Cisco Secure Access Help

PDF

Cisco Secure Access Help

Push Security Events Third-Party Integration

Want to summarize with AI?

Log in

Add a third-party integration, such as ServiceNow or Splunk, for Secure Access push security events.


You can add a Third-party Integration in Secure Access to enable Push Security Events for a third-party product or service.

Push Security Events are logged by Secure Access when end users request destinations that are associated with Security categories or other security criteria. Security categories that trigger security events are Command and Control, Malware, and Phishing.

A Secure Access Third-party Integration for Push Security Events requires a Secure Access Webhook configured with the URL of the third-party HTTP listener and authentication credentials.

To get started, set up your Third-party Integration for Push Security Events with a Secure Access Webhook. Configure the Secure Access Webhook to send the security events to a destination URL for an HTTP target service. Select the type of security events that the Webhook will send to the HTTP listener.

Administrators of the third-party product or service are responsible for deploying the HTTP listener in the organization's on-premises or cloud environment.

Push Security Events are available for various types of network and security activities:

  • DNS activity

  • HTTP activity

  • Other types of activity:

    • Firewall

    • Intrusion Prevention System (IPS)

    • Data Loss Prevention (DLP)

    • Zero Trust Network Access (ZTNA) with a blocked reason

    • Remote Access Virtual Private Network (RAVPN) with a failed reason

Benefits of Integrating Secure Access Push Security Events with Third-Party Security and Information Systems

  • Administrators can configure Secure Access to send Push Security Events to an XDR or Security Information and Event Management (SIEM) system.

  • Third-party integrations enable an organization's Security Operations Centers (SOCs) to have visibility into risky activity.

  • Third-party integrations provide administrators with the capability to trigger automation and incident response and correlation workflows.

  • Assist organizations to identify potential security threats.

Guidelines and Limitations

  • Secure Access supports three (3) third-party integrations of Push Security Events in an organization.

  • Secure Access sends all Push Security Events in batches formatted with the Cloud events schema or Splunk schema.

  • Secure Access sends up to ten security events in each Webhook message.

  • Secure Access does not convert numeric or UUID values in the events into names or labels. You can use the Secure Access API to resolve these identifiers.

How to Set Up a Third-Party Integration for Push Security Events

  1. Deploy an HTTP listener in your on-premises or cloud environment. Ensure that the target system can receive HTTP POST messages from Secure Access. The target system must support Basic authentication with a username and password.

  2. Add a Webhook in Secure Access as a Third-party integration. Configure the Webhook with the URL and Basic authentication credentials of the HTTP listener.

  3. Add a Third-party integration for Push Security Events in Secure Access.

  4. Validate that your target system receives Secure Access Push Security Events.


Add Third-Party Integrations for Push Security Events

Organizations can add a Third-party Integration for Push Security Events in Secure Access. To integrate the Secure Access Push Security Events with a third-party product or service, deploy an HTTP listener in the organization's on-premises or cloud environment.

Note

Secure Access supports three Third-party Integrations for Push Security Events.

Before you begin

  • Full Admin user role. For more information, see Manage Accounts.

  • Configure a Secure Access Webhook for the Third-party Integration of Push Security Events.

Procedure

  1. Navigate to Admin > Third-party Integrations.

    The Third Party Integrations Push Sec Events interface.
  2. Navigate to Push Security Events, and then click + Integrate to enter the details for the Third-party Integration.

  3. Navigate to Select webhook and format.

  4. For Format, choose the format of the Push Security Events that Secure Access will publish to the Webhook.

    The formats that are available to select for Push Security Events are:

    • Cloud Events–The Push Security Events formatted in the Cloud Events schema.

    • Splunk–The Push Security Events formatted in the Splunk events schema.

    The Third Party Select Format Security Events interface.
  5. For Webhook choose a Webhook from the list of configured Webhooks, or navigate to Webhook, click + Add and then configure a new Webhook.

