Cisco Umbrella Activity API

The Activity API from Cisco Umbrella — 7 operation(s) for activity.

Business capability
Threat Detection & Response Management BC-620.30

Operations 7

GET /activity Get Activities (All) #
GET /activity/dns Get Activity DNS #
GET /activity/proxy Get Activity Proxy #
GET /activity/firewall Get Activity Firewall #
GET /activity/intrusion Get Activity Intrusion #
GET /activity/ip Get Activity IP #
GET /activity/amp-retrospective Get Activity AMP Retrospective #

Documentation

📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-admin-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-managed-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-providers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-s3-key-rotation-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-users-roles-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-authentication/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/cloudlock-api-getting-started/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-domains-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-internal-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-network-tunnels-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-networks-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-deployment-policies-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-roaming-computers-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-sites-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-swg-devices-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-tagging-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-virtual-appliances-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-investigate-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-application-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-destination-lists-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-api-usage-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-app-discovery-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reports-overview/
📖
Documentation
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/
📖
APIReference
https://developer.cisco.com/docs/cloud-security/umbrella-api-reference-reporting-overview/

Specifications

Other Resources

🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/key-admin.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/managed-providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/providers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/s3-key-rotation.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/service-providers-console.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/admin/users-roles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/auth/token.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/cloudlock/cloudlock.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-domains.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/internal-networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/network-tunnels.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/networks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/policies.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/roaming-computers.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/sites.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/swg-devices.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/tagging.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/deployments/virtual-appliances.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/investigate/investigate.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/application-lists-internet-umb.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/policies/destination-lists.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/api-usage.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/app-discovery.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/provider-consoles.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/reference/reports/reporting.yaml

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cisco-umbrella-activity-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cisco-umbrella-activity-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cisco Umbrella Reporting Activity API
  description: The Reporting API provides the data to generate the Umbrella reports.
  version: 2.0.0
  contact:
    name: Cloud Security Developer Community
  x-provenance:
    method: harvested
    authored_by: Cisco Umbrella
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: pubhub.devnetcloud.com
    note: 26 first-party OpenAPI 3.0 documents (256 operations) listed by Cisco's own docs-nav config and fetched anonymously. Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source.
  x-evidence:
  - type: source
    url: https://pubhub.devnetcloud.com/media/cloud-security-apis-in-eft/docs/umbrella-config.json
  - type: source
    url: https://developer.cisco.com/docs/cloud-security/
servers:
- url: https://api.umbrella.com/{basePath}
  variables:
    basePath:
      default: reports/v2
security:
- oauthFlow: []
tags:
- name: Activity
paths:
  /activity:
    get:
      tags:
      - Activity
      summary: Get Activities (All)
      description: 'List all activities (dns/proxy/firewall/intrusion) within the timeframe.

        **Note:** The IP activity report is not available.


        **Access Scope:** Reports > Granular Events > Read-Only'
      operationId: getActivities
      security:
      - oauthFlow:
        - reports.granularEvents:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/domainsParam'
      - $ref: '#/components/parameters/urlsParam'
      - $ref: '#/components/parameters/categoriesParam'
      - $ref: '#/components/parameters/policyCategoriesParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/portsParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/identityTypesParam'
      - $ref: '#/components/parameters/applicationIdParam'
      - $ref: '#/components/parameters/verdictParam'
      - $ref: '#/components/parameters/ruleIdParam'
      - $ref: '#/components/parameters/filenameParam'
      - $ref: '#/components/parameters/securityOverriddenParam'
      - $ref: '#/components/parameters/bundleIdParam'
      - $ref: '#/components/parameters/threatsParam'
      - $ref: '#/components/parameters/threatTypesParam'
      - $ref: '#/components/parameters/ampDispositionParam'
      - $ref: '#/components/parameters/antivirusThreatsParam'
      - $ref: '#/components/parameters/xTrafficTypeParam'
      - $ref: '#/components/parameters/isolatedStateParam'
      - $ref: '#/components/parameters/isolatedFileActionParam'
      - $ref: '#/components/parameters/dataLossPreventionStateParam'
      - $ref: '#/components/parameters/filterNoisyDomainsParam'
      - $ref: '#/components/parameters/httpErrorsParam'
      - $ref: '#/components/parameters/existsParam'
      - $ref: '#/components/parameters/timezoneParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      anyOf:
                      - $ref: '#/components/schemas/ActivityDns'
                      - $ref: '#/components/schemas/ActivityFirewall'
                      - $ref: '#/components/schemas/ActivityIntrusion'
                      - $ref: '#/components/schemas/ActivityProxy'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                meta: {}
                data:
                - externalip: 52.8.160.247
                  internalip: 52.8.160.247
                  policycategories:
                  - id: 66
                    label: Malware
                    type: security
                    integration: true
                  categories:
                  - id: 66
                    label: Malware
                    type: security
                    integration: true
                  verdict: allowed
                  domain: google.com
                  timestamp: 1731002169000
                  time: 06:31:46
                  date: '2019-01-24'
                  identities:
                  - id: 1
                    label: Catch Rate Testing System
                    type:
                      id: 21
                      label: Sites
                      type: site
                    deleted: true
                  threats:
                  - label: Wannacry
                    type: Ransomware
                  allapplications:
                  - id: 1
                    label: label
                    type: NBAR
                    category:
                      id: 1
                      label: category
                  allowedapplications:
                  - id: 1
                    label: label
                    type: NBAR
                    category:
                      id: 1
                      label: category
                  querytype: MX
                  returncode: 2
                  blockedapplications: []
                  type: dns
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /activity/dns:
    get:
      tags:
      - Activity
      summary: Get Activity DNS
      description: 'List all DNS entries within the timeframe.


