Cisco Duo Telephony Logs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID CiscoDuoTelephonyConnectorDefinition
Publisher Cisco Systems, Inc.
Used in Solutions CiscoDuoSecurity
Collection Method CCF
Connector Definition Files CiscoDuoTelephony_ConnectorDefinition.json
DCR Definition Files CiscoDuoTelephony_DCR.json
CCF Configuration CiscoDuoTelephony_PollingConfig.json
CCF Capabilities CiscoDuo, Paging

The Cisco Duo Telephony Logs connector ingests SMS and phone-call authentication event data from the Cisco Duo Admin API into Microsoft Sentinel.

Telephony logs record every instance where Duo sends an SMS passcode or places a phone callback during an authentication, enrollment, or administrator bypass workflow. Each event includes the phone number, channel used (sms or phone), context, and number of telephony credits consumed.

Supports HMAC-based API Key authentication (Integration Key and Secret Key).

For more information, visit Cisco Duo Admin API Docs.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
DuoTelephony_CL ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Connect Cisco Duo Telephony Logs to Microsoft Sentinel

To enable the Cisco Duo Telephony Logs connector, provide your Duo Admin API credentials below.

  1. Log in to the Duo Admin Panel.
  2. Navigate to Applications > Protect an Application.
  3. Find Admin API and click Protect.
  4. Ensure the application has Grant read log permission enabled.
  5. Copy the Integration Key, Secret Key, and API Hostname and enter them below.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index