Integrating Cisco Umbrella with Zscaler MDR provides a robust defense-in-depth strategy by combining cloud-based security with advanced threat detection and response. To integrate Cisco Umbrella with Zscaler MDR, follow the procedure below from beginning to end.
Step 1: Zscaler MDR–Create a Zscaler MDR email for alerts
Create a Zscaler MDR provided-email to send Cisco Umbrella alerts for ingestion.
In the Zscaler MDR portal, click Integrations, then click Add Integration.

Type and select Cisco Umbrella (DNS-layer Security).

Click Configure.
Enter a Name for your external alert source.
Select a Display Category.
Under the Ingest Format/Method dropdown, select Cisco Umbrella via Email.
Note: Only Email should be selected for this alert source. For more information, see Supported Integrations.

Click Save Configuration. This will generate the email address you will use to send Cisco Umbrella alerts to.

Click Edit Configuration.
With your alert source configured, click Activate.
With your Zscaler MDR email generated, log in to Cisco Umbrella.
Step 2: Cisco Umbrella–Configure email alerts
Adjust your Cisco Umbrella settings to send generated alerts to your Zscaler MDR-provided email.
From your Cisco Umbrella dashboard, click the Reporting dropdown, and then click Scheduled Reports.
Click +Schedule.
Click Activity Search or Security Activity depending on the type of information you want to send to Zscaler MDR.

Select the type of information you want to include in your alert report.
Enter the recommended configurations below:
Response:
BlockedEvent type:
Select All
When you have selected all of the filters for your alert report, click +Schedule.
Review your filter selections, and then click Continue.
Select a Delivery Schedule, and then click Continue.
Note: Zscaler MDR recommends you select Daily for the Delivery Schedule.

Enter a Name for your Report Title.
Enter the Zscaler MDR email provided in Step 1.7.

Click Save.