path="images/usm-anywhere/ManageColdStorageLogs1.png" />
</Frame>

3. Click **Request Cold Storage Raw Logs**.

   <Tip>
     You may also download any of the previously requested cold storage raw logs, if any. Simply click the download icon.
   </Tip>
4. Click the dropdown to select a date range to download the raw log files (dates are in UTC). Once you have set the date, click **Apply**.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/1WG_ctWjL5Tuf1AM/images/usm-anywhere/RequestLogs.png?fit=max&auto=format&n=1WG_ctWjL5Tuf1AM&q=85&s=6a85de2ad3a23f524fa2107a2d732158" alt="" width="726" height="232" data-path="images/usm-anywhere/RequestLogs.png" />
</Frame>

<Note>
  The start date cannot be earlier than your first day of storage. Furthermore, the date range cannot exceed 31 days.
</Note>

5. Click **Request Cold Storage Raw Log**. A message will be displayed indicating that a new request has been triggered, and the request will be displayed among the list of requests made.

   As the user who requested the raw logs, you will be sent an email to download the logs.

<Note>
  In the **Manage Cold Storage Raw Logs** dialog box, you can see your (latest) request at the top of the list with a **Processing** status. This changes to a download icon once it is ready for downloading.

  /
</Note>

6. Click the link in the email to navigate to the **Raw Logs Management** page. Your list of log requests (as well as those of the other users if you are logged in as a Manager) is displayed.

   <Note>
     You need to be logged into USM Anywhere prior to clicking the link in your email. If you are not logged in, you will be prompted to log into the portal to navigate to the **Raw Logs Management** page.
   </Note>
7. Click the download icon to download the log files. Select the path in which to save the logs, and the download process starts.
8. Extract the zipped bundle, and you will see the files listed as `forensics-YYYY-MM-DD.hh.log.gz`, where *YYYY-MM-DD.hh* refers to the date and hour.

   <Warning>
     Requested raw logs are only available for **72 hours** from the time the logs are available. Any expired log will be removed from the list after an additional 72 hours from the time it expires. Should you click on the link after it has expired, you will be prompted to make a new request for the raw log.
   </Warning>

   <Note>
     You are able to access, request, and download cold storage raw logs as long as your license is valid. When your license expires, you will lose access to USM Anywhere, including your data in it. You have a 14-day grace period to renew your subscription; during which time your raw logs are kept by LevelBlue although no data will be collected until your license is renewed.
   </Note>

## Email Notifications Concerning Your License

USM Anywhere sends the following <Tooltip tip="Communication of an important event, typically through an email message or other desktop display. In USM Appliance, notifications are typically triggered by events, policies, and correlation directives, and in USM Anywhere, they are typically triggered by notification rules or directly from alarms.">notification</Tooltip> emails to the email address associated with your license. Typically, this is the email address used to register the trial or your subscription:

* A license is changed from trial to subscription.
* A license tier is upgraded.
* A license expiration date is updated.
* The number of sensors allowed is updated.
* An activated license has expired.
* An activated license is deleted.
