<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Access: Alert Notifications Webhook in Secure Access Discussions</title>
    <link>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5549065#M172</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1787903"&gt;@cludwigd&lt;/a&gt;&amp;nbsp;thanks so much for confirming this and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/426559"&gt;@Yaron Caspy&lt;/a&gt;&amp;nbsp;for vendor-verification.&amp;nbsp; How might partners get line of sight to the timeline for enabling token-based authorization, i.e. Bearer or Hash-based Message Authentication (HMAC), as we don't support use f basic authentication for Webhooks.&amp;nbsp; I've seen similar basic auth only support for Catalyst SD-WAN.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2026 13:04:09 GMT</pubDate>
    <dc:creator>Prodrick</dc:creator>
    <dc:date>2026-04-29T13:04:09Z</dc:date>
    <item>
      <title>Secure Access: Alert Notifications Webhook</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5546167#M168</link>
      <description>&lt;P&gt;In the documentation, the UI shows Secure Access Webhooks has three authentication options:&lt;/P&gt;&lt;P&gt;&amp;nbsp;basic&lt;/P&gt;&lt;P&gt;oauth&lt;/P&gt;&lt;P&gt;token&lt;/P&gt;&lt;P&gt;but one of the documentation pages says it only supports Basic authentication. &amp;nbsp;Who can confirm if Bearer token authentication is supported now?&lt;/P&gt;&lt;P&gt;&lt;A href="https://securitydocs.cisco.com/docs/csa/olh/161062.dita" target="_blank" rel="noopener"&gt;https://securitydocs.cisco.com/docs/csa/olh/161062.dita&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 11:46:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5546167#M168</guid>
      <dc:creator>Prodrick</dc:creator>
      <dc:date>2026-04-17T11:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Access: Alert Notifications Webhook</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5548310#M169</link>
      <description>&lt;P&gt;Anyone?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 10:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5548310#M169</guid>
      <dc:creator>Prodrick</dc:creator>
      <dc:date>2026-04-27T10:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Access: Alert Notifications Webhook</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5548358#M170</link>
      <description>&lt;P&gt;only basic is available configuration wise at this moment.&lt;BR /&gt;oauth and token is greyed out for me in GUI.&amp;nbsp;&lt;BR /&gt;we are currently testing the SA webhook alerting in parallel to the webhook alerting from platform status monitoring (status.sse.cisco.com). do you found a meaningful mapping for the fields in the JSON alert send? its not very easy to further process these alerts...&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 14:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5548358#M170</guid>
      <dc:creator>cludwigd</dc:creator>
      <dc:date>2026-04-27T14:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Access: Alert Notifications Webhook</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5548651#M171</link>
      <description>&lt;P&gt;You are correct, currently only basic auth is supported.&lt;/P&gt;&lt;P&gt;For the mapping/schema and examples please see the Alerting section under the guides:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://developer.cisco.com/docs/cloud-security/secure-access-api-guides-overview/" target="_blank"&gt;https://developer.cisco.com/docs/cloud-security/secure-access-api-reference-api-anomalies-alerts-overview/#alerts-for-api-anomalies&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 08:14:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5548651#M171</guid>
      <dc:creator>Yaron Caspy</dc:creator>
      <dc:date>2026-04-28T08:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Access: Alert Notifications Webhook</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5549065#M172</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1787903"&gt;@cludwigd&lt;/a&gt;&amp;nbsp;thanks so much for confirming this and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/426559"&gt;@Yaron Caspy&lt;/a&gt;&amp;nbsp;for vendor-verification.&amp;nbsp; How might partners get line of sight to the timeline for enabling token-based authorization, i.e. Bearer or Hash-based Message Authentication (HMAC), as we don't support use f basic authentication for Webhooks.&amp;nbsp; I've seen similar basic auth only support for Catalyst SD-WAN.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 13:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5549065#M172</guid>
      <dc:creator>Prodrick</dc:creator>
      <dc:date>2026-04-29T13:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Access: Alert Notifications Webhook</title>
      <link>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5549072#M173</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1465320"&gt;@Prodrick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Sure thing. The best way would be to request feature enhancements which will help us promote adding this. BTW, in many cases token based authentication can be achieved with basic auth by adding the token as the password along with a placeholder for the username. Here is an example which works with Splunk (I've seen it work with other products as well):&lt;/P&gt;&lt;LI-CODE lang="java"&gt;{
  "name": "token",
  "tags": [
    "string"
  ],
  "type": "basic-auth",
  "value": {
    "password": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxx",
    "username": "a"
  }
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;* Where 'a' is the placeholder and the token is in the password field.&amp;nbsp;&lt;/P&gt;&lt;P&gt;** Full request is here:&amp;nbsp;&lt;A href="https://developer.cisco.com/docs/cloud-security/create-integration/" target="_blank"&gt;https://developer.cisco.com/docs/cloud-security/create-integration/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;*** To do this via API, you need to: 1. Create the webhook. 2. Add credentials to the webhook. 3. Create the Security Events integration and add the webhook as a target. Or you can do this in the UI &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;BR /&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 13:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/secure-access-discussions/secure-access-alert-notifications-webhook/m-p/5549072#M173</guid>
      <dc:creator>Yaron Caspy</dc:creator>
      <dc:date>2026-04-29T13:20:24Z</dc:date>
    </item>
  </channel>
</rss>

