Cisco Umbrella Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Cisco Umbrella Tools
umb_ · 233 tools · Free 140 · Pro 93
DNS-layer security, secure web gateway and threat investigation. The credential is an API key and secret from the Umbrella dashboard. Paths are grouped by family - admin, deployments, policies, reports and investigate - and each carries its own prefix. Two paging models coexist: page with limit on the management endpoints, and limit with offset on reports and investigate. Page size stops at 1000. The Investigate tools need the Umbrella Investigate add-on licence and answer 403 or 404 without it.
All connector tools · Cisco Umbrella setup guide
Cisco Umbrella tool groups
- Admin — 6 tools
- API Keys — 6 tools
- Networks — 12 tools
- Sites — 5 tools
- Tunnels — 12 tools
- Internal Domains — 5 tools
- Devices & Tags — 19 tools
- Destination Lists — 8 tools
- Deployment Policies — 3 tools
- Reports — 23 tools
- App Discovery — 11 tools
- API Usage — 4 tools
- Investigate — 24 tools
- Managed Providers — 5 tools
- Provider Customers — 7 tools
- Provider Trials & Access — 6 tools
- Provider Deals & Organizations — 5 tools
- Provider Branding — 15 tools
- Provider Reporting — 11 tools
- Report Aggregations — 21 tools
- Report Summaries — 16 tools
- Application Lists — 6 tools
- SWG Device Settings — 3 tools
Admin
umb_create_user details
umb_create_user details
[Cisco Umbrella] Create an administrator user in your Umbrella organization. Provide a JSON object body with required fields firstname, lastname, email, and roleId (from umb_list_roles); optional password and timezone. The body contains a password — handle it as a secret. A 403 means the API key lacks the edit:admin (write) scope — re-issue the Umbrella API key with that scope.
umb_delete_user details
umb_delete_user details
[Cisco Umbrella] Delete an administrator user from your Umbrella organization by userId (from umb_list_users). This permanently removes the user. A 403 means the API key lacks the edit:admin (write) scope — re-issue the Umbrella API key with that scope.
umb_get_user details
umb_get_user details
[Cisco Umbrella] Get a single administrator user by id. Returns the user's full detail (name, email, role, status). Discover userId with umb_list_users.
umb_list_roles details
umb_list_roles details
[Cisco Umbrella] List the administrator roles available in your Umbrella organization. Returns each role's id and label. Use the returned roleId when creating an administrator with umb_create_user.
umb_list_users details
umb_list_users details
[Cisco Umbrella] List the administrator users in your Umbrella organization. Returns each user's id, name, email, and role. Paginated with page + limit (limit capped at 1000). Use umb_get_user for one user's full detail and the returned userId with umb_delete_user.
umb_rotate_s3_bucket_key details
umb_rotate_s3_bucket_key details
[Cisco Umbrella] Rotate the S3 bucket access key for your organization's managed S3 log storage. This mints a NEW secretAccessKey and immediately invalidates the previous one — the response returns the new secretAccessKey, so handle it as a secret / credential material. Cisco mandates rotating this key at least every 90 days. Takes no parameters. Vendor scope: Admin > IAM (admin.iam:write). A 403 means the API key lacks the edit:admin (write) scope — re-issue the Umbrella API key with that scope.
API Keys
umb_create_api_key details
umb_create_api_key details
[Cisco Umbrella] Create an API key. Provide a JSON object body with required fields name and scopes (array of scope strings); optional description, expireAt, and allowedIPs (array of IP addresses / CIDR blocks). Returns the new key and its secret (shown once). A 403 means the API key lacks the edit:admin (write) scope — re-issue the Umbrella API key with that scope.
umb_delete_api_key details
umb_delete_api_key details
[Cisco Umbrella] Delete an API key by apiKeyId (from umb_list_api_keys). This permanently revokes the key. A 403 means the API key lacks the edit:admin (write) scope — re-issue the Umbrella API key with that scope.
umb_get_api_key details
umb_get_api_key details
[Cisco Umbrella] Get a single API key by apiKeyId (from umb_list_api_keys). Returns the key's name, scopes, allowed IPs, and expiration (never the secret).
umb_list_api_keys details
umb_list_api_keys details
[Cisco Umbrella] List the API keys created by your organization. Returns each key's id, name, scopes, and expiration (never the secret). Paginated with limit + offset (limit capped at 1000). Use umb_get_api_key for one key's detail and the returned apiKeyId with umb_update_api_key, umb_delete_api_key, or umb_refresh_api_key.
umb_refresh_api_key details
umb_refresh_api_key details
[Cisco Umbrella] Refresh an API key, rotating its secret. Identify the key by apiKeyId (from umb_list_api_keys); no request body. Returns the key with its new secret (shown once). WARNING: rotating a key immediately invalidates its current secret, so EVERY consumer of that key stops working until it is reconfigured with the new secret — no in-use key is safe to rotate blindly. Rotating the key StackJack itself uses for this Umbrella connector is a known self-outage: the one-time secret Umbrella returns is NOT saved back to StackJack's stored connector credentials, so you must manually re-save it in the Portal to restore access. Rotating any OTHER in-use key (other integrations, scripts, dashboards) likewise breaks those consumers until each is updated with the new secret wherever the key is consumed. A 403 means the API key lacks the edit:admin (write) scope — re-issue the Umbrella API key with that scope.
umb_update_api_key details
umb_update_api_key details
[Cisco Umbrella] Update an API key's name, description, scopes, and allowed IPs. Identify the key by apiKeyId (from umb_list_api_keys) and provide a JSON object body with required fields name and scopes (array); optional description and allowedIPs (array). A 403 means the API key lacks the edit:admin (write) scope — re-issue the Umbrella API key with that scope.
Networks
umb_create_internal_network details
umb_create_internal_network details
[Cisco Umbrella] Create an internal network. Provide a JSON object body with required fields name, ipAddress, and prefixLength; optional siteId, networkId, and tunnelId to associate it (discover those with umb_list_sites, umb_list_networks, and the tunnels tools). A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_create_network details
umb_create_network details
[Cisco Umbrella] Create a network (external/egress IP range). Provide a JSON object body with required fields name, prefixLength, isDynamic, and status; optional ipAddress. Note: before creating a network you must contact Cisco Support to get your IP range verified. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_delete_internal_network details
umb_delete_internal_network details
[Cisco Umbrella] Delete an internal network by its origin id (internalNetworkId, from umb_list_internal_networks). This permanently removes the internal network. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_delete_network details
umb_delete_network details
[Cisco Umbrella] Delete a network by networkId (from umb_list_networks). This permanently removes the network from your deployment. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_get_internal_network details
umb_get_internal_network details
[Cisco Umbrella] Get a single internal network by its origin id (internalNetworkId, from umb_list_internal_networks). Returns the internal network's name, IP address/prefix, and associations.
umb_get_network details
umb_get_network details
[Cisco Umbrella] Get a single network by networkId (from umb_list_networks). Returns the network's name, IP address/prefix, dynamic flag, and status.
umb_list_internal_network_policies details
umb_list_internal_network_policies details
[Cisco Umbrella] List the policies applied to an internal network by its origin id (internalNetworkId, from umb_list_internal_networks). Optional type selects the policy family — dns or web. Vendor scope: deployments.internalnetworks:read.
umb_list_internal_networks details
umb_list_internal_networks details
[Cisco Umbrella] List the internal networks defined in your Umbrella deployment. Returns each internal network's id, name, IP address/prefix, and any associated site/network/tunnel. Optionally filter by name. Paginated with page + limit (limit capped at 1000). Use umb_get_internal_network for one record's detail and the returned id with umb_update_internal_network or umb_delete_internal_network.
umb_list_network_policies details
umb_list_network_policies details
[Cisco Umbrella] List the policies applied to a network by its networkId (from umb_list_networks). Optional type selects the policy family — dns or web. Vendor scope: deployments.networks:read.
umb_list_networks details
umb_list_networks details
[Cisco Umbrella] List the networks (external/egress IP ranges) registered in your Umbrella deployment. Returns each network's id, name, IP address/prefix, and status. Paginated with page + limit (limit capped at 1000). Use umb_get_network for one network's detail and the returned networkId with umb_update_network or umb_delete_network.
umb_update_internal_network details
umb_update_internal_network details
[Cisco Umbrella] Update an internal network. Identify it by its origin id (internalNetworkId, from umb_list_internal_networks) and provide a JSON object body with required fields name, ipAddress, and prefixLength; optional siteId, networkId, and tunnelId. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_update_network details
umb_update_network details
[Cisco Umbrella] Update a network. Identify it by networkId (from umb_list_networks) and provide a JSON object body with required fields name, isDynamic, and status; optional ipAddress and prefixLength. Note: before changing the network's IP address you must contact Cisco Support to get your IP range verified. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
Sites
umb_create_site details
umb_create_site details
[Cisco Umbrella] Create a site. Provide a JSON object body with the required field name. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_delete_site details
umb_delete_site details
[Cisco Umbrella] Delete a site by siteId (from umb_list_sites). This permanently removes the site. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_get_site details
umb_get_site details
[Cisco Umbrella] Get a single site by siteId (from umb_list_sites). Returns the site's name and origin id.
