> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# User Behavior Analytics

User behavior analytics (UBA) extends your USM Anywhere Sensor's awareness by enabling it to track actors as well as assets within your environment. With UBA, USM Anywhere can help you identify malicious or compromised <Tooltip tip="In UBA, users are the authenticated people (or service accounts) taking actions in your environment.">users</Tooltip>, and enable you to better prioritize <Tooltip tip="Alarms provide notification of an event or sequence of events that require attention or investigation.">alarms</Tooltip> with the addition of user data.

In addition to analyzing users, UBA also analyzes each of a user's separate accounts, and enables you to manually combine detected users to ensure that your user analytics are accurate. <Tooltip tip="Any traffic or data exchange detected by LevelBlue products through a sensor or external devices such as a firewall.">Events</Tooltip> and alarms can thus be enhanced with user data, including user entities and their individual accounts, as either the source user or the destination user.

To incorporate UBA into your USM Anywhere instance, you must provide information about all users acting in your environment. Each user must be identified by a unique username and account type.

Once users have been identified, there are several tasks that you must complete to ensure that complete and actionable data is being captured and acted upon. This chapter describes these necessary tasks, and covers topics such as user discovery and merging, user scans, user <Tooltip tip="Process of collecting all device status and event information and processing normalized events for evidence of vulnerabilities, possible attacks, and other malicious activity.">monitoring</Tooltip>, and configuration.

This topic discusses these subtopics:

[User List View](user-list-view)

[User Discovery](managing-users)

[Understanding User Status in User Data Sources](user-status-in-data-sources)

[Viewing Full User Details](full-user-details)

[Events, Alarms, and Notifications Created When a User's Status Changes](user-state-events-and-alarms)

[Merging Users](merging-users)

[Deleting Users](deleting-users)

[Importing Users from a CSV File](csv-user-import)