        **Access Scope:** Reports > Granular Events > Read-Only'
      operationId: getActivityDns
      security:
      - oauthFlow:
        - reports.granularEvents:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/orderParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/domainsParam'
      - $ref: '#/components/parameters/categoriesParam'
      - $ref: '#/components/parameters/policyCategoriesParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/identityTypesParam'
      - $ref: '#/components/parameters/applicationIdParam'
      - $ref: '#/components/parameters/verdictParam'
      - $ref: '#/components/parameters/threatsParam'
      - $ref: '#/components/parameters/threatTypesParam'
      - $ref: '#/components/parameters/filterNoisyDomainsParam'
      - $ref: '#/components/parameters/timezoneParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ActivityDns'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - externalip: 52.8.160.247
                  internalip: 52.8.160.247
                  policycategories:
                  - id: 66
                    label: Malware
                    type: security
                    integration: true
                  categories:
                  - id: 66
                    label: Malware
                    type: security
                    integration: true
                  verdict: allowed
                  domain: google.com
                  timestamp: 1731002169000
                  time: 06:31:46
                  date: '2019-01-24'
                  identities:
                  - id: 1
                    label: Catch Rate Testing System
                    type:
                      id: 21
                      label: Sites
                      type: site
                    deleted: true
                  threats:
                  - label: Wannacry
                    type: Ransomware
                  allapplications:
                  - id: 1
                    label: label
                    type: NBAR
                    category:
                      id: 1
                      label: category
                  allowedapplications:
                  - id: 1
                    label: label
                    type: NBAR
                    category:
                      id: 1
                      label: category
                  querytype: MX
                  returncode: 2
                  blockedapplications: []
                  type: dns
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /activity/proxy:
    get:
      tags:
      - Activity
      summary: Get Activity Proxy
      description: 'List all proxy entries within the timeframe.


