<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is cisco AMP support integration with SIEM? in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/is-cisco-amp-support-integration-with-siem/m-p/4467253#M6395</link>
    <description>&lt;P&gt;Is Cisco security support integration with any SIEM solution, if yes please update me with more details&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 20:50:48 GMT</pubDate>
    <dc:creator>RafikWassef</dc:creator>
    <dc:date>2021-09-15T20:50:48Z</dc:date>
    <item>
      <title>Is cisco AMP support integration with SIEM?</title>
      <link>https://community.cisco.com/t5/endpoint-security/is-cisco-amp-support-integration-with-siem/m-p/4467253#M6395</link>
      <description>&lt;P&gt;Is Cisco security support integration with any SIEM solution, if yes please update me with more details&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 20:50:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/is-cisco-amp-support-integration-with-siem/m-p/4467253#M6395</guid>
      <dc:creator>RafikWassef</dc:creator>
      <dc:date>2021-09-15T20:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is cisco AMP support integration with SIEM?</title>
      <link>https://community.cisco.com/t5/endpoint-security/is-cisco-amp-support-integration-with-siem/m-p/4467263#M6396</link>
      <description>Various SEIM products have ways to get events from AMP, but AMP can't push the events.&lt;BR /&gt;&lt;BR /&gt;Logrhythm has a beat for their Open Collector to pull AMP events into the SEIM via the API. (its all based on elastic beats)&lt;BR /&gt;I think Splunk and QRadar both have something similar. Here's Cisco Doc for splunk&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/215973-amp-for-endpoints-integration-with-splun.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/215973-amp-for-endpoints-integration-with-splun.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You may find some useful info and options in SecureX (dashboards/orchestration/incident managment/automated actions, etc.)&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 15 Sep 2021 21:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/is-cisco-amp-support-integration-with-siem/m-p/4467263#M6396</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2021-09-15T21:07:10Z</dc:date>
    </item>
  </channel>
</rss>

