Pull Cisco Duo's authentication telemetry.
Overview
In this guide, you will create integration keys in Cisco Duo to pull authentication telemetry. This telemetry identifies successful and failed multi-factor authentication attempts.
To do this, you’ll need to complete the following steps:
At the end of this configuration, you will provide Radiant Security with the following values:
- API Hostname
- Integration Key
- Secret Key
Prerequisites
To create an API token with permissions to query Duo Authentication Logs, you need to be logged in as an administrator user with at least Owner permissions.
Generate the integration keys
- Log in to the Duo Admin Panel as an Owner.
- Click Applications on the left sidebar.
- Click Protect an Application and locate the entry for Admin API.
- Click Protect to get the integration key, secret key and API hostname.
- Document and store the Integration key, Secret key, and the API hostname before proceeding to the next step.
- Select the Grant read log permission.
- Click Save.
Important note: Be sure to document and store the key values carefully, as it cannot be retrieved later and can present a security risk if used in an unauthorized fashion.
Add the data connector in Radiant Security
We value your opinion. Did you find this article helpful? Share your thoughts by clicking here or reach to our Product and Customer Success teams at support@radiantsecurity.ai
Last updated: 2025-01-22