Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Key Benefits Cisco Secure Access Add-on for Splunk (build 1.0.53)Storing all of the Secure Access Event Logs from S3 in Splunk can get very costly and not all customers can afford the huge number of events we process. Users can now create Event Snaps...
Feature OverviewWe are happy to announce the availability of the Secure Access MCP Server. Key Benefits You can use the Secure Access MCP Server to manage enforcement, reporting, enrichment and other use cases. The MCP Server:Is open Source and the c...
Feature OverviewThis feature provides customers with the ability to leverage external threat intelligence feeds, which provide the common STIX format, over a TAXII protocol, and apply their insights to Secure Access, so that identified Indicators Of ...
Feature OverviewWe are happy to announce the availability of APIs for Do Not Decrypt Lists and Security Profiles.Key BenefitsCustomers can now leverage APIs to automate management, provisioning and enforcement using:Do Not Decrypt APIs which include ...
Feature OverviewCustomers who use Secure Access and Splunk can use the-Cisco Secure Access Add-on for Splunk to bring Pushed Security Events/Alert Notifications as well as S3 event logs into Splunk. The Add-on then extracts fields and maps them, so t...
Hi @Prodrick ,Sure thing. The best way would be to request feature enhancements which will help us promote adding this. BTW, in many cases token based authentication can be achieved with basic auth by adding the token as the password along with a pla...
You are correct, currently only basic auth is supported.For the mapping/schema and examples please see the Alerting section under the guides: https://developer.cisco.com/docs/cloud-security/secure-access-api-reference-api-anomalies-alerts-overview/#a...
Hi Matus,
Looks like latitude and longitude in filters should be floats and not strings:
{"latitude": 39.0299604,"longitude": 39.0299604} ----> %7B%22latitude%22%3A%2039.0299604%2C%22longitude%22%3A%2039.0299604%7D
We will update our API docs but the...
I also just tried and the filter does not seem to work (I agree with your point, peerIP works fine but lat/lon do not).
As requested, can you please open a support ticket and we will look into this?
Absolutely and sorry for the broken link. The correct link to the docs is: https://developer.cisco.com/docs/cloud-security/cisco-cloud-security-add-on-for-splunk/
We will update the post.