Notifications
Clear all
Topic starter
19/07/2026 2:15 am
Hi everyone! 👋 I'm new to the security side of our SaaS stack and I've been tasked with getting our Cisco Umbrella SIG logs into Splunk. We already use Splunk for other app analytics, so it makes sense to have everything in one place.
I've seen the official docs, but they feel a bit high-level. Has anyone here done this integration recently? I'm particularly fuzzy on:
- The exact steps for configuring the log receiver in the Umbrella dashboard.
- Any gotchas with the Splunk TA for Umbrella (like timestamp parsing).
- How you structured the searches/dashboards once the data was flowing.
A real-world example of your log flow would be super helpful! Thanks!