Share via

Cisco Umbrella to Azure Sentinel Integration

Alex 20 Reputation points
Sep 19, 2023, 5:00 PM

I successfully connected Cisco Umbrella Connector to Azure Sentinel. However I'm not sure why the 2 data types are not connected ("Cisco_Umbrella_ip_CL" and "Cisco_Umbrella_cloudfirewall_CL").

User's image

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,157 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 33,081 Reputation points Microsoft Employee
    Sep 22, 2023, 4:14 AM

    @Alex Discussed your issue with my team, so wanted to check couple of things

    • Are you sure that on Cisco Umbrella end, these logs are generated ("Cisco_Umbrella_ip_CL" and "Cisco_Umbrella_cloudfirewall_CL") ?
    • Another check could be to verify if the function that gathers those logs, has thrown some error?

    Let me know if you have any further questions, feel free to post back.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.