Cisco Umbrella Schema Versions


I’ve noticed in the Cisco Umbrella admin dashboard that I have the ability to upgrade the schema version used for the logs written by Umbrella to the Cisco-managed S3 storage. We’re currently on schema version 4 and version 8 is available - descriptions of the schema versions are available at

Does anyone know if the Rapid7 Event Source for Cisco Umbrella supports the latest v8 schema, or better yet are you using that schema version successfully with IDR?


Hi @graeme_hamilton I can confirm we added support for the v8 Schema earlier this year, so you should be good to upgrade.


Thanks David for the quick reply and the confirmation.