Cisco Umbrella to Azure Sentinel Integration

Alex 20 Reputation points
2023-09-19T17:00:10.31+00:00

I successfully connected Cisco Umbrella Connector to Azure Sentinel. However I'm not sure why the 2 data types are not connected ("Cisco_Umbrella_ip_CL" and "Cisco_Umbrella_cloudfirewall_CL").

User's image

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,123 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 32,316 Reputation points Microsoft Employee
    2023-09-22T04:14:17.5466667+00:00

    @Alex Discussed your issue with my team, so wanted to check couple of things

    • Are you sure that on Cisco Umbrella end, these logs are generated ("Cisco_Umbrella_ip_CL" and "Cisco_Umbrella_cloudfirewall_CL") ?
    • Another check could be to verify if the function that gathers those logs, has thrown some error?

    Let me know if you have any further questions, feel free to post back.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.