Document toolboxDocument toolbox

sig.cisco

Introduction

The tags beginning with sig.cisco identify events generated by Cisco Umbrella Secure Internet Gateway (SIG) belonging to Cisco.

Valid tags and data tables 

The full tag must have at least 3 levels. The first two are fixed as sig.cisco. The third level identifies the type of events sent and the fourth indicates the event subtype.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

Cisco Umbrella Secure Internet Gateway (SIG)

sig.cisco.umbrella

sig.cisco.umbrella

sig.cisco.umbrella.audit

sig.cisco.umbrella.audit

sig.cisco.umbrella.dlp

sig.cisco.umbrella.dlp

sig.cisco.umbrella.dns

sig.cisco.umbrella.dns

sig.cisco.umbrella.firewall

sig.cisco.umbrella.firewall

sig.cisco.umbrella.intrusion

sig.cisco.umbrella.intrusion

sig.cisco.umbrella.ip

sig.cisco.umbrella.ip

sig.cisco.umbrella.proxy

sig.cisco.umbrella.proxy

For more information, read more About Devo tags.

Table structure

These are the fields displayed in these tables: