↳ GitHub sourceConnector

Cisco Umbrella (via Codeless Connector Framework)

Description

The Cisco Cloud Security solution for Microsoft Sentinel enables you to ingest [Cisco Secure Access](https://securitydocs.cisco.com/secure-access-sub-landing-page) and [Cisco Umbrella](https://securitydocs.cisco.com/umbrella-sub-landing-page) logs stored in Cisco-managed Amazon S3 Bucket into Microsoft Sentinel using the Amazon S3 REST API. Refer to [Cisco Cloud Security log management documentation](https://securitydocs.cisco.com/docs/csa/olh/118897.dita) for more information.
Declared status
1
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Amazon S3 REST API Credentials/permissions
**AWS Access Key, AWS Secret Access Key, AWS S3 Bucket Name** are required for Amazon S3 REST API.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

1. Configuration of the Cisco Cloud Security Logs Collection
Add new collector
Add new collector
Account details
Data type
Admin Audit Logs
Cloud Firewall Logs
DLP Logs
DNS Logs
File Events Logs
IPS Logs
Remote Access VPN Logs
Web Logs
Zero Trust Access Logs
Zero Trust Access Flow Logs
Access Key
Secret Key
AWS S3 Bucket Name
AWS S3 Bucket Region
AWS S3 Bucket Prefix

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CiscoUmbrellaConnector
Additional source files 2Solutions/CiscoUmbrella/Data Connectors/CiscoUmbrella_CCP/CiscoUmbrella_DataConnectorDefinition.jsonsource ↗Solutions/CiscoUmbrella/Data/Solution_CiscoUmbrella.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.