インテグレーションバージョン1.0.0

To find out if this integration is available in your organization, see your Datadog Integrations page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email [email protected].

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Overview

Cisco Duo is a multi-factor authentication (MFA) and secure access solution. It adds an additional layer of security by requiring users to verify their identity through a second factor, such as a mobile app, before gaining access to applications or systems. Duo is often used to enhance the security of remote access and helps protect against unauthorized access, even if passwords are compromised.

This integration ingests the following logs:

  • Authentication
  • Activity
  • Administrator
  • Telephony
  • Offline Enrollment

Note: The Administrator and Offline Enrollment log endpoints and dashboards are being deprecated. Update any custom assets using these endpoints to use the Activity Logs endpoint instead to avoid service disruption.

The Cisco Duo integration seamlessly collects multi-factor authentication (MFA) and secure access logs, channeling them into Datadog for analysis. Leveraging the built-in logs pipeline, these logs are parsed and enriched, enabling effortless search and analysis. The integration provides insight into fraud authentication events, authentication activity timeline, locations of accessed, authentication devices, and many more through the out-of-the-box dashboards.

Setup

This integration does not support Duo Federal accounts (duofederal.com domains). Only standard Duo accounts (duosecurity.com domains) are supported.

Configuration

Get API Credentials of Cisco Duo

  1. Sign up for a Duo account.
  2. Log in to the Duo Admin Panel.
  3. Navigate to Applications.
  4. Click Protect an Application and locate the entry for Admin API in the applications list.
  5. Click Protect to configure the application and retrieve your integration key, secret key, and API hostname. This information will be used to configure the Cisco Duo integration.
  6. Ensure the Grant read log permission is selected and click Save Changes.

Cisco Duo DataDog Integration Configuration

Configure the Datadog endpoint to forward Cisco Duo logs to Datadog.

  1. Navigate to Cisco Duo.
  2. Add your Cisco Duo credentials.
Cisco Duo ParametersDescription
HostThe API Hostname from Cisco Duo. It is the XXXXXXXX part of https://api-XXXXXXXX.duosecurity.com.
Integration KeyThe Integration Key from Cisco Duo.
Secret KeyThe Secret Key from Cisco Duo.

Data Collected

Logs

The Cisco Duo integration collects and forwards Cisco Duo Authentication, Activity, Administrator, Telephony and Offline Enrollment logs to Datadog.

Metrics

The Cisco Duo integration does not include any metrics.

Events

The Cisco Duo integration does not include any events.

Support

For further assistance, contact Datadog Support.