umb_list_sites details
umb_list_sites details
[Cisco Umbrella] List the sites in your Umbrella organization. Returns each site's id, name, and origin id. Paginated with page + limit (limit capped at 1000). Use umb_get_site for one site's detail and the returned siteId with umb_update_site or umb_delete_site.
umb_update_site details
umb_update_site details
[Cisco Umbrella] Update a site. Identify it by siteId (from umb_list_sites) and provide a JSON object body with the required field name. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
Tunnels
umb_create_tunnel details
umb_create_tunnel details
[Cisco Umbrella] Add a new network tunnel to the organization. Provide the tunnel as a JSON object in fieldsJson — required: name; optional: siteOriginId, deviceType, serviceType, networkCIDRs, transport, authentication (data-center choices come from umb_list_tunnel_datacenters). A 403 means the API key lacks the deployments write scope — re-issue the Umbrella API key with edit:deployments.
umb_delete_tunnel details
umb_delete_tunnel details
[Cisco Umbrella] Permanently delete a network tunnel by its numeric id (from umb_list_tunnels). If the tunnel is attached to policies, set detachPolicies=true to detach it during deletion. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_get_tunnel details
umb_get_tunnel details
[Cisco Umbrella] Get a single network tunnel by its numeric id (from umb_list_tunnels). Returns the tunnel's full configuration including name, siteOriginId, device/service type, network CIDRs, transport, and authentication metadata.
umb_get_tunnel_events details
umb_get_tunnel_events details
[Cisco Umbrella] Get recent events for a network tunnel by its numeric id (from umb_list_tunnels). Optional hour (1-168) selects the lookback window, limit (1-500, capped at 500) caps the page size, and cursor pages forward. Returns a single {meta,data} object. Vendor scope: deployments.tunnels:read.
umb_get_tunnel_global_events details
umb_get_tunnel_global_events details
[Cisco Umbrella] Get global events for a network tunnel (by numeric id, from umb_list_tunnels) filtered to a specific source IP. The ip is a required path segment. Optional hour (1-168), limit (1-500, capped at 500), and cursor page forward. Returns an array of {meta,data} objects. Vendor scope: deployments.tunnels:read.
umb_get_tunnel_state details
umb_get_tunnel_state details
umb_list_tunnel_datacenters details
umb_list_tunnel_datacenters details
[Cisco Umbrella] List the IPsec-enabled Umbrella data centers available for tunnel termination. Each entry includes the data center's IP address and location details — use these when choosing a data center for umb_create_tunnel.
umb_list_tunnel_policies details
umb_list_tunnel_policies details
[Cisco Umbrella] List the policies attached to a network tunnel by its numeric id (from umb_list_tunnels). Optional type selects the policy family — firewallrule or web (note: this endpoint uses firewallrule|web, NOT dns|web). Page with page + limit (limit capped at 1000). Vendor scope: deployments.tunnels:read.
umb_list_tunnel_states details
umb_list_tunnel_states details
[Cisco Umbrella] List the live state information for all network tunnels in the organization (up/down status and connection details across every tunnel). For one tunnel's state, use umb_get_tunnel_state.
umb_list_tunnels details
umb_list_tunnels details
[Cisco Umbrella] List the network tunnels (IPsec) configured for the organization. Returns each tunnel's id, name, device/service type, data center, and status. Set includeState=true to embed live tunnel state. Cursor pagination: pass a bounded limit and, to page, the startKey returned in the Link header of the prior response. Use filters (a JSON object string) to narrow by name/deviceType/serviceType/status/dataCenter/siteOriginId. Tunnel ids feed umb_get_tunnel, umb_update_tunnel, and umb_delete_tunnel.
umb_rotate_tunnel_credentials details
umb_rotate_tunnel_credentials details
[Cisco Umbrella] Rotate the IPsec pre-shared key (PSK) credentials for a network tunnel by its numeric id (from umb_list_tunnels). Provide a JSON object in fieldsJson — required: autoRotate (boolean); when autoRotate is false you MUST supply psk.idPrefix. Optional deprecateCurrentKeys=true deletes the current key immediately; otherwise the current PSK is invalidated but retained for 24h. WARNING: this invalidates the current PSK and RETURNS THE NEW SECRET in the response (treat it as credential material). Vendor scope: deployments.tunnels:write. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_update_tunnel details
umb_update_tunnel details
[Cisco Umbrella] Update a network tunnel by its numeric id (from umb_list_tunnels). Provide the changes as a JSON object in fieldsJson — required: name and client; updatable: name, siteOriginId, networkCIDRs, client (deviceType). Updates to read-only attributes are ignored. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
Internal Domains
umb_add_internal_domains details
umb_add_internal_domains details
[Cisco Umbrella] Add (create) an internal domain. Provide a JSON object body with the required field domain; optional description, includeAllVAs (bool), includeAllMobileDevices (bool), and siteIds (array of site ids from umb_list_sites). If you omit siteIds, the internal domain is associated with all sites in the organization. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_delete_internal_domain details
umb_delete_internal_domain details
[Cisco Umbrella] Delete an internal domain by internalDomainId (from umb_list_internal_domains). This permanently removes the internal domain. A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
umb_get_internal_domain details
umb_get_internal_domain details
[Cisco Umbrella] Get a single internal domain by internalDomainId (from umb_list_internal_domains). Returns the domain, description, and site associations.
umb_list_internal_domains details
umb_list_internal_domains details
[Cisco Umbrella] List the internal domains configured for your Umbrella deployment (domains excluded from DNS redirection). Returns each internal domain's id, domain, description, and site associations. Paginated with page + limit (limit capped at 1000). Use umb_get_internal_domain for one record's detail and the returned id with umb_update_internal_domain or umb_delete_internal_domain.
umb_update_internal_domain details
umb_update_internal_domain details
[Cisco Umbrella] Update an internal domain. Identify it by internalDomainId (from umb_list_internal_domains) and provide a JSON object body with the required field domain; optional description, includeAllVAs (bool), includeAllMobileDevices (bool), and siteIds (array of site ids). A 403 means the API key lacks the edit:deployments (write) scope — re-issue the Umbrella API key with that scope.
Devices & Tags
umb_add_tags_to_devices details
umb_add_tags_to_devices details
[Cisco Umbrella] Associate a device tag with one or more devices. Provide tagId (from umb_list_tags) and originIdsJson, a JSON array of device originIds to tag, e.g. [12345,67890]. Shares its endpoint with umb_remove_tags_from_devices; this tool sends the addOrigins body key. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_create_network_device details
umb_create_network_device details
[Cisco Umbrella] Register a new network device (integrated router/firewall, e.g. Cisco ISR) in the organization. Provide the device as a JSON object in fieldsJson — required: model, macAddress (12 hex chars, no separators), name (1-50 chars), serialNumber. Vendor scope: deployments.networkdevices:write. A 403 means the API key lacks the deployments write scope — re-issue the Umbrella API key with edit:deployments.
umb_create_tag details
umb_create_tag details
[Cisco Umbrella] Create a new device tag in the organization. Provide the tag as a JSON object in fieldsJson — required: name (the tag label), e.g. {"name":"finance-laptops"}. The returned tag id is used by umb_add_tags_to_devices. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_delete_network_device details
umb_delete_network_device details
[Cisco Umbrella] Permanently delete (deregister) a network device from the organization by its numeric originId (from umb_list_network_devices). Vendor scope: deployments.networkdevices:write. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_delete_roaming_computer details
umb_delete_roaming_computer details
[Cisco Umbrella] Permanently delete (deregister) a roaming computer from the organization by its deviceId (from umb_list_roaming_computers). A 403 means the API key lacks the deployments write scope — re-issue the Umbrella API key with edit:deployments.
umb_delete_virtual_appliance details
umb_delete_virtual_appliance details
[Cisco Umbrella] Permanently delete a virtual appliance (VA) from the organization by its numeric originId (virtualApplianceId, from umb_list_virtual_appliances). Vendor scope: deployments.virtualappliances:write. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_get_network_device details
umb_get_network_device details
[Cisco Umbrella] Get a single network device by its numeric originId (from umb_list_network_devices). Returns the device's full detail.
umb_get_roaming_computer details
umb_get_roaming_computer details
[Cisco Umbrella] Get a single roaming computer by its deviceId (from umb_list_roaming_computers). Returns the device's full detail including DNS-layer and SWG status.
umb_get_roaming_computers_orginfo details
umb_get_roaming_computers_orginfo details
[Cisco Umbrella] Get organization-level roaming-computer information (org-wide roaming deployment metadata). Takes no parameters. Vendor scope: deployments.roamingcomputersOrgInfo:read — a plain deployments.roamingcomputers:read key returns 403 for this endpoint.
