<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Retrieve past events from AMP in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4105763#M5459</link>
    <description>&lt;P&gt;Hello all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im trying to extract more than 1 month ago events (.csv) from AMP for Endpoints, but without success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to get this info?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Be&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2020 16:24:10 GMT</pubDate>
    <dc:creator>marcelo89_138</dc:creator>
    <dc:date>2020-06-18T16:24:10Z</dc:date>
    <item>
      <title>Retrieve past events from AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4105763#M5459</link>
      <description>&lt;P&gt;Hello all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im trying to extract more than 1 month ago events (.csv) from AMP for Endpoints, but without success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to get this info?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Be&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 16:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4105763#M5459</guid>
      <dc:creator>marcelo89_138</dc:creator>
      <dc:date>2020-06-18T16:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieve past events from AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4105812#M5461</link>
      <description>&lt;P&gt;Hi Marcelo,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for using Cisco Community, regarding your inquiry, unfortunately, the events on the "Event Section" are deleted after 30 days.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the AMP Console, you can find the event section in&amp;nbsp;&lt;STRONG&gt;Analysis → Events&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2020-06-18 at 12.14.30.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/77117iA1E7BF8073EB88F6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-06-18 at 12.14.30.png" alt="Screen Shot 2020-06-18 at 12.14.30.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, we have other logs that are saved for more than 30days, for example, the Audit Logs, you can find this information on&amp;nbsp;&lt;STRONG&gt;Account → Audit Log&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to review the events of a specific device you can find this information directly on the computer, there is a file called "&lt;STRONG&gt;History.db"&amp;nbsp;&lt;/STRONG&gt;inside the AMP Folder (Commonly storage in C → Program Files → Cisco → AMP)&lt;/P&gt;
&lt;P&gt;If you open the file with a DB Browser&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2020-06-18 at 12.22.51.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/77118iD19B6AFE2169C958/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-06-18 at 12.22.51.png" alt="Screen Shot 2020-06-18 at 12.22.51.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2020-06-18 at 12.23.06.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/77119i8A7036D0A8F21494/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-06-18 at 12.23.06.png" alt="Screen Shot 2020-06-18 at 12.23.06.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also create an&amp;nbsp;&lt;STRONG&gt;Event Stream&amp;nbsp;&lt;/STRONG&gt;in order to send the events to a SIEM or a device to save all the events.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create this Event Stream by generating a Read/Write API (On the Console Navigate to&amp;nbsp;&lt;STRONG&gt;Accounts → API Credentials)&lt;/STRONG&gt;, in the following link you can find the documentation of how to create the&amp;nbsp;&lt;STRONG&gt;Event Stream&lt;/STRONG&gt; &lt;A href="https://api-docs.amp.cisco.com/api_resources/EventStream?api_host=api.amp.cisco.com&amp;amp;api_version=v1" target="_blank"&gt;https://api-docs.amp.cisco.com/api_resources/EventStream?api_host=api.amp.cisco.com&amp;amp;api_version=v1&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this information can be useful to you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 17:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4105812#M5461</guid>
      <dc:creator>jesutorr@cisco.com</dc:creator>
      <dc:date>2020-06-18T17:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieve past events from AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4105917#M5468</link>
      <description>&lt;P&gt;Thats great!&lt;/P&gt;&lt;P&gt;I would like to put this event stream into Splunk, is there any step by step guide?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 19:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4105917#M5468</guid>
      <dc:creator>marcelo89_138</dc:creator>
      <dc:date>2020-06-18T19:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieve past events from AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4106327#M5469</link>
      <description>&lt;P&gt;There is no step by step guide, but &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/215350-configure-amp-for-endpoints-event-stream.html" target="_self"&gt;here&lt;/A&gt; is an article about Event Streams and how to set one up.&amp;nbsp; There are also a few Python scripts in github.com/CiscoSecurity that you may find useful.&amp;nbsp; As for the Splunk side, there are two AMP modules you can use.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3670/" target="_blank"&gt;https://splunkbase.splunk.com/app/3670/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/3686/" target="_blank"&gt;https://splunkbase.splunk.com/app/3686/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Hope that helps!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 13:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrieve-past-events-from-amp/m-p/4106327#M5469</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2020-06-19T13:27:04Z</dc:date>
    </item>
  </channel>
</rss>