        **Access Scope:** Reports > Granular Events > Read-Only'
      operationId: getActivityProxy
      security:
      - oauthFlow:
        - reports.granularEvents:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/orderParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/domainsParam'
      - $ref: '#/components/parameters/urlsParam'
      - $ref: '#/components/parameters/categoriesParam'
      - $ref: '#/components/parameters/policyCategoriesParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/portsParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/identityTypesParam'
      - $ref: '#/components/parameters/applicationIdParam'
      - $ref: '#/components/parameters/verdictParam'
      - $ref: '#/components/parameters/ruleIdParam'
      - $ref: '#/components/parameters/filenameParam'
      - $ref: '#/components/parameters/securityOverriddenParam'
      - $ref: '#/components/parameters/bundleIdParam'
      - $ref: '#/components/parameters/threatsParam'
      - $ref: '#/components/parameters/threatTypesParam'
      - $ref: '#/components/parameters/ampDispositionParam'
      - $ref: '#/components/parameters/antivirusThreatsParam'
      - $ref: '#/components/parameters/tenantControlsParam'
      - $ref: '#/components/parameters/isolatedStateParam'
      - $ref: '#/components/parameters/isolatedFileActionParam'
      - $ref: '#/components/parameters/dataLossPreventionStateParam'
      - $ref: '#/components/parameters/httpErrorsParam'
      - $ref: '#/components/parameters/timezoneParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ActivityProxy'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - destinationip: ''
                  externalip: 32.4.91.7
                  responsesize: 3329530
                  allapplications:
                  - id: 1313
                    label: Netflix
                    category:
                      id: 47
                      label: Media
                  date: '2022-02-18'
                  datalossprevention:
                    state: ''
                  antivirusthreats:
                    puas: []
                    viruses: []
                    others: []
                  internalip: 192.168.1.43
                  referer: ''
                  contenttype: ''
                  tenantcontrols: false
                  securityoverridden: false
                  useragent: ''
                  time: '23:29:42'
                  amp:
                    disposition: ''
                    score: 0
                    malware: ''
                  policycategories: []
                  type: proxy
                  requestsize: 1996
                  port: 443
                  policy:
                    ruleid: 0
                    rulesetid: 0
                    destinationlistids: []
                    timebasedrule: false
                  forwardingmethod: ''
                  categories:
                  - id: 17
                    type: content
                    label: Movies
                    integration: false
                    deprecated: true
                  isolated:
                    state: not-isolated
                    fileaction: ''
                  statuscode: 200
                  egress:
                    ip: 155.190.3.8
                    type: shared
                  blockedfiletype: ''
                  url: https://ipv4-lax2-ix.1.oca.anothervideo.net
                  verdict: allowed
                  responsefilename: ''
                  warnstatus: ''
                  sha256: ''
                  timestamp: 1645226982000
                  blockedapplications: []
                  allowedapplications: []
                  identities:
                  - id: 1
                    type:
                      id: 34
                      type: anyconnect
                      label: Anyconnect Roaming Client
                    label: Vincent's Macbook
                    deleted: false
                  datacenter:
                    label: Los Angeles, US
                    id: LAX
                  threats: []
                  httperrors: []
                  bundleid: 3
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /activity/firewall:
    get:
      tags:
      - Activity
      summary: Get Activity Firewall
      description: 'List all firewall activity within the timeframe.


        **Access Scope:** Reports > Granular Events > Read-Only'
      operationId: getActivityFirewall
      security:
      - oauthFlow:
        - reports.granularEvents:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/ruleIdParam'
      - $ref: '#/components/parameters/verdictParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/portsParam'
      - $ref: '#/components/parameters/timezoneParam'
      - $ref: '#/components/parameters/categoriesParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ActivityFirewall'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - date: '2019'
                  destinationip: 52.8.160.247
                  sourceip: 192.168.0.1
                  sourceport: 0
                  destinationport: 0
                  categories:
                  - id: 66
                    label: Malware
                    type: security
                    integration: true
                  verdict: allowed
                  time: '12:34'
                  timestamp: 1731002169000
                  identities:
                  - id: 1
                    label: Catch Rate Testing System
                    type:
                      id: 21
                      label: Sites
                      type: site
                    deleted: false
                  protocol:
                    id: 17
                    label: UDP
                  rule:
                    id: 1
                    label: Default Rule
                  type: firewall
                  allapplications:
                  - id: 72
                    label: dns IT Service Management
                    app: ''
                  applicationprotocols:
                  - id: 72
                    label: dns IT Service Management
                    app: ''
                  packetsize: 32
                  direction: towards
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /activity/intrusion:
    get:
      tags:
      - Activity
      summary: Get Activity Intrusion
      description: 'List all Intrusion Prevention System (IPS) activity within the timeframe.


        **Access Scope:** Reports > Granular Events > Read-Only'
      operationId: getActivityIntrusion
      security:
      - oauthFlow:
        - reports.granularEvents:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/signaturesParam'
      - $ref: '#/components/parameters/signatureListIdsParam'
      - $ref: '#/components/parameters/intrusionActionParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/portsParam'
      - $ref: '#/components/parameters/filterNoisyDomainsParam'
      - $ref: '#/components/parameters/timezoneParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ActivityIntrusion'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - type: intrusion
                  date: 12-02-22
                  destinationip: 10.10.10.10
                  protocol:
                    id: 17
                    label: UDP
                  sourceip: 10.10.10.10
                  signaturelist:
                    id: 1111
                  classification: malicious
                  rule:
                  - id: 391327
                    label: UNKNOWN
                  ipsProfile: PROFILE
                  sourceport: 22
                  sessionid: 190898098
                  verdict: detected
                  destinationport: 33
                  timestamp: 1594557262000
                  time: 09:30
                  identities:
                  - id: 211034846
                    type:
                      id: 34
                      type: anyconnect
                      label: Anyconnect Roaming Client
                    label: omerta
                    deleted: false
                  severity: HIGH
                  signature:
                    generatorid: 1
                    id: 47829
                    label: SERVER-OTHER JBoss Richfaces expression language injection attempt
                    cves:
                    - cve-2015-0279
                    - cve-2018-12532
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /activity/ip:
    get:
      tags:
      - Activity
      summary: Get Activity IP
      description: '(Deprecated) List all IP activity within the timeframe.


