Cisco Umbrella Reporting
The Umbrella Reporting v2 API provides visibility into your core network and security activities and Umbrella logs.
- Category
- Network Security
- Pack
- CiscoUmbrellaReporting
Configuration parameters
- api_url — API URL (required)
- credentials — API Key (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (9)
- umbrella-reporting-activity-get — List all entries within a time frame based on the traffic type selected. Valid activity types are dns, proxy, firewall, intrusion, ip, amp. Only one activity type can be selected at a time.
- umbrella-reporting-activity-list — List all activity entries (dns/proxy/firewall/ip/intrusion/amp) within the time frame.
- umbrella-reporting-category-list — List of categories ordered by the number of requests made matching the categories in descending order.
- umbrella-reporting-destination-list — List of destinations ordered by the number of requests made in descending order.
- umbrella-reporting-event-type-list — List of event types ordered by the number of requests made for each type of event in descending order. The event types are: domain_security, domain_integration, url_security, url_integration, cisco_amp and antivirus.
- umbrella-reporting-file-list — List of files within a time frame. Only returns proxy data.
- umbrella-reporting-identity-list — List of identities ordered by the number of requests made matching the categories in descending order.
- umbrella-reporting-summary-list — Get the summary.
- umbrella-reporting-threat-list — List of top threats within a time frame. Returns both DNS and Proxy data.