AQUILA - CISCO Umbrella Integration

Introduction

Cisco Umbrella is a cloud-delivered security platform that provides an additional layer of defense against malicious threats on the internet using Cisco’s threat intelligence. It helps block access to:

Assumptions

The procedures described in this guide assume that a Log Collector has already been set up.

Prerequisites

Requirements

This integration supports log ingestion from Cisco Umbrella. Data is collected from:

Supported Dataset

Umbrella Logs

When using Cisco-managed S3 buckets without SQS:

The log dataset is responsible for collecting all Cisco Umbrella logs.


Advantages of the Umbrella API Integration

The Umbrella API introduces several improvements over older versions (v1 and Reporting v2 APIs):

 Before sending requests to the Umbrella API, create Umbrella API credentials and generate an access token.
More details: Cisco Umbrella API Authentication


Authentication

Steps:

  1. Log in to Umbrella at: https://dashboard.umbrella.com

  2. Create a new API Key (ID + Secret).

    • Keys can only be copied once at creation.

    • Lost secrets cannot be retrieved.

  3. Generate an API Access Token using your credentials.

 Important: API keys, passwords, and tokens grant access to private customer data. Never share them with external users or organizations.


Managing Umbrella API Keys

Create a New API Key

  1. Navigate to Admin > API Keys

    • For MSP/MSSP: Console Settings > API Keys

  2. Click Add Key.

  3. Enter a Name (≤256 characters) and optional Description.

  4. Select Scopes (Read-Only or Read/Write).

  5. Configure an Expiry Date (or select Never Expire).

  6. (Optional) Add Network Restrictions (up to 10 public IPs or CIDRs).

  7. Click Create Key → Copy and save Key + Secret.

Refresh an API Key

  1. Go to Admin > API Keys.

  2. Expand the target key → Click Refresh Key.

  3. Copy and save the new Key + Secret.

Update an API Key

  1. Expand an existing key.

  2. Update Name, Description, Scopes, Expiry, or Network Restrictions.

  3. Click Save.


To integrate Cisco Umbrella logs into AQUILA, provide the following details to CyTech Support:

If you need further assistance, kindly contact support@cytechint.com for prompt assistance and guidance. 


Revision #2
Created 3 October 2025 12:59:12 by Richmond Abella
Updated 3 October 2025 13:33:50 by Richmond Abella