umb_get_virtual_appliance details
umb_get_virtual_appliance details
[Cisco Umbrella] Get a single Umbrella virtual appliance by its numeric originId (from umb_list_virtual_appliances). Returns the VA's full configuration and status.
umb_list_network_device_policies details
umb_list_network_device_policies details
[Cisco Umbrella] List the policies applied to a network device by its numeric originId (from umb_list_network_devices). Optional type selects the policy family — dns or web (the server defaults to dns). Vendor scope: deployments.networkdevices:read.
umb_list_network_devices details
umb_list_network_devices details
[Cisco Umbrella] List the network devices (integrated routers/firewalls, e.g. Cisco ISR) registered in the organization. Returns each device's originId, name, and model. Use umb_get_network_device for one device's detail.
umb_list_roaming_computers details
umb_list_roaming_computers details
[Cisco Umbrella] List the roaming computers (Umbrella roaming client / SWG module devices) in the organization. Returns each computer's deviceId, name, DNS-layer status, and SWG (Secure Web Gateway) status. Filter by name, status (DNS-layer), swgStatus, and lastSync window (lastSyncBefore / lastSyncAfter timestamps). Page-based pagination. deviceId feeds umb_get_roaming_computer and umb_delete_roaming_computer.
umb_list_tags details
umb_list_tags details
[Cisco Umbrella] List the device tags defined in the organization. Returns each tag's id and name. Tag ids feed umb_add_tags_to_devices and umb_remove_tags_from_devices. Page-based pagination (page + limit).
umb_list_virtual_appliances details
umb_list_virtual_appliances details
[Cisco Umbrella] List the Umbrella virtual appliances (VAs) deployed in the organization. Returns each VA's originId, name, version, and status. Page-based pagination (page + limit). VA originIds identify these devices as identities in umb_add_identity_to_policy.
umb_remove_tags_from_devices details
umb_remove_tags_from_devices details
[Cisco Umbrella] Remove a device tag association from one or more devices. Provide tagId (from umb_list_tags) and originIdsJson, a JSON array of device originIds to untag, e.g. [12345,67890]. Issues an HTTP DELETE on the shared /tags//devices path (the add sibling is a POST) with the removeOrigins body key. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_update_network_device details
umb_update_network_device details
[Cisco Umbrella] Update a network device by its numeric originId (from umb_list_network_devices). Issues an HTTP PATCH; provide the changes as a JSON object in fieldsJson — required: name. Vendor scope: deployments.networkdevices:write. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_update_roaming_computer details
umb_update_roaming_computer details
[Cisco Umbrella] Update a roaming computer by its deviceId (a hex string, from umb_list_roaming_computers). Provide the changes as a JSON object in fieldsJson — required: name. Vendor scope: deployments.roamingcomputers:write. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_update_virtual_appliance details
umb_update_virtual_appliance details
[Cisco Umbrella] Update a virtual appliance (VA) by its numeric originId (virtualApplianceId, from umb_list_virtual_appliances). Issues an HTTP PUT; provide the changes as a JSON object in fieldsJson — required: siteId. Vendor scope: deployments.virtualappliances:write. A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
Destination Lists
umb_add_destinations details
umb_add_destinations details
[Cisco Umbrella] Add destination entries to a destination list, identified by its numeric id (from umb_list_destination_lists). Provide destinationsJson, a JSON array of objects — each requires destination (a domain, URL, or IP) and optionally a comment, e.g. [{"destination":"badsite.com","comment":"phishing"}]. A 403 means the API key lacks the policies write scope — re-issue the key with edit:policies.
umb_create_destination_list details
umb_create_destination_list details
[Cisco Umbrella] Create a destination list (allow or block list) in the organization. Provide the list as a JSON object in fieldsJson — required: access ("allow" or "block"), isGlobal (bool), name; optional: bundleTypeId, destinations (array of {destination, comment}). A 403 means the API key lacks the policies write scope — re-issue the Umbrella API key with edit:policies.
umb_delete_destination_list details
umb_delete_destination_list details
[Cisco Umbrella] Permanently delete a destination list from the organization by its numeric id (from umb_list_destination_lists). A 403 means the API key lacks the policies write scope — re-issue the Umbrella API key with edit:policies.
umb_get_destination_list details
umb_get_destination_list details
[Cisco Umbrella] Get a single destination list by its numeric id (from umb_list_destination_lists). Returns the list's metadata (name, access, isGlobal, bundleTypeId, destination count). For the entries themselves, use umb_list_destinations.
umb_list_destination_lists details
umb_list_destination_lists details
[Cisco Umbrella] List the destination lists (allow/block lists) in the organization. Returns each list's id, name, access (allow|block), and destination count. List ids feed umb_get_destination_list, umb_list_destinations, umb_update_destination_list, umb_delete_destination_list, umb_add_destinations, and umb_remove_destinations. Page-based pagination (page + limit).
umb_list_destinations details
umb_list_destinations details
[Cisco Umbrella] List the destination entries (domains, URLs, or IPs) inside a destination list, identified by its numeric id (from umb_list_destination_lists). Returns each entry's id, destination, type, and comment. The entry ids are what umb_remove_destinations deletes. Page-based pagination (page + limit).
umb_remove_destinations details
umb_remove_destinations details
[Cisco Umbrella] Remove destination entries from a destination list, identified by its numeric id (from umb_list_destination_lists). Provide destinationsJson, a JSON array of destination entry ids (NOT the domains) to delete, e.g. [123,456] — retrieve these ids via umb_list_destinations. Accepts at most 500 ids per call. A 403 means the API key lacks the policies write scope — re-issue the key with edit:policies.
umb_update_destination_list details
umb_update_destination_list details
[Cisco Umbrella] Rename a destination list by its numeric id (from umb_list_destination_lists). Provide the change as a JSON object in fieldsJson — required: name. To change the entries, use umb_add_destinations / umb_remove_destinations instead. A 403 means the API key lacks the policies write scope — re-issue the key with edit:policies.
Deployment Policies
umb_add_identity_to_policy details
umb_add_identity_to_policy details
[Cisco Umbrella] Add an identity to a deployment policy. Provide policyId (from umb_list_deployment_policies) and the identity's originId (e.g. a network, roaming computer, virtual appliance, or network device origin id). No request body. Policy changes may take up to 20 minutes to take effect globally. A 403 means the API key lacks the deployments write scope — re-issue the Umbrella API key with edit:deployments.
umb_list_deployment_policies details
umb_list_deployment_policies details
[Cisco Umbrella] List the Umbrella deployment policies. Returns each policy's id, name, and type. Filter by type ("dns" or "web"); when omitted, Umbrella returns DNS policies. Policy ids feed umb_add_identity_to_policy and umb_remove_identity_from_policy. Page-based pagination (page + limit).
umb_remove_identity_from_policy details
umb_remove_identity_from_policy details
[Cisco Umbrella] Remove an identity from a deployment policy. Provide policyId (from umb_list_deployment_policies) and the identity's originId. No request body. Policy changes may take up to 20 minutes to take effect globally. A 403 means the API key lacks the deployments write scope — re-issue the Umbrella API key with edit:deployments.
Reports
umb_list_identities details
umb_list_identities details
[Cisco Umbrella] List the identities known to Umbrella reporting (used to interpret and filter other reports). Optional search string and identitytypes (comma-delimited identity types) narrow the results. Page with limit (bounded; the server returns at most 5000 records) + offset. Access Scope: Reports > Utilities > Read-Only.
umb_report_activity details
umb_report_activity details
[Cisco Umbrella] List all activity events (DNS, proxy, firewall, intrusion) within a time window. The IP activity report is not available here. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Granular Events > Read-Only.
umb_report_activity_amp_retrospective details
umb_report_activity_amp_retrospective details
[Cisco Umbrella] List granular AMP retrospective (post-hoc malware detection) activity events within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with ampdisposition, sha256, and timezone filters. Page with offset + limit (bounded). Access Scope: Reports > Granular Events > Read-Only.
umb_report_activity_dns details
umb_report_activity_dns details
[Cisco Umbrella] List DNS activity events within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Granular Events > Read-Only.
umb_report_activity_firewall details
umb_report_activity_firewall details
[Cisco Umbrella] List firewall activity events within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with categories, verdict, identityids, ip, ports, and ruleid filters. Page with offset + limit (bounded). Access Scope: Reports > Granular Events > Read-Only.
umb_report_activity_intrusion details
umb_report_activity_intrusion details
[Cisco Umbrella] List granular intrusion (IPS) activity events within a time window. Requires the firewall-IPS package; without it the endpoint returns 403 or an empty result set (a data-availability concern, not a connector error). from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with identityids, signatures, signaturelistids, intrusionaction, ip, ports, filternoisydomains, and timezone filters. Page with offset + limit (bounded). Access Scope: Reports > Granular Events > Read-Only.
umb_report_activity_ip details
umb_report_activity_ip details
[Cisco Umbrella] List granular IP-layer activity events within a time window. Deprecated in the Umbrella spec (the legacy IP Enforcement Layer) but still served on the current v2 surface. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with identityids, identitytypes, categories, verdict, ip, and ports filters. Page with offset + limit (bounded). Access Scope: Reports > Granular Events > Read-Only.
