<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Finding The Most Recent User In AMP (Secure Endpoint) in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/finding-the-most-recent-user-in-amp-secure-endpoint/m-p/4527046#M6576</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1293471"&gt;@CJ1470&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;just some thoughts about the user information included in an endpoint event.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You may review the Device Trajectory to see more information&lt;/LI&gt;
&lt;LI&gt;Much activity on the endpoint is not done in the user context&lt;/LI&gt;
&lt;LI&gt;The easiest way is to start an Orbital query using the catalog query: &lt;STRONG&gt;Last Logged on User Monitoring&lt;BR /&gt;&lt;/STRONG&gt;Orbital provides an API as well, where you can generate a job querying all your endpoints.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jan 2022 18:01:30 GMT</pubDate>
    <dc:creator>Troja007</dc:creator>
    <dc:date>2022-01-05T18:01:30Z</dc:date>
    <item>
      <title>Finding The Most Recent User In AMP (Secure Endpoint)</title>
      <link>https://community.cisco.com/t5/endpoint-security/finding-the-most-recent-user-in-amp-secure-endpoint/m-p/4524131#M6568</link>
      <description>&lt;P&gt;I've noticed that you can search by username in AMP and get the devices that the user has logged into (or possibly generated events on). This is also possible in the API. I am wondering if there is any way to do the reverse. Is there any way to find the most recent user of a machine by hostname (preferably from the API) ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know in some cases, you can check the "current user" field in recent events, but I have found a machine where all of the events list "current user" as "&lt;EM&gt;none&lt;/EM&gt;". Even though all events say&amp;nbsp;&lt;EM&gt;none&lt;/EM&gt;, if you search by the username associated with that machine, AMP is still able to find that machine. AMP has to be storing this information somewhere, but I can't find any mention of how to access this data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 20:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/finding-the-most-recent-user-in-amp-secure-endpoint/m-p/4524131#M6568</guid>
      <dc:creator>CJ1470</dc:creator>
      <dc:date>2021-12-27T20:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Finding The Most Recent User In AMP (Secure Endpoint)</title>
      <link>https://community.cisco.com/t5/endpoint-security/finding-the-most-recent-user-in-amp-secure-endpoint/m-p/4527046#M6576</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1293471"&gt;@CJ1470&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;just some thoughts about the user information included in an endpoint event.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You may review the Device Trajectory to see more information&lt;/LI&gt;
&lt;LI&gt;Much activity on the endpoint is not done in the user context&lt;/LI&gt;
&lt;LI&gt;The easiest way is to start an Orbital query using the catalog query: &lt;STRONG&gt;Last Logged on User Monitoring&lt;BR /&gt;&lt;/STRONG&gt;Orbital provides an API as well, where you can generate a job querying all your endpoints.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 18:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/finding-the-most-recent-user-in-amp-secure-endpoint/m-p/4527046#M6576</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-01-05T18:01:30Z</dc:date>
    </item>
  </channel>
</rss>

