Configure Cisco Umbrella for Arctic Wolf monitoring

You can configure Cisco Umbrella® to send the necessary logs to Arctic Wolf® for security monitoring.

Note:

If you use the legacy Cisco Umbrella monitoring setup, which forwards Cisco Umbrella logs to Arctic Wolf from an Amazon Web Services (AWS) Simple Storage Service (S3) bucket:

  • Arctic Wolf recommends completing these configuration steps to initiate your migration to an API-based Cisco Umbrella cloud sensor.
  • Generate new Umbrella Reporting API credentials, after which Arctic Wolf receives no Cisco Umbrella logs from your S3 bucket until you provision these credentials to Arctic Wolf and the status of your new Cisco Umbrella account in the MDR Dashboard changes to Healthy.

Create your Cisco Umbrella credentials

  1. Sign in to the Cisco Umbrella console with administrator permissions.
  2. In the navigation menu, click Admin > Log Management.
  3. In the Data Storage section, note the region for the data storage.

    You will provide this value to Arctic Wolf later.

  4. If you are:
    • An MSP customer — On the end-customer Cisco Umbrella configuration page, in the navigation menu, click Console Settings > API Keys.
    • Not an MSP customer — In the navigation menu, click Admin > API Keys.
  5. Click API Keys.
  6. Click Add, and then configure these settings:
    • Name — Enter a name for your API key.
    • Key Scope — Select the Reports checkbox.
    • Reports — Select Read-Only from the list.
    • Expiry Date — Select an expiry date that aligns with your needs.
  7. Click Create Key.
  8. Copy the API Key, Key Secret, and Organization ID values, and then save them in a safe, encrypted location.

    You will provide these values to Arctic Wolf later.

    Note:
    • The Key Secret value is only displayed one time during API key creation and must be saved at this time.
    • The Organization ID is the integer value in your Cisco Umbrella console URL. For example, if your Cisco Umbrella console URL is https://dashboard.umbrella.com/o/1111111, then your organization ID is 1111111.

Provide Cisco Umbrella credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Cisco Umbrella API V2.
  5. Configure these settings:
  6. Click Test and submit credentials.