Cisco Umbrella Logs

Connecting Cisco Umbrella logs to your Panther Console

Overview

Panther supports ingesting Cisco Umbrellaarrow-up-right logs via common Data Transport options.

How to onboard Cisco Umbrella logs to Panther

To connect these logs into Panther:

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for “Cisco Umbrella,” then click its tile.

  4. In the Transport Mechanism drop-down, select the Data Transport method you wish to use for this integration. An arrow is drawn from a tile labeled "Cisco Umbrella" to a "Transport Mechanism" field. To its right is a "Start Setup" button.

  5. Click Start Setup.

  6. Follow Panther's instructions for configuring the selected Data Transport method, such as:

  7. Configure Cisco Umbrella to push logs to the Data Transport source. See Cisco Umbrella's documentationarrow-up-right for instructions on pushing logs to your selected Data Transport source.

Panther-managed detections

See Panther-managedarrow-up-right rules for Cisco Umbrella in the panther-analysis GitHub repositoryarrow-up-right.

Supported log types

CiscoUmbrella.CloudFirewall

Cloud Firewall logs show traffic that has been handled by network tunnels.

Reference: Cisco documentation on Log Formats and Versioningarrow-up-right

CiscoUmbrella.DNS

DNS logs show traffic that has reached our DNS resolvers.

Reference: Cisco documentation on DNS Logs.arrow-up-right

CiscoUmbrella.IP

IP logs show traffic that has been handled by the IP Layer Enforcement feature.

Reference: Cisco documentation on IP Logs.arrow-up-right

CiscoUmbrella.Proxy

Proxy logs show traffic that has passed through the Umbrella Secure Web Gateway (SWG) or the Selective Proxy.

Reference: Cisco documentation on Selection Proxy Logs.arrow-up-right

Last updated

Was this helpful?