<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data retention and Syslog in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4009303#M3210</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco AMP for Endpoints. It is a new installation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to ask if there is a possibility to change the data retention setting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to have data for more than 30 days.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any option to send data to a Syslog server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:12:01 GMT</pubDate>
    <dc:creator>kostasthedelegate</dc:creator>
    <dc:date>2020-02-21T05:12:01Z</dc:date>
    <item>
      <title>Data retention and Syslog</title>
      <link>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4009303#M3210</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco AMP for Endpoints. It is a new installation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to ask if there is a possibility to change the data retention setting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to have data for more than 30 days.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any option to send data to a Syslog server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4009303#M3210</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-02-21T05:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Data retention and Syslog</title>
      <link>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4010981#M3226</link>
      <description>Hello,&lt;BR /&gt;Any ideas?</description>
      <pubDate>Tue, 14 Jan 2020 06:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4010981#M3226</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-01-14T06:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Data retention and Syslog</title>
      <link>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4011068#M3234</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;If you need to have more than 30 days of Events you can always consider to use the AMP API:&lt;BR /&gt;&lt;A href="https://api-docs.amp.cisco.com/api_resources?api_host=api.eu.amp.cisco.com&amp;amp;api_version=v1" target="_blank"&gt;https://api-docs.amp.cisco.com/api_resources?api_host=api.eu.amp.cisco.com&amp;amp;api_version=v1&lt;/A&gt;&lt;BR /&gt;Event section will be the one, which you can use on your SIEM system. There is even special Splunk extension for the Cisco AMP console which gathers such data:&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/3670/" target="_blank"&gt;https://splunkbase.splunk.com/app/3670/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regular syslog is not possible.&lt;/P&gt;
&lt;P&gt;Hope that helps,&lt;BR /&gt;Wojciech&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 09:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4011068#M3234</guid>
      <dc:creator>Wojciech Cecot</dc:creator>
      <dc:date>2020-01-14T09:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Data retention and Syslog</title>
      <link>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4011107#M3241</link>
      <description>Hello Wojciech,&lt;BR /&gt;&lt;BR /&gt;Thank you for your answer.&lt;BR /&gt;Because I am not aware of the API calls. is there any guide, that could be used?&lt;BR /&gt;Especially, I would like to find compatibilities with SIEM systems.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Konstantinos</description>
      <pubDate>Tue, 14 Jan 2020 11:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4011107#M3241</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-01-14T11:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Data retention and Syslog</title>
      <link>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4012831#M3245</link>
      <description>A new resource for third party integrations with AMP is now available:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/products/security/amp-for-endpoints/AMP-endpoints-partners-integrations.html#~third-party-integrations" target="_blank"&gt;https://www.cisco.com/c/en/us/products/security/amp-for-endpoints/AMP-endpoints-partners-integrations.html#~third-party-integrations&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Jan 2020 17:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4012831#M3245</guid>
      <dc:creator>brmcmaho</dc:creator>
      <dc:date>2020-01-16T17:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Data retention and Syslog</title>
      <link>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4013471#M3249</link>
      <description>&lt;P&gt;Thanks a lot!!&lt;/P&gt;&lt;P&gt;Will review it!!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2020 14:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/data-retention-and-syslog/m-p/4013471#M3249</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2020-01-17T14:23:37Z</dc:date>
    </item>
  </channel>
</rss>

