Skip to main content

Cisco Duo

The Cisco Duo Connector provides a secure endpoint to receive authentication logs from the Duo Authentication Logs API. DNIF can collect, normalize, and monitor Cisco authentication logs to help you identify suspicious activity within your workspace in real time.

Pre-requisites
Steps to derive prerequisites:

NOTE : Only administrators with the Owner role can create or modify an Admin API application in the Duo Admin Panel.

  1. Determine the permissions you want to grant to this Admin API application.
    Scroll down to the “Permissions” section of the page and deselect all permission options other than Grant read log (The Admin API application can read authentication, offline access, telephony, and administrator action log information).
Configurations

The following are the configurations to forward Cisco Duo Connector logs to DNIF.‌image 1-3

Field Name Description
 Connector Name Enter a name for the connector
 Integration Key Enter the Cisco Duo Integration Token
 Secret Key Enter the Cisco Duo Secret Token
 API Hostname Enter the Cisco Duo API Hostname
  • Click Save after entering all the required details and click Test Connection, to test the configuration.
  • Connection successful message will be displayed on screen along with the time stamp.