    The Third Party Integrations Add Webhook Push Se interface.
    1. For Webhook name, enter 2–250 alphanumeric, underscore, or hyphen characters. Choose a meaningful name for the Webhook that is unique for all Webhooks in the organization.
    2. For Address/Destination URL, enter the URL for the HTTP listener that you deployed in your environment.
    3. For Authentication method, Secure Access supports Basic authentication.
    4. For Username, enter the name for the user account that Secure Access will use to authenticate the API request to the target service.
    5. For Password, enter the password for the user account that Secure Access will use to authenticate the API request to the target service.
    6. Click Save.
  6. Navigate to Secure Access Configuration.

    1. For Integration name, enter 2–250 alphanumeric, underscore, or hyphen characters.

      Choose a meaningful name for the integration that is unique for all Third-party Integrations in the organization.

    2. For Security Events, click All to select all types of security events, or click the individual types of security events that Secure Access will push to the third-party service.

      The Third Party Integrations Choose Push Se interface.
  7. Click Integrate.


View Third-Party Integrations for Push Security Events

In your Secure Access organization, view the Third-party Integrations configured for Push Security Events.

Before you begin

  • A minimum user role of Read-only. For more information, see Manage Accounts.

Procedure

  1. Navigate to Admin > Third-party Integrations.

    The Third Party Integrations Push Sec Events interface.
  2. On the Integrations tab, navigate to Push Security Events.

  3. Click View details.

    Secure Access displays the list of Third-party Integrations that are set up to receive push notifications.

    • Name—The name of the Third-party Integration for Push Security Events.

    • Webhooks—The name of the Webhooks associated with the integration.

    • Added by—The organization ID and user account that added the Third-party Integratio.

    • Added on—The date and time when the organization added the Third-party Integration.

    The Third Party Push Security Events List Details interface.
  4. Navigate to the Push Security Events table and click on the name of a Third-party Integration to view the details about the integration.

    • Module name—The name of the Third-party Integration for Push Security Events.

    • Integration—The type of the Third-party Integration.

    • Webhook—The name of the Webhook associated with the Third-party Integration.

    • Security Events—The list of security events selected for the Third-party Integration.

    • Type—The type of the Secure Access integration.

    • Added on—The date and time when the organization added the Third-party Integration.

    • Added by—The organization ID and user account that added the Third-party Integration.

    • Status—The status of the Third-party Integration, either Active or Inactive.

    The Third Party Integration Push Security Event Details interface.
  5. Click Close.


Edit a Third-Party Integration for Push Security Events

Organizations can edit a Third-party Integration for Push Security Events in Secure Access. To integrate the Secure Access Push Security Events with a third-party product or service, deploy an HTTP listener in the organization's on-premises or cloud environment.

Note

Secure Access supports three Third-party Integrations for Push Security Events.

Before you begin

Procedure

  1. Navigate to Admin > Third-party Integrations.

    The Third Party Integrations Push Sec Events interface.
  2. Navigate to Push Security Events, and then click View details.

    1. Navigate to a row in the Third-party Integrations table.
    2. Click on the pencil icon for an entry in the table or click the name of a Third-party Integration and then click Edit.
  3. Navigate to Select webhook and format.

  4. For Format, choose the format of the Push Security Events that Secure Access will publish to the Webhook.

    The formats that are available to select for Push Security Events are:

    • Cloud Events–The Push Security Events formatted in the Cloud Events schema.

    • Splunk–The Push Security Events formatted in the Splunk events schema.

    The Third Party Select Format Security Events interface.
  5. For Webhook choose a Webhook from the list of configured Webhooks, or navigate to Webhook, click + Add and then configure a new Webhook.

    The Third Party Integrations Add Webhook Push Se interface.
    1. For Webhook name, enter 2–250 alphanumeric, underscore, or hyphen characters. Choose a meaningful name for the Webhook that is unique for all Webhooks in the organization.
    2. For Address/Destination URL, enter the URL for the HTTP listener that you deployed in your environment.
    3. For Authentication method, Secure Access supports Basic authentication.
    4. For Username, enter the name for the user account that Secure Access will use to authenticate the API request to the target service.
    5. For Password, enter the password for the user account that Secure Access will use to authenticate the API request to the target service.
    6. Click Save.
  6. Navigate to Secure Access Configuration.

    1. For Integration name, enter 2–250 alphanumeric, underscore, or hyphen characters.

      Choose a meaningful name for the integration that is unique for all Third-party Integrations in the organization.

