<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure Endpoint CLI  Usage &amp;amp; Documentation in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-cli-usage-amp-documentation/m-p/4492127#M6460</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if Secure Endpoint has any CLI-based tools to assist in remote work on an endpoint itself (e.g., disable the service for troubleshooting, enable debug logging without using the GUI, get/change configuration, etc.); and, if so, if there is accompanying documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"C:\Program Files\Cisco\AMP\*\ipsupporttool.exe"&lt;/P&gt;&lt;P&gt;This seems like a diagnostic tool ( akin to the GUI-based Diagnostics button for computers ), and the IPSupportTool log suggests there are switches for it ([-h] [-d install_path] [-o output_path] [-t timed_support] [-m archive_size] [-j job_id] [-H time_stamp]). However these switches don't appear to work nor is there an archive created post-execution. It just dumps some files in 'C:\Program Files\Cisco\AMP' (installed_app.csv, running_process.csv, installed_services.csv, systeminfo.txt, etc.). These files do not appear to be in the resultant archive from the Console-based 'Diagnostics' feature for a computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"C:\Program Files\Cisco\AMP\*\AmpCLI.exe"&lt;/P&gt;&lt;P&gt;Would appear to be the right tool, but only looks to have one option (posture) that prints basic Secure Endpoint status information&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"C:\Program Files\Cisco\AMP\*\sfc.exe"&lt;/P&gt;&lt;P&gt;Seems to be the primary Secure Endpoint process for scanning and such, but no CLI interface options&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Mon, 25 Oct 2021 19:51:18 GMT</pubDate>
    <dc:creator>TruthNotTruth</dc:creator>
    <dc:date>2021-10-25T19:51:18Z</dc:date>
    <item>
      <title>Secure Endpoint CLI  Usage &amp; Documentation</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-cli-usage-amp-documentation/m-p/4492127#M6460</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if Secure Endpoint has any CLI-based tools to assist in remote work on an endpoint itself (e.g., disable the service for troubleshooting, enable debug logging without using the GUI, get/change configuration, etc.); and, if so, if there is accompanying documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"C:\Program Files\Cisco\AMP\*\ipsupporttool.exe"&lt;/P&gt;&lt;P&gt;This seems like a diagnostic tool ( akin to the GUI-based Diagnostics button for computers ), and the IPSupportTool log suggests there are switches for it ([-h] [-d install_path] [-o output_path] [-t timed_support] [-m archive_size] [-j job_id] [-H time_stamp]). However these switches don't appear to work nor is there an archive created post-execution. It just dumps some files in 'C:\Program Files\Cisco\AMP' (installed_app.csv, running_process.csv, installed_services.csv, systeminfo.txt, etc.). These files do not appear to be in the resultant archive from the Console-based 'Diagnostics' feature for a computer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"C:\Program Files\Cisco\AMP\*\AmpCLI.exe"&lt;/P&gt;&lt;P&gt;Would appear to be the right tool, but only looks to have one option (posture) that prints basic Secure Endpoint status information&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"C:\Program Files\Cisco\AMP\*\sfc.exe"&lt;/P&gt;&lt;P&gt;Seems to be the primary Secure Endpoint process for scanning and such, but no CLI interface options&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 19:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-cli-usage-amp-documentation/m-p/4492127#M6460</guid>
      <dc:creator>TruthNotTruth</dc:creator>
      <dc:date>2021-10-25T19:51:18Z</dc:date>
    </item>
  </channel>
</rss>