umb_report_activity_proxy details
umb_report_activity_proxy details
[Cisco Umbrella] List proxy (secure web gateway) activity events within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Granular Events > Read-Only.
umb_report_summary details
umb_report_summary details
[Cisco Umbrella] Get an aggregate summary report (request totals with category and threat rollups) for a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. offset paginates. Access Scope: Reports > Aggregations > Read-Only.
umb_report_threat_types details
umb_report_threat_types details
[Cisco Umbrella] List the threat types Umbrella recognizes (a reference lookup; no time window or pagination). Use the returned type identifiers to interpret threat-type fields in other reports such as umb_report_top_threats. Access Scope: Reports > Utilities > Read-Only.
umb_report_top_categories details
umb_report_top_categories details
[Cisco Umbrella] List the content/security categories that received the most requests in a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, and policycategories filters. offset paginates. Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_destinations_dns details
umb_report_top_destinations_dns details
[Cisco Umbrella] List the top DNS destinations (domains) by request volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_destinations_firewall details
umb_report_top_destinations_firewall details
[Cisco Umbrella] List the top firewall destinations by connection/request volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_destinations_ip details
umb_report_top_destinations_ip details
[Cisco Umbrella] List the top IP-layer (IP enforcement) destinations by request volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_destinations_proxy details
umb_report_top_destinations_proxy details
[Cisco Umbrella] List the top proxy destinations by request volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_identities details
umb_report_top_identities details
[Cisco Umbrella] List the identities that made the most requests within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_ips details
umb_report_top_ips details
[Cisco Umbrella] List the top IP addresses by request volume within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, and policycategories filters. Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_threats details
umb_report_top_threats details
[Cisco Umbrella] Get the top threats (both DNS and proxy) within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_total_requests details
umb_report_total_requests details
[Cisco Umbrella] Get the total count of requests within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Access Scope: Reports > Aggregations > Read-Only.
umb_report_total_requests_dns details
umb_report_total_requests_dns details
[Cisco Umbrella] Get the total count of DNS requests within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_total_requests_firewall details
umb_report_total_requests_firewall details
[Cisco Umbrella] Get the total count of firewall events within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_total_requests_ip details
umb_report_total_requests_ip details
[Cisco Umbrella] Get the total count of IP-layer (IP enforcement) requests within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_total_requests_proxy details
umb_report_total_requests_proxy details
[Cisco Umbrella] Get the total count of proxy requests within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
App Discovery
umb_appdiscovery_get_app_identities details
umb_appdiscovery_get_app_identities details
[Cisco Umbrella] List the identities (users/devices) observed using a discovered application. applicationId comes from umb_appdiscovery_list_applications. Page with limit (bounded) + offset. Use this to see who is using a given cloud app. Access Scope: Reports > Read-Only.
umb_appdiscovery_get_app_risk details
umb_appdiscovery_get_app_risk details
[Cisco Umbrella] Get the risk assessment for a single discovered application: its risk score and the contributing risk attributes used to triage Shadow IT / SaaS exposure. applicationId comes from umb_appdiscovery_list_applications. Access Scope: Reports > Read-Only.
umb_appdiscovery_get_application details
umb_appdiscovery_get_application details
[Cisco Umbrella] Get a single discovered cloud application by id, including its metadata used to triage Shadow IT / SaaS exposure. applicationId comes from umb_appdiscovery_list_applications. Access Scope: Reports > App Discovery (reports.appDiscovery:read).
umb_appdiscovery_get_protocol details
umb_appdiscovery_get_protocol details
[Cisco Umbrella] Get a single application protocol by id. protocolId comes from umb_appdiscovery_list_protocols. Optionally pass date (YYYY-MM-DD) to report as of a specific day. Access Scope: Reports > App Discovery (reports.appDiscovery:read).
umb_appdiscovery_list_application_attributes details
umb_appdiscovery_list_application_attributes details
[Cisco Umbrella] List the attributes (security/compliance/business characteristics) of a discovered application. applicationId comes from umb_appdiscovery_list_applications. Optionally filter by categories (comma-separated). Access Scope: Reports > App Discovery (reports.appDiscovery:read).
umb_appdiscovery_list_application_categories details
umb_appdiscovery_list_application_categories details
[Cisco Umbrella] List the application categories used to classify discovered cloud apps. Page with limit (1..100) + offset. Access Scope: Reports > App Discovery (reports.appDiscovery:read).
umb_appdiscovery_list_applications details
umb_appdiscovery_list_applications details
[Cisco Umbrella] List cloud applications discovered in your Umbrella traffic (App Discovery / Shadow IT report). Each application carries an id required by umb_appdiscovery_get_app_risk, umb_appdiscovery_get_app_identities, and umb_appdiscovery_update_app_label. Optionally pass date (YYYY-MM-DD) to report as of a specific day; omit for the latest data. Page with limit (bounded) + offset. Access Scope: Reports > Read-Only.
umb_appdiscovery_list_protocol_identities details
umb_appdiscovery_list_protocol_identities details
[Cisco Umbrella] List the identities (users/devices) observed using a given application protocol. protocolId comes from umb_appdiscovery_list_protocols. Optionally pass date (YYYY-MM-DD) and sort with sort/order. Page with limit (1..100) + offset. Access Scope: Reports > App Discovery (reports.appDiscovery:read).
umb_appdiscovery_list_protocols details
umb_appdiscovery_list_protocols details
[Cisco Umbrella] List cloud application protocols observed in your Umbrella traffic. Optionally filter by identity and sort with sort/order. Page with limit (1..100) + offset. Access Scope: Reports > App Discovery (reports.appDiscovery:read).
umb_appdiscovery_update_app_label details
umb_appdiscovery_update_app_label details
[Cisco Umbrella] Set the review label / status on a discovered application (for example approve or tag it). applicationId comes from umb_appdiscovery_list_applications. Body (required): label. A 403 means the Umbrella API key lacks the reports write scope — re-issue the key with edit access to App Discovery.
umb_appdiscovery_update_applications details
umb_appdiscovery_update_applications details
[Cisco Umbrella] Bulk-set the review label / status on many discovered applications at once (collection-level PATCH — distinct from the single-item umb_appdiscovery_update_app_label). Body (required): label (the review label to apply) and applicationsList (array of 1..1000 application ids). A 403 means the Umbrella API key lacks the App Discovery write scope — re-issue the key with reports.appDiscovery:write.
API Usage
umb_apiusage_keys details
umb_apiusage_keys details
[Cisco Umbrella] List Umbrella API usage attributed per API key over a date window (which keys made how many calls). from/to are calendar dates in YYYY-MM-DD format, passed verbatim (do not reformat). Use this to attribute consumption to individual keys discovered via umb_list_api_keys. Access Scope: Reports > Read-Only.
umb_apiusage_requests details
umb_apiusage_requests details
[Cisco Umbrella] List Umbrella API request counts over a date window, broken down by request. from/to are calendar dates in YYYY-MM-DD format, passed verbatim (do not reformat). Companion to umb_apiusage_summary (totals) and umb_apiusage_responses (status-code breakdown). Access Scope: Reports > Read-Only.
umb_apiusage_responses details
umb_apiusage_responses details
[Cisco Umbrella] List Umbrella API response counts over a date window, broken down by HTTP response/status code. from/to are calendar dates in YYYY-MM-DD format, passed verbatim (do not reformat). Use this to spot elevated error rates (4xx/5xx) in your API traffic. Access Scope: Reports > Read-Only.
umb_apiusage_summary details
umb_apiusage_summary details
[Cisco Umbrella] Get an aggregate summary of your organization's Umbrella API usage (total request counts and rollups) over a date window. from/to are calendar dates in YYYY-MM-DD format and are passed through verbatim (do not reformat). Use this to gauge overall API consumption before drilling into umb_apiusage_requests, umb_apiusage_responses, or umb_apiusage_keys. Access Scope: Reports > Read-Only.
