↳ GitHub sourceConnector
Cisco Umbrella (via Codeless Connector Framework)
Description
The Cisco Cloud Security solution for Microsoft Sentinel enables you to ingest [Cisco Secure Access](https://securitydocs.cisco.com/secure-access-sub-landing-page) and [Cisco Umbrella](https://securitydocs.cisco.com/umbrella-sub-landing-page) logs stored in Cisco-managed Amazon S3 Bucket into Microsoft Sentinel using the Amazon S3 REST API. Refer to [Cisco Cloud Security log management documentation](https://securitydocs.cisco.com/docs/csa/olh/118897.dita) for more information.
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Amazon S3 REST API Credentials/permissions
**AWS Access Key, AWS Secret Access Key, AWS S3 Bucket Name** are required for Amazon S3 REST API.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
1. Configuration of the Cisco Cloud Security Logs Collection
Add new collector
Add new collector
Account details
Data type
Admin Audit Logs
Cloud Firewall Logs
DLP Logs
DNS Logs
File Events Logs
IPS Logs
Remote Access VPN Logs
Web Logs
Zero Trust Access Logs
Zero Trust Access Flow Logs
Access Key
Secret Key
AWS S3 Bucket Name
AWS S3 Bucket Region
AWS S3 Bucket Prefix
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
CiscoUmbrellaConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC