<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CISCO Secure Endpoint Third Party Integration Recommendations in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-third-party-integration-recommendations/m-p/4486929#M6440</link>
    <description>&lt;P&gt;We have a client who is deploying CISCO Secure Endpoint across their organization and would like to forward critical and high alerts/notifications to our cybersecurity platform.&amp;nbsp; We can support syslogs, custom logs or integration via a REST or other style of API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are wondering if there is a recommended/preferred approach?&amp;nbsp; We have been searching to find an answer and don't seem to be getting very far.&amp;nbsp; If you have any suggestions, pointers to articles, presentations or documentation that would be greatly appreciate.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Oct 2021 13:28:02 GMT</pubDate>
    <dc:creator>ShoreSempai</dc:creator>
    <dc:date>2021-10-15T13:28:02Z</dc:date>
    <item>
      <title>CISCO Secure Endpoint Third Party Integration Recommendations</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-third-party-integration-recommendations/m-p/4486929#M6440</link>
      <description>&lt;P&gt;We have a client who is deploying CISCO Secure Endpoint across their organization and would like to forward critical and high alerts/notifications to our cybersecurity platform.&amp;nbsp; We can support syslogs, custom logs or integration via a REST or other style of API.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are wondering if there is a recommended/preferred approach?&amp;nbsp; We have been searching to find an answer and don't seem to be getting very far.&amp;nbsp; If you have any suggestions, pointers to articles, presentations or documentation that would be greatly appreciate.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 13:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-third-party-integration-recommendations/m-p/4486929#M6440</guid>
      <dc:creator>ShoreSempai</dc:creator>
      <dc:date>2021-10-15T13:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO Secure Endpoint Third Party Integration Recommendations</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-third-party-integration-recommendations/m-p/4486938#M6441</link>
      <description>There is an API. API docs are here: &lt;A href="https://api-docs.amp.cisco.com/" target="_blank"&gt;https://api-docs.amp.cisco.com/&lt;/A&gt;&lt;BR /&gt;There's a whole developer site on Dev net here: &lt;A href="https://developer.cisco.com/amp-for-endpoints/" target="_blank"&gt;https://developer.cisco.com/amp-for-endpoints/&lt;/A&gt;&lt;BR /&gt;Depending upon your platform/SEIM, they may already have facilities to do the ingestion. Splunk surely does. Logrhythm does (OpenCollector, plus someone posted python -&amp;gt; flatfile ingestion years ago...)&lt;BR /&gt;Also this page: &lt;A href="https://ciscosecurity-amp-00-integration-workflows.readthedocs-hosted.com/en/latest/amp/intro.html" target="_blank"&gt;https://ciscosecurity-amp-00-integration-workflows.readthedocs-hosted.com/en/latest/amp/intro.html&lt;/A&gt;&lt;BR /&gt;Google "cisco amp api"... in the first 3 pages all of the big players pop up.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 15 Oct 2021 13:44:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-third-party-integration-recommendations/m-p/4486938#M6441</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2021-10-15T13:44:35Z</dc:date>
    </item>
  </channel>
</rss>