Investigate
umb_investigate_bgp_routes_asn details
umb_investigate_bgp_routes_asn details
[Cisco Umbrella] Get the CIDR prefixes and geo information advertised by an Autonomous System Number (ASN). Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_bgp_routes_ip details
umb_investigate_bgp_routes_ip details
[Cisco Umbrella] Get Autonomous-System information for an IPv4 address (ASN, CIDR, RIR, and owner/description). Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_bulk_categorization details
umb_investigate_bulk_categorization details
[Cisco Umbrella] Provide a list of domains and look up the status, and security and content category IDs for each domain. The domain status is a numerical value determined by the Cisco Security Labs team. Valid status values are: '-1' (malicious), '1' (safe), or '0' (undetermined status). Requires the Umbrella Investigate add-on license; calls return 403/404 without it. Body: {"domains": ["example.com", ...]} (Tier 2/3 only).
umb_investigate_domain_categorization details
umb_investigate_domain_categorization details
[Cisco Umbrella] Look up the status, and security and content category IDs for the domain. The domain status is a numerical value determined by the Cisco Security Labs team. Valid status values are: '-1' (malicious), '1' (safe), or '0' (undetermined status). Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_domain_risk_score details
umb_investigate_domain_risk_score details
[Cisco Umbrella] The Investigate Risk Score is based on an analysis of the lexical characteristics of the domain name and patterns in queries and requests to the domain. The risk score is scaled from 0 to 100 where 100 is the highest risk and 0 represents no risk at all. Periodically, Investigate updates this score based on additional inputs. A domain blocked by Umbrella receives a score of 100. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_domain_security details
umb_investigate_domain_security details
[Cisco Umbrella] List multiple scores or security features for a domain. You can use the scores or security features to determine relevant data points and build insights on the reputation or security risk posed by the site. No one security information feature is conclusive. Instead, consider these features as part of your security research. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_domain_volume details
umb_investigate_domain_volume details
[Cisco Umbrella] List the query volume for a domain over the last 30 days. If there is no information about the domain, Investigate returns an empty array. As the query takes time to generate, the last two hours may be blank. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_links details
umb_investigate_links details
[Cisco Umbrella] List domains that co-occur within a small time window of the given domain (the true co-occurrence 'links' endpoint). No pagination. Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_pdns_domain details
umb_investigate_pdns_domain details
[Cisco Umbrella] The Passive DNS endpoint provides historical data from the Umbrella resolvers for domains, IPs, and other resource records. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_pdns_ip details
umb_investigate_pdns_ip details
[Cisco Umbrella] Get the Resource Record (RR) data for DNS responses, and categorization data, where the answer (or rdata) is the domain(s). Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_pdns_raw details
umb_investigate_pdns_raw details
[Cisco Umbrella] Get Passive-DNS Resource Records matching raw rdata (for example TXT record contents). URL-encode the value; wrap TXT strings in quotes. Page with limit + offset (bounded, capped at 1000; default 500). Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_pdns_rr_domain details
umb_investigate_pdns_rr_domain details
[Cisco Umbrella] Get Passive-DNS Resource Records (RRs) where the answer/rdata is the given domain — the answer-side view, distinct from umb_investigate_pdns_domain which returns query-side RRs on /pdns/name. Page with limit + offset (bounded, capped at 1000; default 500). Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_related details
umb_investigate_related details
umb_investigate_samples details
umb_investigate_samples details
[Cisco Umbrella] Specify a domain, IP, or URL. Use the destination to search for all samples associated with the destination. The default number of items in a response is 10. You can extend the limit. You must have a license for Cisco Secure Malware Analytics to receive the samples data. Cisco Secure Malware Analytics retains checksum samples for one year. You may find that Investigate previously listed a sample related to a destination. If Cisco Secure Malware Analytics no longer contains a sample related to the destination, Investigate does not display the sample in the list of associated samples. An error may occur when the requested destination is not in a valid format, if the requested host is not found in our database, or if there is no data available for the destination that you have requested. CIDR subnets (for example: 10.10.10.0/24) and pattern search is not supported. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_search details
umb_investigate_search details
[Cisco Umbrella] List the newly seen domains that match a regular expression pattern. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_subdomains details
umb_investigate_subdomains details
[Cisco Umbrella] List known subdomains of a domain. limit is capped at 100 (default 20); use offsetName (the last subdomain from the previous page) as the pagination cursor. Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_timeline details
umb_investigate_timeline details
[Cisco Umbrella] List the historical tagging timeline for a given IP, domain, or URL. Investigate sorts the timeline items in descending order using the timestamp field. Each timeline item includes lists of security category, attack, or threat type associated with the destination. Use the Tagging Timeline endpoint to verify when Umbrella assigned or removed a security category, attack, or threat type. If the current timeline item contains the security category, type of attack, or threat type not found in the previous timeline item, Umbrella updated the current timeline item. If the current timeline item does not contain the security category, attack, or threat type found in the previous timeline item, Umbrella removed the security category, type of attack, or threat type. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_top_million details
umb_investigate_top_million details
[Cisco Umbrella] List the most seen domains in Umbrella. You can download the data in a zip file, or use the Investigate API to stream the data into a SIEM. The popularity list contains our most queried domains based on passive DNS usage across our Umbrella global network of more than 180 billion requests per day with many tens of millions of unique active users, in more than 165 countries. The metric does not only consist of browser-based http requests from users but also takes in to account the number of unique client IPs invoking this domain relative to the sum of all requests to all domains. Our popularity ranking reflects the domain's relative internet activity agnostic to the invocation protocols and applications where as site ranking models (such as Alexa) focus on the web activity over port 80 (primarily from browsers). In addition, the Umbrella popularity algorithm also applies data normalization techniques to smooth potential biases that may occur due to sampling of DNS usage data. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_whois details
umb_investigate_whois details
[Cisco Umbrella] Get the WHOIS information for the specified email addresses, nameservers, and domains. You can search by multiple email addresses or multiple nameservers. This documentation outlines the following API endpoints: email (single and multiple), domain record (current and historical), and nameserver (single and multiple). In some instances, WHOIS information can be irregular as there are no standards between domain registrars and large volumes of information can be returned from a query. As such, both the email and nameserver WHOIS endpoints have a limit of 500 results, which you can reduce to a smaller set of results. There is an `offset` parameter that can be leveraged to retrieve the entire set of domain entries for a given email without any limitation. Only the email parameter supports this. You can sort the email parameter by filtering the entries based on the timestamp field. If a domain, email, or nameserver has no known WHOIS information, Investigate returns `HTTP 404`. If a domain, email or nameserver does not exist, Investigate returns `HTTP 404`. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_whois_email details
umb_investigate_whois_email details
[Cisco Umbrella] List the domains registered by a registrant email address. WHOIS caps at 500 results per request; use offset to page past 500 (email is the one endpoint that pages the full set). Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_whois_history details
umb_investigate_whois_history details
[Cisco Umbrella] List historical WHOIS records for a domain. Default 10 records. Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_whois_nameserver details
umb_investigate_whois_nameserver details
[Cisco Umbrella] List the domains registered against a SINGLE nameserver (path parameter). WHOIS endpoints cap at 500 results; use offset to page. Distinct from umb_investigate_whois_nameservers (batch query). Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_whois_nameservers details
umb_investigate_whois_nameservers details
[Cisco Umbrella] List the domains registered against a BATCH of nameservers. The required nameServerList is a comma-delimited list of nameserver hostnames. WHOIS endpoints cap at 500 results; use offset to page. Distinct from umb_investigate_whois_nameserver (single, path-param). Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
umb_investigate_whois_search details
umb_investigate_whois_search details
[Cisco Umbrella] Regex-search WHOIS records by field (for example 'nameservers' or 'emails') matching a regular-expression pattern. start is REQUIRED and the search window is at most 30 days. Investigate scope investigate.investigate:read. Requires the Umbrella Investigate add-on license; calls return 403/404 without it.
Managed Providers
umb_create_managed_customer details
umb_create_managed_customer details
[Cisco Umbrella] Create a customer under the Managed Providers (Multi-Org/MSP) console. Provide a JSON object body — required: customerName (string 1-255) and seats (integer >= 1). Requires a Managed-Provider/MSP-console API key; a 403 means the key lacks the admin.customers:write scope (or is not a provider-tier key) — re-issue the Umbrella API key with that scope.
umb_delete_managed_customer details
umb_delete_managed_customer details
[Cisco Umbrella] Permanently delete a Managed Providers customer by customerId (from umb_list_managed_customers). This cannot be undone. A 403 means the API key lacks the admin.customers:write scope — re-issue the Umbrella API key with that scope.
umb_get_managed_customer details
umb_get_managed_customer details
[Cisco Umbrella] Get a single Managed Providers customer by customerId (from umb_list_managed_customers). Returns customerId, customerName, and seats.
umb_list_managed_customers details
umb_list_managed_customers details
[Cisco Umbrella] List the customers under your Umbrella Managed Providers (Multi-Org/MSP) console. Returns an array of customers, each with customerId, customerName, and seats. Paginated with page + limit (limit max 100). Use umb_get_managed_customer for one customer and the returned customerId with umb_update_managed_customer / umb_delete_managed_customer.
umb_update_managed_customer details
umb_update_managed_customer details
[Cisco Umbrella] Update a Managed Providers customer by customerId (from umb_list_managed_customers). Provide a JSON object body — required: customerName (string 1-255) and seats (integer >= 1); both must be supplied. A 403 means the API key lacks the admin.customers:write scope — re-issue the Umbrella API key with that scope.
