Cisco Umbrella to Azure Sentinel Integration

Alex 20 Reputation points
2023-09-19T17:00:10.31+00:00

I successfully connected Cisco Umbrella Connector to Azure Sentinel. However I'm not sure why the 2 data types are not connected ("Cisco_Umbrella_ip_CL" and "Cisco_Umbrella_cloudfirewall_CL").

User's image

Microsoft Security Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 35,621 Reputation points Microsoft Employee Moderator
    2023-09-22T04:14:17.5466667+00:00

    @Alex Discussed your issue with my team, so wanted to check couple of things

    • Are you sure that on Cisco Umbrella end, these logs are generated ("Cisco_Umbrella_ip_CL" and "Cisco_Umbrella_cloudfirewall_CL") ?
    • Another check could be to verify if the function that gathers those logs, has thrown some error?

    Let me know if you have any further questions, feel free to post back.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.