        **Access Scope:** Reports > Granular Events > Read-Only'
      operationId: getActivityIP
      security:
      - oauthFlow:
        - reports.granularEvents:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/identityIdsParam'
      - $ref: '#/components/parameters/identityTypesParam'
      - $ref: '#/components/parameters/categoriesParam'
      - $ref: '#/components/parameters/verdictParam'
      - $ref: '#/components/parameters/ipParam'
      - $ref: '#/components/parameters/portsParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items: {}
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data: []
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
  /activity/amp-retrospective:
    get:
      tags:
      - Activity
      summary: Get Activity AMP Retrospective
      description: 'List all AMP retrospective activity within the timeframe.


        **Access Scope:** Reports > Granular Events > Read-Only'
      operationId: getActivityAmpRetrospective
      security:
      - oauthFlow:
        - reports.granularEvents:read
      parameters:
      - $ref: '#/components/parameters/fromParam'
      - $ref: '#/components/parameters/toParam'
      - $ref: '#/components/parameters/offsetParam'
      - $ref: '#/components/parameters/limitParam'
      - $ref: '#/components/parameters/ampDispositionParam'
      - $ref: '#/components/parameters/sha256Param'
      - $ref: '#/components/parameters/timezoneParam'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/ActivityAMPRetro'
                  meta:
                    $ref: '#/components/schemas/Meta'
                required:
                - data
                - meta
              example:
                data:
                - timestamp: 1548311506
                  firstseenat: 1548311506
                  disposition: clean
                  score: 10
                  hostname: google.com
                  malwarename: malware
                  sha256: 9495b6c155044053953efe30ebaf804780c114e7b721b14f6a5b0a782769696e
                meta: {}
        '400':
          $ref: '#/components/responses/400Error'
        '401':
          $ref: '#/components/responses/401Error'
        '403':
          $ref: '#/components/responses/403Error'
        '404':
          $ref: '#/components/responses/404Error'
        '500':
          $ref: '#/components/responses/500Error'
components:
  parameters:
    fromParam:
      name: from
      in: query
      description: 'A timestamp or relative time string (for example: ''-1days'').

        Filter for data that appears after this time.'
      required: true
      schema:
        type: string
      example: '1639146300000'
    policyCategoriesParam:
      name: policycategories
      in: query
      description: 'A category ID or comma-delimited list of category ID.

        Filter the request by the categories that trigger a policy.'
      schema:
        type: string
      example: 67,69
    categoriesParam:
      name: categories
      in: query
      description: A category ID or comma-delimited list of category ID.
      schema:
        type: string
      example: 148,151,66
    threatTypesParam:
      name: threattypes
      in: query
      description: A threat type or comma-delimited list of threat types.
      schema:
        type: string
    httpErrorsParam:
      name: httperrors
      in: query
      description: Filter data for requests that resulted in a TLS error or a certificate error.
      schema:
        type: string
        enum:
        - certificateerror
        - tlserror
      example: certificateerror
    limitParam:
      name: limit
      in: query
      description: The maximum number of records to return from the collection.
      required: true
      schema:
        type: number
        default: 100
      example: 100
    existsParam:
      name: exists
      in: query
      description: 'Specify an attribute or comma-separated list of attributes to filter the data.

        Valid values are: `categories`, `policycategories`, `applicationid`,

        `nbarapplicationid`, `nbarapplicationtypeids`, `privateapplicationid`, `applicationgroupids`,

