Skip to main content

How to Integrate Cisco Umbrella

In this guide, we'll run through how to integrate Cisco Umbrella with the Defense.com SIEM platform.

Written by Kara Crimson
Updated over 2 weeks ago

This integration is available on our Advanced and Enterprise packages.

Before you get started

You will require the following before integrating Cisco Umbrella using a Cisco-managed S3 bucket.

  • Full administrative access to Cisco Umbrella.

Configuring your Cisco-managed S3 Bucket

  1. Navigate to Admin > Log Management and select Use a Cisco-managed Amazon S3 bucket.

  2. Select the Region eu-west-2 and a Retention Duration of 7 days.

  3. Click Save and then Continue to confirm your settings.

  4. Wait for Umbrella to activate its ability to export to an AWS S3 account. The Amazon S3 Summary page will appear when the activation is complete.

  5. Copy the data path, access key and secret key to a safe location. Make sure to save these now, as once you leave the page, you will no longer have access to them unless you regenerate the keys.

  6. Once the keys are copied and safe, select Got it and then click Continue.

Completing the integration

Once the above steps are complete, please create a ticket with our Technical Support team and provide the following information.

  • Data Path

  • Access Key

  • Secret Key

And that's it! You've successfully integrated Cisco Umbrella πŸŽ‰

Did this answer your question?