Integrations

Note: Only users with an Administrator role can add integrations.

With Cisco XDR, incident responders, threat hunters, and security analysts can better understand threats on their network by gathering, combining, and correlating local security observations (for example, EDR detections and network security alerts), networks and system telemetry (such as netflow data and system process details), and threat intelligence (such as Cisco Talos alerts about known threat actors). It brings together threat intelligence and local security context and control from multiple products all in one place for the security analyst. Each source of global or local intelligence is provided by an integration.

Cisco XDR offers integrations for Cisco security products and third-party solutions. The Integrations page allows you to configure and view your integrations, and to view all Cisco and third-party integrations that are available for configuration. For Cisco integrations, click Free Trial for information on how to try out the Cisco product, if available.

Integrated products are leveraged via their APIs. Authentication methods may vary per product but are typically API tokens or keys. Integrated products must be reachable from Cisco XDR's cloud infrastructure. For on-premises products, this can be accomplished via port forwarding, Automation Remote, or registering and configuring them as on-premises appliances.

Note: The threat intelligence and IT Service Management (ITSM) third-party integrations are included with the Cisco XDR Essentials licensing tier and all other third-party integrations require Cisco XDR Advantage or Cisco XDR Premier licensing tier. For details, see the Minimum Cisco XDR Licensing Tier Required column in Cisco and Third-Party Integrations and Supported Capabilities. If your organization's licensing tier is Cisco XDR Essentials, the threat intelligence and ITSM third-party integrations are available and a message is displayed at the top of the Third-Party tab with additional information on how to upgrade the license to access all third-party integrations and learn more about custom integrations. You can view your organization's licensing tier on the My Account page. For more information on the licensing tiers, see Cisco XDR Licenses.

Available Integrations

Cisco Secure Cloud Analytics is now a part of Cisco XDR. You can configure the following integrations in Secure Cloud Analytics to collect telemetry for incident detection and correlation in Cisco XDR: Cisco Meraki, Cisco Umbrella, Cisco ISE, Cisco Attack Surface Management, Amazon Web Services, Microsoft Azure, Google Cloud Platform, and Kubernetes. For more information on configuring the Secure Cloud Analytics integrations, see Secure Cloud Analytics Documentation.