Data Source: Cisco Duo Administrator

Description

Data source object for Cisco Duo Administrator

Details

Property Value
Source cisco_duo
Sourcetype cisco:duo:administrator
Name ▲▼ Technique ▲▼ Type ▲▼
Cisco Duo Bulk Policy Deletion Modify Authentication Process TTP
Cisco Duo Bypass Code Generation Modify Authentication Process TTP
Cisco Duo Policy Allow Devices Without Screen Lock Modify Authentication Process TTP
Cisco Duo Policy Allow Network Bypass 2FA Modify Authentication Process TTP
Cisco Duo Policy Allow Old Flash Modify Authentication Process TTP
Cisco Duo Policy Allow Old Java Modify Authentication Process TTP
Cisco Duo Policy Allow Tampered Devices Modify Authentication Process TTP
Cisco Duo Policy Bypass 2FA Modify Authentication Process TTP
Cisco Duo Policy Deny Access Modify Authentication Process TTP
Cisco Duo Policy Skip 2FA for Other Countries Modify Authentication Process TTP
Cisco Duo Set User Status to Bypass 2FA Modify Authentication Process TTP

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">action</span>
  
  <span class="pill kill-chain">actionlabel</span>
  
  <span class="pill kill-chain">ctime</span>
  
  <span class="pill kill-chain">description</span>
  
  <span class="pill kill-chain">eventtype</span>
  
  <span class="pill kill-chain">extracted_eventtype</span>
  
  <span class="pill kill-chain">isotimestamp</span>
  
  <span class="pill kill-chain">object</span>
  
  <span class="pill kill-chain">timestamp</span>
  
  <span class="pill kill-chain">username</span>
  
</div>

Example Log

1{"ctime": "Tue Jul  8 12:28:47 2025", "action": "policy_create", "description": "{\"enroll_policy\": \"Allow Access\", \"name\": \"test4\", \"pretty_trusted_devices\": \"\", \"admin_email\": \"test@test.com\"}", "isotimestamp": "2025-07-08T12:28:47+00:00", "object": "test4", "timestamp": 1751977727, "username": "Test Test", "host": "api-41e72ada.duosecurity.com", "extracted_eventtype": "administrator", "actionlabel": "Added policy"}

Required Output Fields

  • user

Source: GitHub | Version: 1