        `sha256`, `filename`, `threats`, `threattypes`, `antivirusthreats`, `destinationlistids`, and `httperrors`.'
      schema:
        type: string
      example: destinationlistids,threattypes
    ruleIdParam:
      name: ruleid
      in: query
      description: The firewall policy rule ID.
      schema:
        type: number
      example: 1
    applicationIdParam:
      name: applicationid
      in: query
      description: The ID of the application.
      schema:
        type: string
      example: '1'
    sha256Param:
      name: sha256
      in: query
      description: A SHA-256 hash.
      schema:
        type: string
      example: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
    filterNoisyDomainsParam:
      name: filternoisydomains
      in: query
      description: Filter out domains that generate a lot of insignificant traffic (noise).
      schema:
        type: boolean
      example: true
    domainsParam:
      name: domains
      in: query
      description: A domain name or comma-delimited list of domain name.
      schema:
        type: string
      example: cisco.com,nasa.gov
    ampDispositionParam:
      name: ampdisposition
      in: query
      description: An AMP disposition string or a comma-delimited list of AMP disposition strings.
      schema:
        type: string
      example: clean,malicious,unknown
    threatsParam:
      name: threats
      in: query
      description: A threat name or comma-delimited list of threat names.
      schema:
        type: string
    ipParam:
      name: ip
      in: query
      description: An IP address.
      schema:
        type: string
      example: 10.10.10.10
    urlsParam:
      name: urls
      in: query
      description: A URL or comma-delimited list of URL.
      schema:
        type: string
      example: https://google.com,facebook.com/help
    toParam:
      name: to
      in: query
      description: 'A timestamp or relative time string (for example: ''now'').

        Filter for data that appears before this time.'
      required: true
      schema:
        type: string
      example: '1640010300000'
    isolatedStateParam:
      name: isolatedstate
      in: query
      description: A string that describes the remote browser isolation (RBI) isolation type.
      schema:
        type: string
        enum:
        - isolated
        - not-isolated
      example: isolated
    dataLossPreventionStateParam:
      name: datalosspreventionstate
      in: query
      description: 'A string that describes the status of a destination.

        Filter for requests that are blocked by the DLP layer security.'
      schema:
        type: string
        enum:
        - blocked
      example: blocked
    isolatedFileActionParam:
      name: isolatedFileAction
      in: query
      description: A string that describes the remote browser isolation (RBI) file action type.
      schema:
        type: string
        enum:
        - viewed
        - downloaded-original-file
        - downloaded-safe-pdf
      example: downloaded-safe-pdf
    securityOverriddenParam:
      name: securityoverridden
      in: query
      description: Specify whether to filter on requests that override security.
      schema:
        type: boolean
      example: true
    identityIdsParam:
      name: identityids
      in: query
      description: An identity ID or comma-delimited list of identity IDs.
      schema:
        type: string
      example: 1,2,3
    identityTypesParam:
      name: identitytypes
      in: query
      description: An identity type or comma-delimited list of identity types.
      schema:
        type: string
      example: network,roaming
    bundleIdParam:
      name: bundleid
      in: query
      description: A proxy bundle ID.
      schema:
        type: number
      example: 1
    signatureListIdsParam:
      name: signaturelistids
      in: query
      description: The signature ID or comma-separated list of signature list IDs.
      schema:
        type: string
      example: 1,2
    antivirusThreatsParam:
      name: antivirusthreats
      in: query
      description: A threat name or comma-delimited list of threat names.
      schema:
        type: string
      example: Trojan.Linux.Generic.144075
    orderParam:
      name: order
      in: query
      description: 'A string that describes how to order the results: ascending (`asc`) or descending (`desc`).'
      schema:
        type: string
        enum:
        - asc
        - desc
      example: desc
    filenameParam:
      name: filename
      in: query
      description: 'A string that identifies a filename. Filter the request by the filename.

        Supports globbing or use of the wildcard character (''*''). The asterisk (*) matches

        zero or more occurrences of any character.'
      schema:
        type: string
      example: myfilename_*
    verdictParam:
      name: verdict
      in: query
      description: A string or comma-delimited string that describes whether the traffic can reach the destination.
      schema:
        type: string
      example: allowed,blocked,proxied
    timezoneParam:
      name: timezone
      in: query
      description: 'Display the timestamp of the traffic events in the specified timezone.

        For the timezone, provide a continent and city separated by an url-encoded forward slash (''/''), for example: timezone=''ASIA%2fCALCUTTA''.'
      schema:
        type: string
      example: ASIA%2fCALCUTTA
    signaturesParam:
      name: signatures
      in: query
      description: The signature or comma-separated list of <signatureid>-<generatorid> signatures.
      schema:
        type: string
      example: 1-2,1-4
    offsetParam:
      name: offset
      in: query
      description: A number that represents an index in the collection.
      schema:
        type: number
        default: 0
      example: 0
    xTrafficTypeParam:
      name: x-traffic-type
      in: header
      description: 'A string or comma-delimited list of strings that describes the type of traffic.

        If the heade

# --- truncated at 32 KB (64 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-umbrella/refs/heads/main/openapi/cisco-umbrella-activity-api-openapi.yml