Cisco Secure Access Data Integration
Overview
Identity Intelligence integrates with Cisco Secure Access to ingest and display data associated with Application and User and Entity Behavior Analytics events (UEBA). For information on configuring Secure Access to consume Trust Level data from Identity Intelligence via Security Cloud Control (SCC), please refer to the Secure Access documentation guide, which contains information about connecting both an existing or new Identity Intelligence tenant to your Secure Access organization. If you already have an Identity Intelligence tenant via Duo, please follow the "Existing Tenant" set up steps.
Configuration Steps
Follow the instructions below in the order written
Generate an API Key in Secure Access
You will first need to generate an API key with the necessary permissions within Secure Access. To do so:
Log in to your Secure Access org with a Full Admin or Security Administrator role
Navigate to the Admin menu item and select API Keys

Select Add, then enter a easily recognizable name and a description for the key
Assign the key the required scopes by selecting the respective check boxes:
Deployments (Identities and Networks)
Reports

Select
Read-Onlyfor each selected scope and resourceFor Expiry Date choose an expiration date or select Never Expire. Do NOT enter any information in the Network Restrictions area
Select Create Key. Then copy and save your API Key and Key Secret in a secure location, as you will need this information to complete the integration steps within Identity Intelligence
Select Accept and Close
Identity Intelligence Configuration Steps
Sign in to Identity Intelligence with an Administrator role
Navigate to Integrations and select Add Integration from the Secure Access tile
Enter a name for the integration. This name will be reused through Identity Intelligence to identify the source
Paste the API Key and Key Secret generated in Secure Access into their respective fields in the form

Select Save to finish setting up the integration
Your integration has been created! Identity Intelligence will test the connectivity automatically, and if there are no errors, will begin the data ingestion process
Last updated