This article leads you through the process of integrating Cisco Umbrella with Red Canary. Follow the procedure from beginning to end.
Step 1: Red Canary–Create a Red Canary email for alerts
Create a Red Canary provided-email to send Cisco Umbrella alerts for ingestion.
- From your Red Canary homepage, click Integrations.
- From the Integrations section, locate and then click the security product you want to integrate with Red Canary.
Note: If you do not see your security product listed, click See all integrations. - In the search bar, type and then select your third-party security source.
- Continue onto the next step by configuring your third-party security source in Red Canary.
Note: Your third-party security source may require that you contact Red Canary to configure. - Enter a Name for your external alert source.
- Select a Display Category.
- Under the Ingest Format/Method dropdown, select Cisco Umbrella via Email. (Please note that only Email should be selected for this alert source — see supported ingest methods here)
- Click Save Configuration. This will generate the email address you will use to send Cisco Umbrella alerts to.
- Click Edit Configuration.
- With your alert source configured, click Activate.
- With your Red Canary email generated, log in to Cisco Umbrella.
Step 2: Cisco Umbrella–Configure email alerts
Adjust your Cisco Umbrella settings to send generated alerts to your Red Canary-provided email.
- From your Cisco Umbrella dashboard, click the Reporting dropdown, and then click Scheduled Reports.
- Click +Schedule.
- Click Activity Search or Security Activity depending on the type of information you want to send to Red Canary.
- Select the type of information you want to include in your alert report.
- Enter the recommended configurations below:
- Response:
Blocked
- Event type:
Select All
- Response:
- When you have selected all of the filters for your alert report, click +Schedule.
- Review your filter selections, and then click Continue.
- Select a Delivery Schedule, and then click Continue.
Note: Red Canary recommends you select Daily for the Delivery Schedule. - Enter a Name for your Report Title.
- Enter the Red Canary email provided in Step 1.8.
- Click Save.
Comments
0 comments
Please sign in to leave a comment.