In this article, you will learn how to integrate Cisco Umbrella with Real-Time Coaching. Once you set up this integration, data from Cisco Umbrella will be available in the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in Cisco Umbrella
For this integration, you'll first need to create an API key and API secret in your Cisco Umbrella console by following the steps below:
- Log in to your Cisco Umbrella administrator account.
- In the left sidebar, navigate to Admin > API Keys.
- From the top-right corner of the page, select Add.
- In the API Key Name field, enter a name for your application, such as “CoachingAPIAccess”.
- In the Key Scope section, select the Reports option. Then, select Read-Only for the selected scope and resource.
- In the Expiry Date section, select Never expire.
- Select Create Key.
- Copy and save both the API Key and API Secret somewhere you can easily access them later. You will need these credentials to set up the integration in Real-Time Coaching.
- Select Accept and Close.
Set Up the Integration in Real-Time Coaching
Once you have created your Cisco Umbrella API key and API secret, you can set up the integration in Real-Time Coaching by following these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Cisco Umbrella vendor tile and select Configure.
- Enter your API Key and API Secret in the corresponding fields.
-
Select Authorize.
Map Your Users
After you’ve finished integrating Cisco Umbrella, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage Cisco Umbrella detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the Cisco Umbrella integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Cisco Umbrella vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.
