<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: End point detection in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076406#M8324</link>
    <description>&lt;P&gt;OK so let me be more specific. You can only browse events under Event tab that will give you all the details such as event names, Device Trajectory, File trajectory, Detection,&amp;nbsp; etc..&amp;nbsp; for 30 days&amp;nbsp; how ever you can get summarized reports by default &lt;STRONG&gt;Weekly / Monthly&lt;/STRONG&gt; under &lt;STRONG&gt;Analysis&lt;/STRONG&gt; tab &lt;STRONG&gt;Reports&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Those are available to you and go back for very long time. In my org for example since it was created in 2020 but those reports are very high overview and basic so not sure if that's enough for you. It will contain this info in words and graphical preview.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Table of Contents&lt;BR /&gt;---------------&lt;/P&gt;
&lt;P&gt;Connector Status: 444K Files Scanned, 30.7K IPs Scanned&lt;BR /&gt;Compromises: 3 New Compromises, 0 Resolved&lt;BR /&gt;File Detections: 98 Detections, 47 Quarantines&lt;BR /&gt;Network Detections: 0 DFC Detections, 0 Computers Affected, 0 Agentless Global Threat Alerts Events&lt;BR /&gt;Threat Root Cause&lt;BR /&gt;Low Prevalence Executables: 12 Low Prevalence Executables Analyzed&lt;BR /&gt;Vulnerabilities: 2 Vulnerabilities Observed&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2024 16:16:42 GMT</pubDate>
    <dc:creator>Roman Valenta</dc:creator>
    <dc:date>2024-04-23T16:16:42Z</dc:date>
    <item>
      <title>End point detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5072080#M8311</link>
      <description>&lt;P&gt;I am new to cisco endpoint and will need some help in creating rolling 3 months analysis for end point positive detections&lt;/P&gt;&lt;P&gt;and also analysis for false positive detection.Any help and directions will be deeply appriciated.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 14:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5072080#M8311</guid>
      <dc:creator>neroblaze</dc:creator>
      <dc:date>2024-04-17T14:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: End point detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5072155#M8312</link>
      <description>&lt;P&gt;I'm not sure what you mean by creating &amp;lt;&lt;STRONG&gt;rolling 3 months analysis&lt;/STRONG&gt;&amp;gt; but there is retention policy in place for AMP where we only keep data available to you for 30 days. Anything older than 30 days is automatically purged. If you are looking for some type of reports you can setup custom or browse through built in weekly / monthly reports in your console under &lt;STRONG&gt;Analysis&lt;/STRONG&gt; tab&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 15:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5072155#M8312</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2024-04-17T15:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: End point detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5072502#M8316</link>
      <description>&lt;P&gt;Since you are new to Cisco secure endpoint, I suggest looking at the best practices guides as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/fireamp-endpoints/secure-endpoint-og.html#PolicyConfigurationPlanning" target="_blank"&gt;Secure Endpoint Best Practices Guide - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/213681-best-practices-for-amp-for-endpoint-excl.html" target="_blank"&gt;Configure and Identify Secure Endpoint Exclusions - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="times new roman,times" size="2"&gt;&lt;EM&gt;&lt;STRONG&gt;If you find this useful, please mark it helpful.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 02:47:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5072502#M8316</guid>
      <dc:creator>Pulkit Mittal</dc:creator>
      <dc:date>2024-04-18T02:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: End point detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076309#M8322</link>
      <description>&lt;P&gt;Hi&amp;nbsp; Roman, thanks for your response. By creating 3 months I mean getting data from the previous 2 months and comparing them to the recent month. Is there a way I can generate a report for detected threat events from February and March ,and then compare them to a report in April? Or the retention policy does not make that possible? Thanks for all the help.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076309#M8322</guid>
      <dc:creator>neroblaze</dc:creator>
      <dc:date>2024-04-23T14:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: End point detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076314#M8323</link>
      <description>&lt;P&gt;Thanks alot for the information&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 14:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076314#M8323</guid>
      <dc:creator>neroblaze</dc:creator>
      <dc:date>2024-04-23T14:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: End point detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076406#M8324</link>
      <description>&lt;P&gt;OK so let me be more specific. You can only browse events under Event tab that will give you all the details such as event names, Device Trajectory, File trajectory, Detection,&amp;nbsp; etc..&amp;nbsp; for 30 days&amp;nbsp; how ever you can get summarized reports by default &lt;STRONG&gt;Weekly / Monthly&lt;/STRONG&gt; under &lt;STRONG&gt;Analysis&lt;/STRONG&gt; tab &lt;STRONG&gt;Reports&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Those are available to you and go back for very long time. In my org for example since it was created in 2020 but those reports are very high overview and basic so not sure if that's enough for you. It will contain this info in words and graphical preview.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Example:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Table of Contents&lt;BR /&gt;---------------&lt;/P&gt;
&lt;P&gt;Connector Status: 444K Files Scanned, 30.7K IPs Scanned&lt;BR /&gt;Compromises: 3 New Compromises, 0 Resolved&lt;BR /&gt;File Detections: 98 Detections, 47 Quarantines&lt;BR /&gt;Network Detections: 0 DFC Detections, 0 Computers Affected, 0 Agentless Global Threat Alerts Events&lt;BR /&gt;Threat Root Cause&lt;BR /&gt;Low Prevalence Executables: 12 Low Prevalence Executables Analyzed&lt;BR /&gt;Vulnerabilities: 2 Vulnerabilities Observed&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 16:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076406#M8324</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2024-04-23T16:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: End point detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076415#M8325</link>
      <description>&lt;P&gt;I have seen the summarized reports that can be generated under the analysis tab Reports. They are not really helpful as i am looking for reports for endpoint detections which will allow me to also filter out false positives. I need to get this reports for positive detections and also false positive detections for management. Any ideas are welcome and thanks again.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 16:39:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/end-point-detection/m-p/5076415#M8325</guid>
      <dc:creator>neroblaze</dc:creator>
      <dc:date>2024-04-23T16:39:34Z</dc:date>
    </item>
  </channel>
</rss>