Provider Customers
umb_create_provider_customer details
umb_create_provider_customer details
[Cisco Umbrella] Create a Service-Provider customer. Provide a JSON object body — required: customerName (1-255), seats (>=1), streetAddress, city, countryCode (2-3), packageId (171/202/246/248/250/252/312), adminEmails (array of email). Optional: streetAddress2, state, zipCode, dealId, ccwDealOwnerEmails, addonRbi ('0'-'3'), addonCdfwL7, addonDlp, licenseType ('term'/'msla'), isTrial. A 403 means the API key lacks admin.customers:write or is not a provider-console key.
umb_delete_provider_customer details
umb_delete_provider_customer details
[Cisco Umbrella] Permanently delete a Service-Provider customer by customerId. Returns 204 (no content). Cannot be undone. A 403 means the API key lacks admin.customers:write.
umb_get_provider_customer details
umb_get_provider_customer details
[Cisco Umbrella] Get one Service-Provider customer by customerId (from umb_list_provider_customers). Returns the full customer object. Requires a provider-console key with admin.customers:read.
umb_get_provider_customer_packages details
umb_get_provider_customer_packages details
[Cisco Umbrella] List the packages available when creating a Service-Provider customer. Returns an array of {id, name, pkgSeatMin, ppovSeatMin}. Use a returned id as packageId in umb_create_provider_customer. Requires a provider-console key with admin.customers:read.
umb_get_provider_customer_subscription details
umb_get_provider_customer_subscription details
[Cisco Umbrella] Get subscription details for a Service-Provider customer by customerId — package, seats, start/end dates, trial lifecycle, access-request state. (createdAt/modifiedAt here are epoch-seconds integers, e.g. 1594557263; note the top-level Customer schema instead uses ISO-8601 strings for these fields.) Requires a provider-console key with admin.customers:read.
umb_list_provider_customers details
umb_list_provider_customers details
[Cisco Umbrella] List the customers under your Umbrella Service-Provider/MSSP console. Returns an array of customers (customerId, customerName, packageName/packageId, seats, address, adminEmails, addons). Paginated with page + limit (max 100). Requires a provider-console key with admin.customers:read. A 403/404 means the API key lacks that scope or is not a provider-console key.
umb_update_provider_customer details
umb_update_provider_customer details
[Cisco Umbrella] Update a Service-Provider customer by customerId (full replace). JSON body — required: customerName, seats, streetAddress, city, countryCode, packageId, adminEmails. Optional: streetAddress2, state, zipCode, dealId, ccwDealOwnerEmails. Note: the update body does NOT accept licenseType/isTrial/addonRbi/addonCdfwL7/addonDlp (response-only fields). A 403 means the API key lacks admin.customers:write.
Provider Trials & Access
umb_convert_provider_customer_trial details
umb_convert_provider_customer_trial details
[Cisco Umbrella] Irreversibly convert a trial to a paying customer by customerId. Provide a JSON object body — required: packageId (one of 246/248/250/252). Returns . This changes billing state and cannot be undone. Requires admin.customers:write on a provider-console key. (Vendor example shows 107 but the enum is [246,248,250,252] — send an enum value.)
umb_create_provider_access_request details
umb_create_provider_access_request details
[Cisco Umbrella] Request delegated access to a customer's Umbrella org by customerId. No request body (built from the path and provider identity). Returns the AccessRequest object. Requires admin.customers:write on a provider-console key.
umb_extend_provider_customer_trial details
umb_extend_provider_customer_trial details
[Cisco Umbrella] Extend a customer's trial by customerId. Provide a JSON object body — trialExtensionDays (must be 7 or 14). Returns the full customer object. Requires admin.customers:write on a provider-console key.
umb_get_provider_access_request details
umb_get_provider_access_request details
[Cisco Umbrella] Get a delegated-access request by customerId and accessRequestId. Returns the request object (id, organizationId, state = approved/denied/pending, organizationName, timestamps). Requires a provider-console key with admin.customers:read.
umb_get_provider_customer_trial_strength details
umb_get_provider_customer_trial_strength details
[Cisco Umbrella] Get a trial customer's engagement strength by customerId — customerLoggedIn, lastLoginDate, identitiesCreated, hasTraffic, trialStrength (Low/Medium/High/-). Requires a provider-console key with admin.customers:read.
umb_update_provider_access_request details
umb_update_provider_access_request details
[Cisco Umbrella] Advance a delegated-access request's state by customerId and accessRequestId. No request body — the transition is a server-side action driven by the path, so a repeat call is not guaranteed to be a no-op. Returns the updated AccessRequest. Requires admin.customers:write on a provider-console key.
Provider Deals & Organizations
umb_get_provider_customer_deal details
umb_get_provider_customer_deal details
[Cisco Umbrella] Get a customer deal by dealId. Required query ccoId (integer — the CCO id of the querying user). Returns an array of CustomerDeal objects (Cisco returns array shape even for get-by-id). Requires a provider-console key with admin.customerDeals:read; a 403 means the key lacks that scope or is not a provider-console key.
umb_list_provider_customer_addresses details
umb_list_provider_customer_addresses details
[Cisco Umbrella] List Service-Provider customer addresses. Paginated with page + limit (max 100). Returns an array of {accountId, accountSiteId, mappedCrPartyId, organizationName, address fields}. Requires a provider-console key with admin.customerSearch:read; a 403 means the key lacks that scope.
umb_list_provider_organizations details
umb_list_provider_organizations details
[Cisco Umbrella] List the organizations visible to a provider-org member. Required query email (a member of the provider org). Optional page/offset/limit (max 100). Returns an array of {organizationId, organizationName, mspOrganizationId, organizationTypeId, ...}. A 404 means the email was not found. Requires a provider-console key with admin.organizations:read.
umb_reset_provider_customer_passwords details
umb_reset_provider_customer_passwords details
[Cisco Umbrella] Force a password reset for named admin accounts in a child (customer) org by customerId. Provide a JSON object body — required: adminEmails (array of the child-org user emails to reset). This irreversibly invalidates those users' current passwords and triggers a reset flow. 200 returns an empty body. Requires a parent (provider) org token with admin.passwordreset:write; a 403 means the key lacks that scope or is not a provider-console key.
umb_update_provider_customer_deal details
umb_update_provider_customer_deal details
[Cisco Umbrella] Update a customer deal by dealId (full replace). Provide a JSON object body — required: ccoid (integer), customerId (integer); optional: quoteId (integer), majorLineItems (array of {objectId, sourceAppRefId}). NB casing: the write op carries ccoid in the body (the read uses ccoId in the query). Requires admin.customerDeals:write; a 403 means the key lacks that scope or is not a provider-console key.
Provider Branding
umb_create_provider_cname details
umb_create_provider_cname details
[Cisco Umbrella] Create a console CNAME. Provide a JSON object body — required: cname (string, e.g. "example.com"). Returns 200 with the created object. A 403 means the API key lacks admin.config:write or is not a provider-console key.
umb_create_provider_contact details
umb_create_provider_contact details
[Cisco Umbrella] Create a console contact. Provide a JSON object body — required: contactType (billing/blockfeedback/report/serviceupdate/support/distributor), emailAddress. Optional: primaryContact (yes/no), name/address/phone fields, nested settings.organization{name,email}. A 403 means the API key lacks admin.config:write or is not a provider-console key.
umb_create_provider_logo details
umb_create_provider_logo details
[Cisco Umbrella] Upload a branding logo (multipart/form-data). Params — all required: imageBase64 (the image file, base64-encoded), imageUrl, token (64 chars), enabled (bool), brandingTypeId (int). Returns the logo object. A 403 means the API key lacks admin.config:write or is not a provider-console key.
umb_delete_provider_cname details
umb_delete_provider_cname details
[Cisco Umbrella] Delete a console CNAME by cnameId. Returns 204 (no content). Cannot be undone. Requires admin.config:write on a provider-console key.
umb_delete_provider_contact details
umb_delete_provider_contact details
[Cisco Umbrella] Delete a console contact by contactId. Returns 204 (no content). Cannot be undone. Requires admin.config:write on a provider-console key.
umb_delete_provider_logo details
umb_delete_provider_logo details
[Cisco Umbrella] Delete a logo by logoId. Returns 204 (no content). Cannot be undone. Requires admin.config:write on a provider-console key.
umb_get_provider_cname details
umb_get_provider_cname details
[Cisco Umbrella] Get one console CNAME by cnameId (from umb_list_provider_cnames). Requires admin.config:read.
umb_get_provider_contact details
umb_get_provider_contact details
[Cisco Umbrella] Get one console contact by contactId (from umb_list_provider_contacts). Requires admin.config:read.
umb_get_provider_logo details
umb_get_provider_logo details
[Cisco Umbrella] Get one logo's metadata by logoId (JSON, not binary). Requires admin.config:read.
umb_list_provider_cnames details
umb_list_provider_cnames details
[Cisco Umbrella] List the console CNAMEs. Returns an array of {cnameId, cname, organizationId}. Requires a provider-console key with admin.config:read.
umb_list_provider_contacts details
umb_list_provider_contacts details
[Cisco Umbrella] List console contacts (billing/support/report/…). Returns an array; output flattens orgName/distributorVisibility to top level. Requires admin.config:read.
umb_list_provider_logos details
umb_list_provider_logos details
[Cisco Umbrella] List logo metadata (id, imageUrl, imageKey, token, enabled, brandingTypeId, timestamps) — JSON, not image bytes. Requires admin.config:read.
umb_update_provider_cname details
umb_update_provider_cname details
[Cisco Umbrella] Update (full replace) a console CNAME by cnameId. Provide a JSON object body — required: cname. Requires admin.config:write on a provider-console key.
umb_update_provider_contact details
umb_update_provider_contact details
[Cisco Umbrella] Update (full replace) a console contact by contactId. Provide a JSON object body with the same schema as umb_create_provider_contact. Requires admin.config:write on a provider-console key.
umb_update_provider_logo details
umb_update_provider_logo details
[Cisco Umbrella] Replace a logo by logoId (multipart/form-data, full replace). Params — all required: imageBase64, imageUrl, token, enabled, brandingTypeId. Requires admin.config:write on a provider-console key.
