<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can CISCO AMP integrate with QRadar in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560420#M1399</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Moving to &lt;A href="https://community.cisco.com/space/4781"&gt;Advanced Malware Protection (AMP)&lt;/A&gt; ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Sep 2016 17:25:27 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2016-09-07T17:25:27Z</dc:date>
    <item>
      <title>Can CISCO AMP integrate with QRadar</title>
      <link>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560419#M1395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it possible to integrate CISCO AMP (all modules, i.e Endpoint, network, ESA,WSA and Threatgrid) to IBM QRadar SIEM solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, is it possible for me to view from QRadar all the malicious file or flow activities that has been detected by CISCO AMP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another question, what is the format of the CISCO AMP logs (CEF, LEEF,...etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks guys,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560419#M1395</guid>
      <dc:creator>sherif.hassan</dc:creator>
      <dc:date>2020-02-21T05:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can CISCO AMP integrate with QRadar</title>
      <link>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560420#M1399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Moving to &lt;A href="https://community.cisco.com/space/4781"&gt;Advanced Malware Protection (AMP)&lt;/A&gt; ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2016 17:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560420#M1399</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-09-07T17:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can CISCO AMP integrate with QRadar</title>
      <link>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560421#M1401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the case of AMP for Networks, the Malware events are available from Firepower Management Center (FMC) via eStreamer, which is widely supported by SIEMS, including (I am pretty sure) QRader.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the case of AMP for Endpoints, until relatively recently the recommended way to get those events into a SIEM was to integrate your endpoint cloud console with FMC and then use eStreamer, as above.&amp;nbsp; With the API that is now available in the AMP for Endpoints product, it is now possible for SIEM vendors to retrieve events directly; I don't know if QRadar has done so yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Threat Grid has had a richly functional API from day one -- literally.&amp;nbsp; They made the strategic decision to build the entire product around the API from the ground up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the content gateways (AMP for ESA and AMP for WSA), the Malware events are included in the normal logging mechanisms from those products, meaning syslog and/or periodic exports of the underlying log files.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2016 17:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560421#M1401</guid>
      <dc:creator>brmcmaho</dc:creator>
      <dc:date>2016-09-07T17:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can CISCO AMP integrate with QRadar</title>
      <link>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560422#M1403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;H5 class="simple"&gt;brmcmaho already provided you the answer. Below is the doc link which help you to integrate QRader with FMC&lt;/H5&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.5/com.ibm.dsm.doc/c_dsm_guide_sourcefire_dc_overview.html" title="http://www.ibm.com/support/knowledgecenter/SS42VS_7.2.5/com.ibm.dsm.doc/c_dsm_guide_sourcefire_dc_overview.html"&gt;IBM Knowledge Center&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2017 09:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/can-cisco-amp-integrate-with-qradar/m-p/3560422#M1403</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2017-01-12T09:10:31Z</dc:date>
    </item>
  </channel>
</rss>

