Overview
The Cisco integration covers multiple Cisco product lines through a single connector. Pick the source you want to collect from at configuration time:
| Source | Description |
|---|---|
umbrella |
Umbrella DNS, Proxy, Cloud Firewall, IP, and audit logs (via S3 bucket) |
meraki |
Meraki Dashboard event log and security events |
asa |
Cisco ASA syslog forwarded to a collector |
firepower |
Firepower Threat Defense events via FMC API |
secure_endpoint |
Cisco Secure Endpoint (AMP for Endpoints) events |
This page covers the most common case — Cisco Umbrella — and points to the credentials needed for the others.
Prerequisites — Cisco Umbrella
- A Cisco Umbrella account with Full Admin privileges.
- An S3 bucket configured under Admin → Log Management to receive Umbrella logs.
- The Access Key and Secret Key generated for that S3 bucket by Umbrella.
Step 1 (Umbrella): Enable log export to S3
- Sign in to the Cisco Umbrella dashboard.
- Go to Admin → Log Management.
- Choose Use Cisco-managed Amazon S3 (Umbrella creates and manages the bucket) or Use your own Amazon S3 bucket.
- Save the configuration. Umbrella displays the bucket name, region, access key, and secret key (or grants you the bucket policy if you supplied your own).
Step 2 (Umbrella): Connect Cisco in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the Cisco card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Source | Cisco product to ingest from. | umbrella |
| Access Key ID | S3 access key from Umbrella. | AKIA... |
| Secret Access Key | S3 secret key. | •••••••• |
| S3 Bucket | Bucket receiving Umbrella logs. | cisco-managed-us-east-1-... |
| Region | Bucket region. | us-east-1 |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Other Cisco sources
| Source | Credentials to supply |
|---|---|
| Meraki | Dashboard API key (under My Profile → API access) and Organization ID |
| ASA | Forward syslog to an Atatus log collector; no API credentials |
| Firepower | FMC hostname + admin username/password with API access |
| Secure Endpoint (AMP) | API Client ID + API Key (Accounts → API Credentials) |
The form fields shown above are replaced by the credentials appropriate to the source you select.
Verification
- The Cisco card shows Configured.
- Logs appear in Security → Cloud SIEM → Audit Logs → Events with source
cisco.
+1-415-800-4104