Provider Reporting
umb_create_provider_security_report details
umb_create_provider_security_report details
[Cisco Umbrella] Enqueue generation of a customer security report by customerId (Service-Provider/MSSP console). No request body; returns 200 with header.status='pending', task='enqueue-task'. Poll results with umb_get_provider_security_report. Restriction: only tokens issued for a Partner Proof-of-Value (PPoV) parent organization are authorized — a non-PPoV key will 4xx. Requires reports.customers:write on a provider-console key.
umb_get_provider_console_data details
umb_get_provider_console_data details
[Cisco Umbrella] Get the Service-Provider/MSSP console subscription summary — packageName, seatsTotal/seatsUsed, customerCount, status, rebillAt, expiresAt. No parameters (scoped by the provider-console token). Requires reports.customers:read on a provider-console key.
umb_get_provider_security_report details
umb_get_provider_security_report details
[Cisco Umbrella] Fetch/poll the generated customer security report (Service-Provider/MSSP console). isReportReady (bool) is the readiness flag — poll this after umb_create_provider_security_report. No parameters (scoped by the provider-console token). JSON output only (the vendor outputFormat=csv variant is intentionally not exposed). Requires reports.customers:read on a provider-console key.
umb_provider_report_categories details
umb_provider_report_categories details
[Cisco Umbrella] List the content categories available for provider (Service-Provider/MSSP console) reporting. Returns {data:[{id, legacyid, label, type, integration, deprecated}]} — use a returned id in the categories/policycategories filters of the other provider report tools. Vendor scope for this op: reports.utilities:read. A 403 means the API key lacks that scope or is not a provider-console key.
umb_provider_report_category_requests_by_org details
umb_provider_report_category_requests_by_org details
[Cisco Umbrella] Per-managed-customer content-category breakdown across all managed customer organizations (Service-Provider/MSSP console) over a from/to window. from/to accept an epoch-millisecond timestamp or a relative string ('-1days'/'now'), passed verbatim. Optional threats/threattypes/filternoisydomains. limit is bounded (capped at 1000). Requires reports.customers:read on a provider-console key.
umb_provider_report_deployments details
umb_provider_report_deployments details
[Cisco Umbrella] Deployment status per managed customer organization over a from/to window (Service-Provider/MSSP console). from/to accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now') and are passed through verbatim. Optionally narrow with threats and threattypes (comma-delimited). Requires a provider-console key with reports.customers:read.
umb_provider_report_requests_by_category details
umb_provider_report_requests_by_category details
[Cisco Umbrella] Request totals by content category across all managed customer organizations (Service-Provider/MSSP console) over a from/to window. from/to accept an epoch-millisecond timestamp or a relative string ('-1days'/'now'), passed verbatim. Optional threats/threattypes/filternoisydomains. limit is bounded (capped at 1000). Requires reports.customers:read on a provider-console key.
umb_provider_report_requests_by_destination details
umb_provider_report_requests_by_destination details
[Cisco Umbrella] Top destinations across all managed customer organizations (Service-Provider/MSSP console) over a from/to window. from/to accept an epoch-millisecond timestamp or a relative string ('-1days'/'now'), passed verbatim. Optional threats/threattypes/filternoisydomains. limit is bounded (capped at 1000). Requires reports.customers:read on a provider-console key.
umb_provider_report_requests_by_hour details
umb_provider_report_requests_by_hour details
[Cisco Umbrella] Request totals bucketed by hour across all managed customer organizations (Service-Provider/MSSP console). from/to accept an epoch-millisecond timestamp or a relative string ('-1days'/'now'), passed verbatim. Page with limit (bounded, capped at 1000) + offset. Optional filters: domains, urls, categories, policycategories, ip, identityids, identitytypes, applicationid, verdict, sha256, threats, threattypes, datalosspreventionstate (e.g. 'blocked'), filternoisydomains. Requires reports.customers:read on a provider-console key.
umb_provider_report_requests_by_org details
umb_provider_report_requests_by_org details
[Cisco Umbrella] Per-managed-customer request totals ({organization, counts:{total, totalblocked}}) over a from/to window (Service-Provider/MSSP console). from/to accept an epoch-millisecond timestamp or a relative string ('-1days'/'now'), passed verbatim. Optional threats/threattypes/filternoisydomains. limit is bounded (capped at 1000). Requires reports.customers:read on a provider-console key.
umb_provider_report_requests_by_timerange details
umb_provider_report_requests_by_timerange details
[Cisco Umbrella] Request totals bucketed by a timerange granularity across all managed customer organizations (Service-Provider/MSSP console). The granularity is set by the timerange parameter (minute/hour/day; sent as a request header, defaults to hour). from/to accept an epoch-millisecond timestamp or a relative string ('-1days'/'now'), passed verbatim. Page with limit (bounded, capped at 1000) + offset. Same optional filters as requests-by-hour minus sha256. Requires reports.customers:read on a provider-console key.
Report Aggregations
umb_report_bandwidth_by_hour details
umb_report_bandwidth_by_hour details
[Cisco Umbrella] Get bandwidth usage bucketed by hour within a time window (secure web gateway / proxy traffic only). from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_bandwidth_by_timerange details
umb_report_bandwidth_by_timerange details
[Cisco Umbrella] Get bandwidth usage bucketed by a configurable time range within a window (secure web gateway / proxy traffic only). from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. The bucket size is set by the timerange parameter (minute, hour, or day; default hour). Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_categories_by_hour details
umb_report_categories_by_hour details
[Cisco Umbrella] Get request counts by hour and content/security category across all traffic types within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_categories_by_hour_by_type details
umb_report_categories_by_hour_by_type details
[Cisco Umbrella] Get request counts by hour and content/security category for a specific traffic type within a time window. type must be one of dns, proxy, ip. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_categories_by_timerange details
umb_report_categories_by_timerange details
[Cisco Umbrella] Get request counts by content/security category bucketed by a configurable time range across all traffic types within a window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. The bucket size is set by the timerange parameter (minute, hour, or day; default hour). Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_categories_by_timerange_by_type details
umb_report_categories_by_timerange_by_type details
[Cisco Umbrella] Get request counts by content/security category bucketed by a configurable time range for a specific traffic type within a window. type must be one of dns, proxy, ip. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. The bucket size is set by the timerange parameter (minute, hour, or day; default hour). Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_requests_by_hour details
umb_report_requests_by_hour details
[Cisco Umbrella] Get request counts bucketed by hour across all traffic types within a time window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_requests_by_hour_by_type details
umb_report_requests_by_hour_by_type details
[Cisco Umbrella] Get request counts bucketed by hour for a specific traffic type within a time window. type must be one of dns, proxy, firewall, intrusion, ip. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_requests_by_timerange details
umb_report_requests_by_timerange details
[Cisco Umbrella] Get request counts bucketed by a configurable time range across all traffic types within a window. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. The bucket size is set by the timerange parameter (minute, hour, or day; default hour). Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_requests_by_timerange_by_type details
umb_report_requests_by_timerange_by_type details
[Cisco Umbrella] Get request counts bucketed by a configurable time range for a specific traffic type within a window. type must be one of dns, proxy, firewall, intrusion, ip. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. The bucket size is set by the timerange parameter (minute, hour, or day; default hour). Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_categories_by_type details
umb_report_top_categories_by_type details
[Cisco Umbrella] List the top content/security categories by request volume for a specific traffic type within a time window, in descending order. type must be one of dns, proxy, ip. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset (required by this endpoint; no limit — default 0 is always sent). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_destinations details
umb_report_top_destinations details
[Cisco Umbrella] List the top destinations across all traffic types by request volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded); offset is required by this endpoint (default 0 is always sent). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_dns_query_types details
umb_report_top_dns_query_types details
[Cisco Umbrella] List the top DNS query types (A, AAAA, MX, TXT, …) by request volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_eventtypes details
umb_report_top_eventtypes details
[Cisco Umbrella] Get aggregated event-type counts within a time window (this endpoint takes no limit/offset). from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_files details
umb_report_top_files details
[Cisco Umbrella] List the top files seen in proxy/SWG traffic by request volume within a time window, in descending order (proxy/SWG only). from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Optionally narrow with filename, sha256, verdict, ampdisposition, and identityids filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_identities_by_type details
umb_report_top_identities_by_type details
[Cisco Umbrella] List the identities that made the most requests for a specific traffic type within a time window, in descending order. type must be one of dns, proxy, firewall, ip. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_ips_internal details
umb_report_top_ips_internal details
[Cisco Umbrella] List the top internal IP addresses by request volume within a time window (this endpoint takes no limit/offset). from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_threat_types details
umb_report_top_threat_types details
[Cisco Umbrella] List the top threat types across all traffic by volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_threat_types_by_type details
umb_report_top_threat_types_by_type details
[Cisco Umbrella] List the top threat types for a specific traffic type within a time window, in descending order. type must be one of dns, proxy. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_threats_by_type details
umb_report_top_threats_by_type details
[Cisco Umbrella] List the top threats for a specific traffic type within a time window, in descending order. type must be one of dns, proxy. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_top_urls details
umb_report_top_urls details
[Cisco Umbrella] List the top URLs (SWG/proxy traffic) by request volume within a time window, in descending order. from/to accept an epoch-millisecond timestamp or a relative string (for example '-7days' or 'now') and are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded); offset is required by this endpoint (default 0 is always sent). Access Scope: Reports > Aggregations > Read-Only.
