What can Cisco Umbrella see?

Table of Contents

What Cisco Umbrella can see, and therefore track and log, depends on which parts of the service your organisation uses. DNS-layer security sees only the domains a device looks up. The secure web gateway, especially with TLS decryption turned on, can see far more.

Visibility by layer

Umbrella layer What it can see What it cannot see
DNS-layer security Every domain queried, the time, the identity (network, user or device), the policy applied and whether it was allowed or blocked Full URLs, page content, form data, files
Secure web gateway without decryption Destination domain (from the TLS SNI field), IP address, bytes transferred, application Anything inside the encrypted session
Secure web gateway with decryption Full URL, HTTP method, file names and hashes, uploads and downloads, cloud app and tenant Domains on the selective decryption list
Data loss prevention (SIG Advantage) Content that matches DLP rules, such as card numbers or other sensitive data patterns Data that never passes through the proxy
Cloud-delivered firewall Source and destination IP addresses, ports, protocols and applications for tunnelled traffic Traffic that does not go through the tunnel

How identities are attached

Umbrella can only report “who” as precisely as the deployment allows:

  • Network egress IP only: activity is logged against the office or site, not the person.
  • Virtual appliances with Active Directory: activity is tied to internal IP addresses, users and groups.
  • Umbrella module in Cisco Secure Client: activity is tied to the device, and to the user when AD integration is set up, on or off the corporate network.

What Umbrella does not track

  • Keystrokes, screenshots or what is shown on screen.
  • Files stored on the device, or activity in apps that never make a network request.
  • Traffic that bypasses it, such as a device using a different DNS server or a personal VPN.
  • Text typed into web apps, unless TLS decryption and DLP inspection are both applied to that traffic.

Logging and retention controls

Administrators choose per policy whether to log all requests, security events only, or nothing. Logs are searchable in the dashboard’s Activity Search and can be exported to an Amazon S3 bucket for a SIEM. In practice, on a managed work device you should assume your employer can see every site you visit at the domain level, and much more if the secure web gateway is in use.