Cisco Umbrella

Download 5
Last updated Apr 13, 2026

umbrella-s3-dns-logs

Scan DNS log files from Cisco Umbrella S3 export bucket.

Syntax

umbrella-s3-dns-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]

Options

profile=PROFILE
Optional. Cisco Umbrella S3 connect profile code
duration=NUM{mon|w|d|h|m|s}
Optional. Scan only recent data. Use s(second), m(minute), h(hour), d(day), mon(month) time unit.
from=yyyyMMddHHmmss
Optional. Start time of range. yyyyMMddHHmmss format.
to=yyyyMMddHHmmss
Optional. End time of range. yyyyMMddHHmmss format.

Output Fields

FieldTypeNameDescription
_timeDateTimee.g. 2026-04-12 23:39:45
profileStringProfileCisco Umbrella S3 connect profile code
domainStringDomaine.g. www.google.com
actionStringActione.g. Allowed
query_typeStringQuery Typee.g. 1 (A)
response_codeStringResponse Codee.g. NOERROR
external_ipIP addressExternal IPe.g. 198.51.100.1
internal_ipIP addressInternal IPe.g. 198.51.100.1
identityStringIdentitye.g. Logpresso_Guest
identity_typeStringIdentity Typee.g. Networks
identitiesStringIdentitiese.g. Logpresso_Guest
identity_typesStringIdentity Typese.g. Networks
categoriesStringCategoriese.g. Search Engines, Application
blocked_categoriesStringBlocked Categoriese.g. Malware
rule_idStringRule IDe.g. 12345
destination_countriesStringDestination Countriese.g. US
org_idStringOrg IDe.g. 8395347