Loading

Cisco Umbrella Integration

Stack 9.0.0 Serverless Observability Serverless Security

Version 1.32.0 (View all)
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic
Ingestion method(s) AWS S3

This integration is for Cisco Umbrella. It includes the following datasets for receiving logs from an AWS S3 bucket using an SQS notification queue and Cisco Managed S3 bucket without SQS:

  • log dataset: supports Cisco Umbrella logs.

This integration supports the log schema version 8 and 9.

To start collecting logs from Cisco Umbrella, you need to configure an S3 bucket where the logs will be exported. Depending on your setup, you can choose between a Cisco-managed or a self-managed S3 bucket.

Note

Make sure to disable the Include Optional Log Headers in S3 Export toggle to prevent optional headers from appearing in the S3 log management report. Refer to the reference documentation for details.

When using Cisco Managed S3 buckets that do not use SQS; there is no load balancing for multiple agents. A single agent should be configured to poll the S3 bucket for new and updated files, and the number of workers can be configured to scale vertically.

The log dataset collects Cisco Umbrella logs.

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.