# NG SIEM - CISCO Umbrella Integration

##### <span style="color: rgb(53, 152, 219);">**Introduction**</span>

<span style="color: rgb(0, 0, 0);">Cisco Umbrella is a cloud-delivered security platform that provides an additional layer of defense against malicious threats on the internet using Cisco’s threat intelligence. It helps block access to:</span>

- <span style="color: rgb(0, 0, 0);">**Malware**</span>
- <span style="color: rgb(0, 0, 0);">**Adware**</span>
- <span style="color: rgb(0, 0, 0);">**Botnets**</span>
- <span style="color: rgb(0, 0, 0);">**Phishing attacks**</span>
- <span style="color: rgb(0, 0, 0);">**Known malicious websites**</span>

##### <span style="color: rgb(53, 152, 219);">**Assumptions**</span>

<span style="color: rgb(0, 0, 0);">The procedures described in this guide assume that a Log Collector has already been set up.</span>

##### <span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

- <span style="color: rgb(0, 0, 0);">Full Admin access to Cisco Umbrella to create and manage Umbrella API keys.</span>
- <span style="color: rgb(0, 0, 0);">Umbrella API KeyAdmin access (if managing API key scopes and expirations).</span>

---

##### <span style="color: rgb(53, 152, 219);">**Requirements**</span>

<span style="color: rgb(0, 0, 0);">**This integration supports log ingestion from Cisco Umbrella. Data is collected from:**</span>

- <span style="color: rgb(0, 0, 0);">AWS S3 buckets using an SQS notification queue</span>
- <span style="color: rgb(0, 0, 0);">Cisco-managed S3 buckets without SQS</span>

##### <span style="color: rgb(53, 152, 219);">**Supported Dataset**</span>

- <span style="color: rgb(0, 0, 0);">log dataset: Collects Cisco Umbrella logs.</span>

---

##### <span style="color: rgb(53, 152, 219);">**Umbrella Logs**</span>

<span style="color: rgb(0, 0, 0);">**When using Cisco-managed S3 buckets without SQS:**</span>

- <span style="color: rgb(0, 0, 0);">Load balancing across multiple agents is not supported.</span>
- <span style="color: rgb(0, 0, 0);">A single agent must be configured to poll the S3 bucket.</span>
- <span style="color: rgb(0, 0, 0);">Vertical scaling can be applied by configuring the number of workers.</span>

<span style="color: rgb(0, 0, 0);">**The log dataset is responsible for collecting all Cisco Umbrella logs.**</span>

---

##### <span style="color: rgb(53, 152, 219);">**Advantages of the Umbrella API Integration**</span>

<span style="color: rgb(0, 0, 0);">**The Umbrella API introduces several improvements over older versions (v1 and Reporting v2 APIs):**</span>

- <span style="color: rgb(0, 0, 0);">Intuitive base URI</span>
- <span style="color: rgb(0, 0, 0);">API paths defined by top-level scopes</span>
- <span style="color: rgb(0, 0, 0);">Granular, intent-based API key scopes</span>
- <span style="color: rgb(0, 0, 0);">API key expiration support</span>
- <span style="color: rgb(0, 0, 0);">Updated API administration dashboard</span>
- <span style="color: rgb(0, 0, 0);">Programmatic API key administration</span>
- <span style="color: rgb(0, 0, 0);">Authentication &amp; authorization via OAuth 2.0 client credentials flow</span>
- <span style="color: rgb(0, 0, 0);">Portable, programmable API interface for integrations</span>

<span style="color: rgb(0, 0, 0);"> **Before sending requests to the Umbrella API, create Umbrella API credentials and generate an access token.**</span>  
<span style="color: rgb(0, 0, 0);">**More details: <span style="color: rgb(132, 63, 161);">[Cisco Umbrella API Authentication](https://developer.cisco.com/docs/cloud-security/authentication/#authentication)</span>** </span>

---

##### <span style="color: rgb(53, 152, 219);">**Authentication**</span>

- <span style="color: rgb(0, 0, 0);">The Umbrella API provides a **REST interface**.</span>
- <span style="color: rgb(0, 0, 0);">Supports **OAuth 2.0 client credentials flow**.</span>

