Cisco Umbrella

Download 0
Last updated Apr 12, 2026

umbrella-activity-logs

Query activity logs from Cisco Umbrella Reports.

Syntax

umbrella-activity-logs [profile=PROFILE] [duration=DURATION] [from=FROM] [to=TO] [type=TYPE] [order=ORDER]

Options

profile=PROFILE
Optional. Cisco Umbrella connect profile code
duration=DURATION
Optional. Scan only recent data. Use s(second), m(minute), h(hour), d(day), mon(month) time unit.
from=FROM
Optional. Start time of range. yyyyMMddHHmmss format.
to=TO
Optional. End time of range. yyyyMMddHHmmss format.
type=TYPE
Optional. Traffic type. dns, proxy, or firewall
order=ORDER
Optional. Sort order. asc or desc (default: desc)

Output Fields

FieldTypeNameDescription
profileStringProfileCisco Umbrella connect profile code
typeStringTypee.g. dns
timestampDateTimestampe.g. 2026-04-10 03:00:02
domainStringDomaine.g. www.google.com
appStringApplicatione.g. 1Password
actionStringActione.g. PERMIT
external_ipIP addressExternal IPe.g. 198.51.100.1
internal_ipIP addressInternal IPe.g. 198.51.100.1
query_typeStringQuery Typee.g. A
return_codeIntegerReturn Codee.g. 0
identityStringIdentitye.g. Logpresso_Guest
identity_typeStringIdentity Typee.g. network
categoriesStringCategoriese.g. Software/Technology, Computer Security
threatsStringThreatse.g. Malware