Cisco Umbrella Out-of-the-Box Data Collection Integration

Cisco Umbrella Out-of-the-Box Data Collection Integration

To learn more about Out-of-the-box Integrations and their benefits, please refer to this article.

Requirements

  • A Cisco Umbrella DNS Security Essentials subscription or above
  • An active Lumu Defender Subscription

Setup Cisco Umbrella

Rest API Client

To interact with any of the Umbrella APIs, create an API Key in the Cisco Umbrella portal and use the credentials to obtain an access token for making requests. To do so, follow the steps bellow:

1. Login into Umbrella Console.

2. Navigate to Admin > API Keys.

3. Click on Add. Fill in the required data: API Key name and select Key Scope. For the integration to work with the least privileges, we recommend the scope of the following image.


4. Copy the API Key and Key Secret, these are required to setup the integration. Once you click on ACCEPT AND CLOSE, you will not be able to see the Key Secret.

Add Integration

1. Log in to you Lumu account through the Lumu Portal and navigate to the integrations screen.

2. Locate the Cisco Umbrella integration in the available apps area and click to add, then click to view details.

3. Familiarize yourself with the integration details available in the app description and click the button below to activate the integration.


4. To activate integration, add a Name and select the Label. It is always recommended to assign a label to organize and categorize the traffic of your organization. Click Next.

5. Fill in the required information, the API Key and the API Secret with the data collected before. Click Next.

The integration is now created and active. Now, the Lumu Portal will display the details of the created integration:


        • Related Articles

        • Cisco Umbrella Out-of-the-box Response Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. Requirements A Cisco Umbrella DNS Security Essentials subscription package or above Lumu Defender Subscription Setup Cisco Umbrella Rest API Client To ...
        • Lumu Out-of-the-box Integrations

          For getting started with Lumu integrations with third-party solutions, consult our Integrations guide. Lumu's Out-of-the-box (OOTB) integrations are a seamless and convenient way to integrate Lumu with other solutions in your cyberdefense stack to ...
        • Cisco Umbrella Custom Response Integration with Lumu Defender API

          Before going through this article, check our Out-of-the-box App Integrations category. This is the recommended way to integrate the components of your cybersecurity stack with Lumu. If the product you are looking to integrate is there, it is advised ...
        • AWS Out-of-the-Box Data Collection Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. In this article, you will find out how to configure Amazon Web Services (AWS) to pull and collect data from your network in the form of logs, and have ...
        • Kubernetes (K8s) Out-of-the-box Data Collection Integration

          To learn more about Out-of-the-box Integrations and their benefits, please refer to this article. In this article, you will find out how to configure your Kubernetes cluster to record and collect DNS data from your cluster network and have it sent to ...