This article details how to ingest logs of Cisco Umbrella into Hunters XDR.

Supported APIs and data types

  • Proxy Logs: Shows HTTP traffic that has passed through an Umbrella proxy (either the Secure Web Gateway or Selectie Proxy). In addition to showing whether the traffic was blocked, it shows the size of the requests and a user agent.

    "2021-12-14 13:09:14","Kate","","","","text/plain","ALLOWED","URL","","Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/897.32 (KHTML, like Gecko) Chrome/12.0.842.32 Safari/987.22","235","","356","11","123ce97659ab9321098fe81728abbc9981588909","Business Services,Infrastructure","","","","","","Anyconnect Roaming Client",""
  • IP Logs: Similiar to Proxy Logs, just shows traffic that is handled by Umbrella's IP Layer Enforcement feature.

    "2021-12-07 15:53:43","LAPTOP-X","","2222","","3333","","Anyconnect Roaming Client"
  • DNS Logs: Shows DNS requests to Umbrella's DNS servers, can be used to identify known (and new!) malicious domains.

    "2021-12-14 12:29:52","Nick","Nick","","","Allowed","1 (A)","NOERROR","String","Application","Anyconnect Roaming Client","Anyconnect Roaming Client",""

Sending data to Hunters


In order to set up a S3 bucket for Umbrella's data, please follow this guide, and configure the bucket according to this tutorial.

More information about Cisco Umbrella's content and capabilities may be found here and for more ingestion relevant documentation here.

Creating a Data Flow

After you have configured an S3 bucket to be accessible by Hunters and started exporting your Umbrella logs, login into the Hunters Portal, go to the "Data Flows" section in the left bar, and click the "Add Data Flows" button.

  1. In the Product box, select Cisco Umbrella

  2. Paste the Role ARN from the setup tutorial in the Hunters' "Add Data Flow" wizard.

  3. For each data type, put down the bucket name, the prefix containing all the logs from that datatype (And only them), and choose the format CSV with no header

  4. Click the "Test Connection" button.

  5. After the test has passed, click the "Submit" button and the data flow will be created.