CiscoUmbrellaZeroTrustAccessFlow_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (28 columns)

Source: Connector definition

Column Name Type Description
AppConnectorGroupId string The group ID of the App Connector.
AppConnectorId string The ID of the App Connector.
ConnectionFailureReason string The error codes for failed connection requests.
ConnectionStatus string The status of the request to connect to the private resource. Valid values are: Connected, Reset, Terminated, or Unknown.
EgressIp string The egress IP address is not included in the flow logs and appears as empty. However, it can be found in the ZTA logs using the same transaction ID.
EgressPort string The egress port number of the network where the request originated.
EnforcedBy string The Secure Access component or service that enforced the policy or control related to this event (e.g., Firewall, Web Proxy).
EventType string The type of flow event.
FtdEnforcementId string The unique identifier of the enforcement action taken by a Firepower Threat Defense (FTD) device integrated with Secure Access.
FtdEnforcementName string The name or type of enforcement action taken by a FTD device integrated with Secure Access (e.g., Malware Block, URL Category Block).
HeadendType string The type of the headend. Valid values are: CLAP or BAP.
HostName string The hostname of the user device.
IdentityEmail string The email address of the Active Directory user.
IdentityLabels string The list of labels for the identity.
IdentityTypeLabels string The label of the identity type.
MspOrganizationId string The Secure Access organization ID of the parent managed service provider.
NtGroupId string The tunnel ID associated with this request.
OrganizationId string The Secure Access organization ID.
PrivateResourceGroupId string The ID if the rule matched is based on the private application group.
PrivateResourceId string The ID that Secure Access assigns to the customer-defined private application.
RuleId string The ID of the access rule.
RulesetId string The ID of the ruleset.
RxBytes string The number of bytes received during the session.
TimeGenerated datetime
Timestamp string The date and time of the ZTA event, expressed as a UTC-formatted string.
TransactionId string Universally unique identifier (UUID) of the transaction associated with the event.
TxBytes string The number of bytes transmitted or sent during the session.
ZtaSourcePort string The port number used by the Zero Trust proxy service to connect to an unmanaged device requesting a connection to a private resource.

Solutions (1)

This table is used by the following solutions:

Connectors (3)

This table is ingested by the following connectors:

Connector Selection Criteria
Cisco Umbrella (via Codeless Connector Framework)
Cisco Cloud Security
Cisco Cloud Security (using elastic premium plan)

Content Items Using This Table (21)

Analytic Rules (10)

GitHub Only:

Analytic Rule Selection Criteria
Cisco Cloud Security - Connection to Unpopular Website Detected
Cisco Cloud Security - Connection to non-corporate private network
Cisco Cloud Security - Crypto Miner User-Agent Detected
Cisco Cloud Security - Empty User Agent Detected
Cisco Cloud Security - Hack Tool User-Agent Detected
Cisco Cloud Security - Rare User Agent Detected
Cisco Cloud Security - Request Allowed to harmful/malicious URI category
Cisco Cloud Security - Request to blocklisted file type
Cisco Cloud Security - URI contains IP address
Cisco Cloud Security - Windows PowerShell User-Agent Detected

Hunting Queries (10)

In solution CiscoUmbrella:

Hunting Query Selection Criteria
Cisco Cloud Security - 'Blocked' User-Agents.
Cisco Cloud Security - Anomalous FQDNs for domain
Cisco Cloud Security - DNS Errors.
Cisco Cloud Security - DNS requests to unreliable categories.
Cisco Cloud Security - High values of Uploaded Data
Cisco Cloud Security - Higher values of count of the Same BytesIn size
Cisco Cloud Security - Possible connection to C2.
Cisco Cloud Security - Possible data exfiltration
Cisco Cloud Security - Proxy 'Allowed' to unreliable categories.
Cisco Cloud Security - Requests to uncategorized resources

Workbooks (1)

In solution CiscoUmbrella:

Workbook Selection Criteria
CiscoUmbrella

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
Cisco_Umbrella CiscoUmbrella

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index