Documentation Center
AlienVault® USM Anywhere™

Collecting Logs from Cisco Umbrella

  Role Availability   Read-Only   Analyst   Manager

To fully integrate USM Anywhere with your Cisco Umbrella (formerly, OpenDNS) implementation, you should configure log collection so that USM Anywhere can retrieve and normalizeNormalization describes the translation of log file entries received from disparate types of monitored assets into the standardized framework of Event types and sub-types. raw log data from Cisco Umbrella. The combination of the Cisco Umbrella plugin and configuration of the AlienApp for Cisco Umbrella provides a full scope of data and analysis within USM Anywhere.

Note: Cisco Umbrella provides log retention for the mid (Insights) and top (Platform) tier product packages only. If you are using the lowest tier package (Professional), you cannot collect log data from Cisco Umbrella. For more information about the Cisco Umbrella product packages, refer to their website.

Important: By design, Cisco Umbrella will export log data only to an AWS S3 bucket. Because of this limitation, log collection requires a USM Anywhere Sensor deployed in an AWS account. However, you can use another deployed Sensor type to configure an AlienApp for Cisco Umbrella API connection to support response actions.

For more information about deploying an additional USM Anywhere Sensor in an AWS environment, see Adding an Additional Sensor for Other AWS Accounts.

S3 Log Management

Before the USM Anywhere can collect the Umbrella log data, you must set up Amazon S3 log management in your Cisco Umbrella deployment. This requires that you have an S3 bucket in an AWS account that is configured to accept uploads from the Umbrella Service. For detailed information about this configuration, refer to this article: https://support.umbrella.com/hc/en-us/articles/231248448-Cisco-Umbrella-Log-Management-in-Amazon-S3

To verify Amazon S3 log management in Cisco Umbrella

  1. Log into the Cisco Umbrella (OpenDNS) dashboard.
  2. Navigate to Settings > Log Management.
  3. Click Amazon S3.
  4. In the Bucket Name field, enter the exact S3 bucket name.
  5. Click Verify.

    A confirmation message in the dashboard will indicate that the bucket was successfully verified.

Scheduling Log Collection

After you verify that Cisco Umbrella is configured to send log data to an AWS S3 bucket for an account where you have a deployed USM Anywhere Sensor, you can set up a log collection job for USM Anywhere to retrieve that data.

Note: If you want to deploy a sensor to facilitate Cisco Umbrella log collection, see AWS Sensor Deployment.

To schedule Cisco Umbrella log collection

  1. Go to SETTINGS > SCHEDULER.
  2. In the left navigation list, click Log Collection.

    Note: You can use the Sensor filter at the top of the list to choose your AWS sensor to easily review the current AWS log jobs.

  3. Click Create Log Collection Job.

    Click Create Log Collection Job to add a scheduled log collection job

    Note: If you recently deployed a new Sensor, it can take 10 to 20 minutes for USM Anywhere to discover the various log sources. After it discovers the logs, you must manually enable the AWS log collection jobs you want before the system collects the log data.

  4. Enter the Name and Description for the job.

    The description is optional, but it is a best practice to provide this information so that others can easily understand what it does.

  5. For the Select App option, select Amazon Web Services.
  6. For the App Action option, select Monitor S3 bucket.

    Select the Monitor S3 Bucket app action

  7. In the Bucket Name field, enter the name of the S3 bucket that is configured in Cisco Umbrella log management.
  8. In the Path field, enter the path on the bucket where the logs reside (in this case, dnslogs/).
  9. For the Source Format option, select raw.
  10. For the Plugin option, select Cisco Umbrella.

    Set Monitor S3 Bucket options for collecting the Cisco Umbrella log data

  11. Set the Schedule to specify when USM Anywhere runs the job.

    First, choose the increment as Hour, Day, Week, Month, or Year. Next, set the interval options for the increment. The selected increment determines the available options.

    For example, on a weekly increment you can select the days of the week to run the job.

    Set the schedule for the job to run each week

    Or, on a monthly increment you can specify a date or a day of the week that occurs within the month.

    Set the schedule for the job to run each month

    To finish, set the Start time. This is the time that the job starts at the specified interval. It uses the time zone configured for your USM Anywhere instance (default is UTC).

  12. Click Save.

    You should start seeing new Cisco Umbrella events in USM Anywhere shortly after the initial raw log data collection and normalization.