<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP: Archiving Events in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3803940#M147</link>
    <description>&lt;P&gt;Thanks Sean, I'll check out the API and Devnet.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Feb 2019 09:46:28 GMT</pubDate>
    <dc:creator>matty-boy</dc:creator>
    <dc:date>2019-02-18T09:46:28Z</dc:date>
    <item>
      <title>AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801024#M105</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We need to archive some events so they're not lost forever after 30 days.&lt;/P&gt;
&lt;P&gt;I believe Splunk can integrate with the AMP API and can do this but alas we do not have Splunk or any other decent SIEM for that matter.&lt;/P&gt;
&lt;P&gt;Any bright ideas on how we could achieve this?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:07:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801024#M105</guid>
      <dc:creator>matty-boy</dc:creator>
      <dc:date>2020-02-21T05:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801052#M114</link>
      <description>&lt;P&gt;I'm assuming you are wanting some type of historical log analysis? If that is the case right now, a SIEM is the only way you are able to extract that data and retain it. There are a number of open source SIEM tools available that can take advantage of the API's available. ELK (Elasticsearch, Logstash, and Kibana) is a popular option. I have not personally used it with AMP, but I can't see any reason it won't work.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 15:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801052#M114</guid>
      <dc:creator>seanmil</dc:creator>
      <dc:date>2019-02-13T15:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801087#M125</link>
      <description>&lt;P&gt;Thank you for the suggestion. I'll take a look at ELK.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 15:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801087#M125</guid>
      <dc:creator>matty-boy</dc:creator>
      <dc:date>2019-02-13T15:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801356#M132</link>
      <description>&lt;P&gt;I would prefer to use ELK its open source with some addons to pay additional and you do your own dashboards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it is easy and simple.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 22:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801356#M132</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-02-13T22:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801592#M135</link>
      <description>&lt;P&gt;Hi BB,&lt;/P&gt;
&lt;P&gt;Thank you for your input.&lt;/P&gt;
&lt;P&gt;I've not used ELK before and like many open source solutions, it looks kind of.... "&lt;EM&gt;involved&lt;/EM&gt;".&lt;/P&gt;
&lt;P&gt;Have you used it for something similar? Can you point me in the direction of a how-to guide to get it set up and extracting events from AMP to be easily used at later date?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801592#M135</guid>
      <dc:creator>matty-boy</dc:creator>
      <dc:date>2019-02-14T08:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801618#M139</link>
      <description>&lt;P&gt;Its still under process in&amp;nbsp; my lab start putting all in place for other device to collect and make kibana dashboard, on hand i do not have document to offer for you now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there is good cisco document others did already that give you idea, how you can start with.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://blogs.cisco.com/security/step-by-step-setup-of-elk-for-netflow-analytics" target="_blank"&gt;https://blogs.cisco.com/security/step-by-step-setup-of-elk-for-netflow-analytics&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the content gateways (AMP for ESA and AMP for WSA), the Malware events are included in the normal logging mechanisms from those products, meaning syslog and/or periodic exports of the underlying log files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you have AMP onsite infrastructure ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801618#M139</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-02-14T08:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801626#M141</link>
      <description>&lt;P&gt;Thank you sir. It's actually AMP4E that we need to extract events from. The events have already happened and we need a way to archive those events as they're only held in the AMP4E dashboard for 30 days.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 09:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3801626#M141</guid>
      <dc:creator>matty-boy</dc:creator>
      <dc:date>2019-02-14T09:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3802069#M144</link>
      <description>&lt;P&gt;The API doc for AMP4E is located here. &lt;A href="https://api-docs.amp.cisco.com/api_resources?api_host=api.amp.cisco.com&amp;amp;api_version=v1" target="_blank"&gt;https://api-docs.amp.cisco.com/api_resources?api_host=api.amp.cisco.com&amp;amp;api_version=v1&lt;/A&gt; You'll be able to massage the data into ELK as you see fit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you haven't already, I'd also explore joining Cisco Devnet. &lt;A href="https://developer.cisco.com/" target="_blank"&gt;https://developer.cisco.com/&lt;/A&gt; You'll gain access to a ton of great development content for the beginner to advance programmer.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 17:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3802069#M144</guid>
      <dc:creator>seanmil</dc:creator>
      <dc:date>2019-02-14T17:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: AMP: Archiving Events</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3803940#M147</link>
      <description>&lt;P&gt;Thanks Sean, I'll check out the API and Devnet.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 09:46:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-archiving-events/m-p/3803940#M147</guid>
      <dc:creator>matty-boy</dc:creator>
      <dc:date>2019-02-18T09:46:28Z</dc:date>
    </item>
  </channel>
</rss>