Report Summaries
umb_report_applications details
umb_report_applications details
[Cisco Umbrella] List the applications known to Umbrella reporting (a reference lookup used to interpret application fields in other reports). Optionally pass an application name/substring to filter. This is the reporting-utility listing, distinct from the App Discovery applications surface. Access Scope: Reports > Utilities > Read-Only.
umb_report_categories details
umb_report_categories details
[Cisco Umbrella] List all content and security categories Umbrella recognizes (a reference lookup; no time window, no parameters, no pagination). Use the returned category IDs to interpret and filter other reports. Access Scope: Reports > Utilities > Read-Only.
umb_report_deployment_status details
umb_report_deployment_status details
[Cisco Umbrella] Get deployment-status counts (how many requests came from fully vs partially protected identities) within a time window. from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Optionally filter by threats and threattypes, and set the timezone. No pagination (no limit/offset). Access Scope: Reports > Aggregations > Read-Only.
umb_report_get_identities_by_ids details
umb_report_get_identities_by_ids details
[Cisco Umbrella] Resolve a batch of identity IDs to their labels/metadata. This is a POST-as-read: it sends a request body but does not modify anything. Body: {"identityids": [123, 456, ...]}. Page the resolved results with limit (bounded). Access Scope: Reports > Utilities > Read-Only.
umb_report_get_identity details
umb_report_get_identity details
[Cisco Umbrella] Get a single identity (label and metadata) by its identity ID. Access Scope: Reports > Utilities > Read-Only.
umb_report_get_threat_name details
umb_report_get_threat_name details
[Cisco Umbrella] Get a single threat name by its threat-name ID (for example 'WannaCry'). A reference lookup; no time window or pagination. Access Scope: Reports > Utilities > Read-Only.
umb_report_get_threat_type details
umb_report_get_threat_type details
[Cisco Umbrella] Get a single threat type by its threat-type ID (for example 'Ransomware'). A reference lookup; no time window or pagination. Access Scope: Reports > Utilities > Read-Only.
umb_report_identity_distribution details
umb_report_identity_distribution details
[Cisco Umbrella] Get the distribution of requests across identity types within a time window (all traffic types). from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_identity_distribution_by_type details
umb_report_identity_distribution_by_type details
[Cisco Umbrella] Get the distribution of requests across identity types within a time window, for a single traffic type (dns or proxy). from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_summaries_by_category details
umb_report_summaries_by_category details
[Cisco Umbrella] Get per-category summaries (request totals with allowed/blocked rollups per content/security category) within a time window (all traffic types). from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_summaries_by_category_by_type details
umb_report_summaries_by_category_by_type details
[Cisco Umbrella] Get per-category summaries within a time window, for a single traffic type (dns, proxy, or ip). from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_summaries_by_destination details
umb_report_summaries_by_destination details
[Cisco Umbrella] Get per-destination summaries (request totals with allowed/blocked rollups per destination) within a time window (all traffic types). from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_summaries_by_destination_by_type details
umb_report_summaries_by_destination_by_type details
[Cisco Umbrella] Get per-destination summaries within a time window, for a single traffic type (dns or proxy). from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_summaries_by_rule_intrusion details
umb_report_summaries_by_rule_intrusion details
[Cisco Umbrella] Get intrusion (IPS) signature-list summaries within a time window — counts per signature list / rule. Requires the firewall-IPS package (returns 403/empty without it). from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Optionally narrow results with signatures, signaturelistids, ip, identityids, identitytypes, intrusionaction, and ports filters. Page with offset + limit (bounded). Access Scope: Reports > Summaries By Rule > Read-Only.
umb_report_summary_by_type details
umb_report_summary_by_type details
[Cisco Umbrella] Get a single aggregate summary object (request totals with allowed/blocked rollups) for a single traffic type (dns, proxy, firewall, or ip) within a time window. from/to are REQUIRED and accept an epoch-millisecond timestamp or a relative string (for example '-1days' or 'now'); both are passed through verbatim. Optionally narrow results with domains, categories, threattypes, verdict, identityids, ip, ports, and policycategories filters. Page with offset + limit (bounded). Access Scope: Reports > Aggregations > Read-Only.
umb_report_threat_names details
umb_report_threat_names details
[Cisco Umbrella] List all threat names Umbrella recognizes (a reference lookup; no time window, no parameters, no pagination). Use the returned names to interpret threat-name fields in other reports. Access Scope: Reports > Utilities > Read-Only.
Application Lists
umb_create_application_list details
umb_create_application_list details
[Cisco Umbrella] Create an application list. Body (required): applicationListName (string), isDefault (bool), applicationIds (array of application ids to include). A 403 means the Umbrella API key lacks the policies write scope — re-issue the key with policies.applicationlists:write.
umb_delete_application_list details
umb_delete_application_list details
[Cisco Umbrella] Permanently delete an application list. Any policy referencing it loses that application grouping — this cannot be undone. applicationListId comes from umb_list_application_lists. Access Scope: Policies (policies.applicationlists:write).
umb_get_application_list details
umb_get_application_list details
[Cisco Umbrella] Get a single application list by id, including its member application ids. applicationListId comes from umb_list_application_lists. Access Scope: Policies (policies.applicationlists:read).
umb_get_applications_usage details
umb_get_applications_usage details
[Cisco Umbrella] Report where a set of applications is in use across policies. Both query params are REQUIRED: attributeName (e.g. 'umbrella.destination.application_ids') and attributeValue (comma-separated application ids). Access Scope: Policies (policies.applicationlists:read).
umb_list_application_lists details
umb_list_application_lists details
[Cisco Umbrella] List all application lists in the organization (named groupings of cloud applications used by web/SWG policies). Returns {count, result[]}; each entry carries an applicationListId used by umb_get_application_list, umb_update_application_list, and umb_delete_application_list. Access Scope: Policies (policies.applicationlists:read).
umb_update_application_list details
umb_update_application_list details
[Cisco Umbrella] Replace an application list (full PUT, not a partial PATCH). applicationListId comes from umb_list_application_lists. Body (required, same shape as create): applicationListName, isDefault, applicationIds. A 403 means the Umbrella API key lacks the policies write scope — re-issue the key with policies.applicationlists:write.
SWG Device Settings
umb_list_swg_device_settings details
umb_list_swg_device_settings details
[Cisco Umbrella] List the per-device SWG (Secure Web Gateway) override settings for specific roaming devices. Provide fieldsJson: a JSON object with originIds (a JSON array of device origin ids, at most 100 per call), e.g. {"originIds":[123456,123457]}. Returns each device's current SWG override. This read is sent as a POST with a request body (POST-as-read). Vendor scope: Deployments > Devices > SWG (deployments.devices.swg:read).
umb_remove_swg_device_setting details
umb_remove_swg_device_setting details
[Cisco Umbrella] Remove the per-device SWG (Secure Web Gateway) override on specific roaming devices, reverting each device to the organization-level SWG setting. Provide fieldsJson: a JSON object with originIds (a JSON array of device origin ids, at most 100 per call), e.g. {"originIds":[123456,123457]}. Vendor scope: Deployments > Devices > SWG (deployments.devices.swg:write). A 403 means the API key lacks the deployments write scope — re-issue the key with edit:deployments.
umb_set_swg_device_setting details
umb_set_swg_device_setting details
[Cisco Umbrella] Override the SWG (Secure Web Gateway) enablement on specific roaming devices, overriding the organization-level setting. Provide fieldsJson: a JSON object with value ("1" to enable, "0" to disable) and originIds (a JSON array of device origin ids, at most 100 per call), e.g. {"value":"1","originIds":[123456,123457]}. Vendor scope: Deployments > Devices > SWG (deployments.devices.swg:write). A 403 means the API key lacks the deployments write scope — re-issue the Umbrella API key with edit:deployments.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team