<span style="color: rgb(0, 0, 0);">**Steps:**</span>

1. <span style="color: rgb(0, 0, 0);">Log in to Umbrella at: <span style="color: rgb(132, 63, 161);">**[https://dashboard.umbrella.com](https://dashboard.umbrella.com/)**</span></span>
2. <span style="color: rgb(0, 0, 0);">Create a new **API Key (ID + Secret)**.</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Keys can only be copied once at creation.</span>
    - <span style="color: rgb(0, 0, 0);">Lost secrets cannot be retrieved.</span>
3. <span style="color: rgb(0, 0, 0);">Generate an **API Access Token** using your credentials.</span>

<p class="callout warning"><span style="color: rgb(0, 0, 0);"> **Important:** API keys, passwords, and tokens grant access to private customer data. **Never share them** with external users or organizations.</span></p>

---

##### <span style="color: rgb(53, 152, 219);">**Managing Umbrella API Keys**</span>

<span style="color: rgb(0, 0, 0);">**Create a New API Key**</span>

1. <span style="color: rgb(0, 0, 0);">Navigate to **Admin &gt; API Keys**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">For MSP/MSSP: **Console Settings &gt; API Keys**</span>
2. <span style="color: rgb(0, 0, 0);">Click **Add Key**.</span>
3. <span style="color: rgb(0, 0, 0);">Enter a **Name** (≤256 characters) and optional **Description**.</span>
4. <span style="color: rgb(0, 0, 0);">Select **Scopes** (Read-Only or Read/Write).</span>
5. <span style="color: rgb(0, 0, 0);">Configure an **Expiry Date** (or select *Never Expire*).</span>
6. <span style="color: rgb(0, 0, 0);">(Optional) Add **Network Restrictions** (up to 10 public IPs or CIDRs).</span>
7. <span style="color: rgb(0, 0, 0);">Click **Create Key** → Copy and save **Key + Secret**.</span>

<span style="color: rgb(0, 0, 0);">**Refresh an API Key**</span>

1. <span style="color: rgb(0, 0, 0);">Go to **Admin &gt; API Keys**.</span>
2. <span style="color: rgb(0, 0, 0);">Expand the target key → Click **Refresh Key**.</span>
3. <span style="color: rgb(0, 0, 0);">Copy and save the new **Key + Secret**.</span>

<span style="color: rgb(0, 0, 0);">**Update an API Key**</span>

1. <span style="color: rgb(0, 0, 0);">Expand an existing key.</span>
2. <span style="color: rgb(0, 0, 0);">Update **Name, Description, Scopes, Expiry, or Network Restrictions**.</span>
3. <span style="color: rgb(0, 0, 0);">Click **Save**.</span>

---

<p class="callout warning"><span style="color: rgb(0, 0, 0);">To integrate Cisco Umbrella logs into AQUILA, provide the following details to **CyTech Support**:</span></p>

- <span style="color: rgb(0, 0, 0);">**Queue URL**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">AWS SQS queue URL where messages will be received.</span>
    - <span style="color: rgb(0, 0, 0);">For Cisco-managed S3 without SQS, use **Bucket ARN** instead.</span>
- <span style="color: rgb(0, 0, 0);">**Bucket ARN**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Required for Cisco-managed S3.</span>
    - <span style="color: rgb(0, 0, 0);">Example: `arn:aws:s3:::cisco-managed-eu-central-1`</span>
    - **<span style="color: rgb(132, 63, 161);">[List of Cisco-managed S3 buckets](https://docs.umbrella.com/mssp-deployment/docs/enable-logging-to-a-cisco-managed-s3-bucket)</span>**
- <span style="color: rgb(0, 0, 0);">**Bucket Region**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">The AWS region where the bucket is located.</span>
- <span style="color: rgb(0, 0, 0);">**Bucket List Prefix**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">The root folder of the S3 bucket to be monitored (visible in the S3 UI).</span>
    - <span style="color: rgb(0, 0, 0);">Example: `1235_654vcasd23431e5dd6f7fsad457sdf1fd5`</span>
- <span style="color: rgb(0, 0, 0);">**Number of Workers**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Number of workers to process S3 objects (min = 1).</span>
- <span style="color: rgb(0, 0, 0);">**Bucket List Interval**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Time interval for polling the S3 bucket. Default = 120s.</span>
- <span style="color: rgb(0, 0, 0);">**Access Key ID**</span>
- <span style="color: rgb(0, 0, 0);">**Secret Access Key**</span>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"><span style="color: rgb(53, 152, 219);"> </span>for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>