Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | CiscoDuoActivityConnectorDefinition |
| Publisher | Cisco Systems, Inc. |
| Used in Solutions | CiscoDuoSecurity |
| Collection Method | CCF |
| Connector Definition Files | CiscoDuoActivity_ConnectorDefinition.json |
| DCR Definition Files | CiscoDuoActivity_DCR.json |
| CCF Configuration | CiscoDuoActivity_PollingConfig.json |
| CCF Capabilities | CiscoDuo, Paging |
The Cisco Duo Activity Logs connector ingests admin and user activity log data from the Cisco Duo Admin API into Microsoft Sentinel.
Activity logs capture admin panel actions such as user creation, modification, deletion, admin logins, and configuration changes.
Supports HMAC-based API Key authentication (Integration Key and Secret Key).
For more information, visit Cisco Duo Admin API Docs.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
DuoActivity_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connect Cisco Duo Activity Logs to Microsoft Sentinel
To enable the Cisco Duo Activity Logs connector, provide your Duo Admin API credentials below.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