Details

This atomic belongs to the Cisco Umbrella (v2) atomic group.

Gets a list of activity from within the given timeframe from Cisco Umbrella. If no activity type is provided, all types will be included. See the "Activity Type" input variable for more information about supported filters. The "Additional Parameters" input variable can be used to provide additional query string parameters which will be passed through to Umbrella. This atomic requires read permission to the "Reports / Aggregations" API scope.

Target: Umbrella integration target or HTTP Endpoint for "api.umbrella.com" with no path

Account Key: None if using an integration-provided target, access token if using an HTTP Endpoint target

Steps:
[] Build the authorization header
[] Check if an activity type was provided and, if so, update the URL
[] Make the API request for the report entries
[] Check if the API request succeeded:
[]> If it did, set the output variable
[]> If it didn't, output an error

More information about this API: https://developer.cisco.com/docs/cloud-security/get-activities-all/

About
Integration
Authorship
Cisco Managed