Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | CiscoDuoTelephonyConnectorDefinition |
| Publisher | Cisco Systems, Inc. |
| Used in Solutions | CiscoDuoSecurity |
| Collection Method | CCF |
| Connector Definition Files | CiscoDuoTelephony_ConnectorDefinition.json |
| DCR Definition Files | CiscoDuoTelephony_DCR.json |
| CCF Configuration | CiscoDuoTelephony_PollingConfig.json |
| CCF Capabilities | CiscoDuo, Paging |
The Cisco Duo Telephony Logs connector ingests SMS and phone-call authentication event data from the Cisco Duo Admin API into Microsoft Sentinel.
Telephony logs record every instance where Duo sends an SMS passcode or places a phone callback during an authentication, enrollment, or administrator bypass workflow. Each event includes the phone number, channel used (sms or phone), context, and number of telephony credits consumed.
Supports HMAC-based API Key authentication (Integration Key and Secret Key).
For more information, visit Cisco Duo Admin API Docs.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
DuoTelephony_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Connect Cisco Duo Telephony Logs to Microsoft Sentinel
To enable the Cisco Duo Telephony Logs connector, provide your Duo Admin API credentials below.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