Skip to main content

Cisco Umbrella

Visualize Cisco Umbrella networks, domains, destinations, users, and discovered applications in the JupiterOne graph. Use this integration to also map Cisco Umbrella users to employees in your JupiterOne account and to monitor changes to Cisco Umbrella entities using JupiterOne alerts.

Installation

info

Cisco Umbrella uses OAuth 2.0 client credentials (API Key and Key Secret) to authenticate API requests. You need access to an account with permission to create API keys. You must also have permission in JupiterOne to install new integrations.

Configuration in Cisco Umbrella

  1. Sign in to Cisco Umbrella and navigate to Admin > API Keys.
  2. Create a new API key with the following minimum scopes (all Read-Only):
    • Admin — Roles, Users
    • Deployments
    • Policies — Destination Lists, Destinations
    • Reports — App Discovery
  3. Record the API Key and Key Secret values.
note

Network Tunnel data requires an active Cisco Umbrella SIG (Secure Internet Gateway) license. If your account does not have SIG enabled, the integration will skip network tunnel ingestion and log a warning — all other data types will still be collected.

Configuration in JupiterOne

To install the Cisco Umbrella integration in JupiterOne, navigate to the Integrations tab, select Cisco Umbrella, and click New Instance.

Creating an instance requires the following:

  • API Key — The Cisco Umbrella API key used for authentication.
  • Key Secret — The secret associated with the API key.

You can also set an optional Description and choose a Polling Interval for how often the integration runs. Leave the polling interval as DISABLED to trigger runs manually.

Click Create to save and activate the integration.

Next steps

After creating the instance, the integration will run on the polling interval you configured and populate data in JupiterOne. See the Instance management guide for more on managing integration instances.