What Cisco Umbrella can see, and therefore track and log, depends on which parts of the service your organisation uses. DNS-layer security sees only the domains a device looks up. The secure web gateway, especially with TLS decryption turned on, can see far more.
Visibility by layer
| Umbrella layer | What it can see | What it cannot see |
|---|---|---|
| DNS-layer security | Every domain queried, the time, the identity (network, user or device), the policy applied and whether it was allowed or blocked | Full URLs, page content, form data, files |
| Secure web gateway without decryption | Destination domain (from the TLS SNI field), IP address, bytes transferred, application | Anything inside the encrypted session |
| Secure web gateway with decryption | Full URL, HTTP method, file names and hashes, uploads and downloads, cloud app and tenant | Domains on the selective decryption list |
| Data loss prevention (SIG Advantage) | Content that matches DLP rules, such as card numbers or other sensitive data patterns | Data that never passes through the proxy |
| Cloud-delivered firewall | Source and destination IP addresses, ports, protocols and applications for tunnelled traffic | Traffic that does not go through the tunnel |
How identities are attached
Umbrella can only report “who” as precisely as the deployment allows:
- Network egress IP only: activity is logged against the office or site, not the person.
- Virtual appliances with Active Directory: activity is tied to internal IP addresses, users and groups.
- Umbrella module in Cisco Secure Client: activity is tied to the device, and to the user when AD integration is set up, on or off the corporate network.
What Umbrella does not track
- Keystrokes, screenshots or what is shown on screen.
- Files stored on the device, or activity in apps that never make a network request.
- Traffic that bypasses it, such as a device using a different DNS server or a personal VPN.
- Text typed into web apps, unless TLS decryption and DLP inspection are both applied to that traffic.
Logging and retention controls
Administrators choose per policy whether to log all requests, security events only, or nothing. Logs are searchable in the dashboard’s Activity Search and can be exported to an Amazon S3 bucket for a SIEM. In practice, on a managed work device you should assume your employer can see every site you visit at the domain level, and much more if the secure web gateway is in use.