    2. For Security Events, click All to select all types of security events, or click the individual types of security events that Secure Access will push to the third-party service.
      The Third Party Integrations Choose Push Se interface.
  7. Click Integrate.


Delete a Third-Party Integration for Push Security Events

Before you begin

Procedure

  1. Navigate to Admin > Third-party Integrations.

    The Third Party Integrations Push Sec Events interface.
  2. Navigate to Push Security Events, and then click View details.

    1. Navigate to a row in the Third-party Integrations table for Push Security Events.
    2. Click on the trash can icon for an entry in the table or click the name of a Third-party Integration and then click Delete.
  3. In the dialog window, click Delete to confirm the removal of the Third-party Integration.

    The Third Party Integration Delete Push Security Events interface.

Splunk Integration: Configure Push Security Events

To receive Push Security Events in Splunk, set up a Webhook for Splunk in Secure Access. Then, configure a Third-party Integration and add the Webhook for Splunk to the Third-party Integration.

Secure Access logs security events when end users send requests to destinations associated with Security categories. The Security categories are Command and Control, Malware, Phishing or other security criteria. Secure Access publishes the Push Security Events for Splunk in JSON using the Splunk events schema. For more information, see Push Security Events Third-Party Integration.

Set Up Push Security Events in Secure Access for Splunk

Configure a Secure Access Webhook for Splunk and then set up the Secure Access Third-party Integration for Push Security Events.

  1. Add a Webhook in Secure Access. Configure the Webhook with the URL for the Splunk HTTP listener and the Basic authentication credentials for your Splunk account. For more information, see Manage Webhooks for Third-Party Integrations.

  2. Add a Secure Access Third-party Integration for Splunk. For the Third-party Integration, select the Push Security Events. For more information, see Add Third-Party Integrations for Push Security Events.

  3. Validate that your instance of Splunk receives the Secure Access Push Security Events.


ServiceNow Integration: Configure Push Security Events

Configure the integration of a Third-party Integration with ServiceNow to publish Data Loss Prevention (DLP) Push Security Events. Secure Access publishes the DLP Push Security Events for ServiceNow formatted in the cloud events schema.

ServiceNow creates incidents when the ServiceNow HTTP listener receives the DLP push security events from Secure Access and identifies that certain security conditions are present in the events.

Set up a Webhook for ServiceNow in Secure Access and add the Webhook to the Third-party Integration for ServiceNow. For more information, see Push Security Events Third-Party Integration.

Step1: Set Up ServiceNow to Receive Secure Access Push Security Events

Before you begin, obtain a ServiceNow account with administrative privileges.

  1. In the ServiceNow app, create a Group for your Cisco Secure Access organization.

  2. Set up filters in ServiceNow. The filters enable ServiceNow to read specific fields in the Secure Access DLP push security events. Optionally add boolean logic with the ServiceNow filters.

    • cisco_origin: The name of the Cisco Secure Access origin.

    • metadata.correlation_id: The correlation IDs for the Secure Access services.

    • policy.name: The name of the DLP policy that triggered the DLP security event.

    • cisco_dlp_metadata.severity: The severity of the security event.

    • cisco_dlp_metadata.event_type: Type of the security event.

    • cisco_organization_id: The ID of the Secure Access organization.

  3. Configure authentication for the ServiceNow HTTP listener. Allow end users to manage Basic authentication for the Cisco Secure Access Group.

  4. Submit the configuration of the Group for Cisco Secure Access.

  5. ServiceNow exposes a single Scripted REST API endpoint URL for all groups.

Step 2: Set Up Push Security Events in Secure Access for ServiceNow

  1. Add a Webhook in Secure Access. Configure the Webhook with the URL for the ServiceNow HTTP listener and the Basic authentication credentials for your ServiceNow account. For more information, see Manage Webhooks for Third-Party Integrations.

  2. Add a Secure Access Third-party Integration for ServiceNow. For more information, see Push Security Events Third-Party Integration.

    For the Third-party Integration, select the DLP Push Security Events only.

    For the format of the Push Security Events, select Cloud Events.

  3. Validate that your target system receives the Secure Access DLP Push Security Events.