Overview

The Cisco integration covers multiple Cisco product lines through a single connector. Pick the source you want to collect from at configuration time:

Source Description
umbrella Umbrella DNS, Proxy, Cloud Firewall, IP, and audit logs (via S3 bucket)
meraki Meraki Dashboard event log and security events
asa Cisco ASA syslog forwarded to a collector
firepower Firepower Threat Defense events via FMC API
secure_endpoint Cisco Secure Endpoint (AMP for Endpoints) events

This page covers the most common case — Cisco Umbrella — and points to the credentials needed for the others.


Prerequisites — Cisco Umbrella

  • A Cisco Umbrella account with Full Admin privileges.
  • An S3 bucket configured under Admin → Log Management to receive Umbrella logs.
  • The Access Key and Secret Key generated for that S3 bucket by Umbrella.

Step 1 (Umbrella): Enable log export to S3

  1. Sign in to the Cisco Umbrella dashboard.
  2. Go to Admin → Log Management.
  3. Choose Use Cisco-managed Amazon S3 (Umbrella creates and manages the bucket) or Use your own Amazon S3 bucket.
  4. Save the configuration. Umbrella displays the bucket name, region, access key, and secret key (or grants you the bucket policy if you supplied your own).

Step 2 (Umbrella): Connect Cisco in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the Cisco card and click Connect.
  3. Fill in the form:
Field Description Example
Source Cisco product to ingest from. umbrella
Access Key ID S3 access key from Umbrella. AKIA...
Secret Access Key S3 secret key. ••••••••
S3 Bucket Bucket receiving Umbrella logs. cisco-managed-us-east-1-...
Region Bucket region. us-east-1
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Other Cisco sources

Source Credentials to supply
Meraki Dashboard API key (under My Profile → API access) and Organization ID
ASA Forward syslog to an Atatus log collector; no API credentials
Firepower FMC hostname + admin username/password with API access
Secure Endpoint (AMP) API Client ID + API Key (Accounts → API Credentials)

The form fields shown above are replaced by the credentials appropriate to the source you select.


Verification

  • The Cisco card shows Configured.
  • Logs appear in Security → Cloud SIEM → Audit Logs → Events with source cisco.