What can Cisco Umbrella see?

What Cisco Umbrella can see depends on the package your organisation uses and how it is configured.

With DNS-layer protection only, Umbrella sees:

  • Which domains were requested, such as example.com
  • When each request was made
  • The identity behind it, such as the network, internal IP address, Active Directory user or device name
  • The domain’s category and whether it was allowed or blocked

It does not see full URLs, page content, messages or passwords. It knows which sites were looked up, not what you did on them.

With the SIG web gateway, visibility increases. Umbrella can log full URLs, file downloads and cloud app activity. If HTTPS inspection is enabled and the Cisco root certificate is installed on the device, it can decrypt and inspect encrypted traffic. Administrators can exempt sensitive categories, such as banking or healthcare, from decryption. Without decryption, it sees the domain name but not the page path.

For administrators, the Activity Search report works like a domain-level browsing history for each identity. Detailed DNS logs are kept for 90 days, and organisations can export logs to their own storage for longer retention.

There are blind spots. Umbrella generally cannot see traffic inside a personal VPN, lookups a browser sends to its own DNS-over-HTTPS provider, or activity on devices away from the corporate network that do not have the Secure Client module installed.

Still have a question?

Cloudbrink’s team can walk through how your current deployment maps across.