<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Endpoint - API - Threat Detected in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-api-threat-detected/m-p/5127233#M8395</link>
    <description>Start with getting the types, types come with names...&lt;BR /&gt;Get the guids for the types whose names you want by hitting &lt;A href="https://api.amp.cisco.com/v1/event_types" target="_blank"&gt;https://api.amp.cisco.com/v1/event_types&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Then get events filtered by the guids you want where the guids are query string parameters.&lt;BR /&gt;&lt;A href="https://api.amp.cisco.com/v1/events?event_type[]=1090519081&amp;amp;event_type[]=1107296272" target="_blank"&gt;https://api.amp.cisco.com/v1/events?event_type[]=1090519081&amp;amp;event_type[]=1107296272&lt;/A&gt;&amp;lt;&amp;gt;   ... etc.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;event types are OR'd, so you can put in as many as the url will take...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;________________________________&lt;BR /&gt;&lt;BR /&gt;This email is intended solely for the use of the individual to whom it is addressed and may contain information that is privileged, confidential or otherwise exempt from disclosure under applicable law. If the reader of this email is not the intended recipient or the employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this communication is strictly prohibited.&lt;BR /&gt;If you have received this communication in error, please immediately notify us by telephone and return the original message to us at the listed email address.&lt;BR /&gt;Thank You.</description>
    <pubDate>Fri, 07 Jun 2024 16:54:22 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2024-06-07T16:54:22Z</dc:date>
    <item>
      <title>Secure Endpoint - API - Threat Detected</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-api-threat-detected/m-p/5126590#M8391</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Is there a good example how to use the Secure Endpoint API to extract only the threats detected?&lt;BR /&gt;I saw an article regarding the events endpoint and all alert_types to filter, but is that the only way?&lt;BR /&gt;&lt;A href="https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-event/" target="_blank" rel="noopener"&gt;https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-event/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I've noticed the URL below, but it wasn't allowed to open the URL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-v1-api-events-not-equal/td-p/4907164" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-v1-api-events-not-equal/td-p/4907164&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 14:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-api-threat-detected/m-p/5126590#M8391</guid>
      <dc:creator>SanderZumbrink</dc:creator>
      <dc:date>2024-06-06T14:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Endpoint - API - Threat Detected</title>
      <link>https://community.cisco.com/t5/endpoint-security/secure-endpoint-api-threat-detected/m-p/5127233#M8395</link>
      <description>Start with getting the types, types come with names...&lt;BR /&gt;Get the guids for the types whose names you want by hitting &lt;A href="https://api.amp.cisco.com/v1/event_types" target="_blank"&gt;https://api.amp.cisco.com/v1/event_types&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Then get events filtered by the guids you want where the guids are query string parameters.&lt;BR /&gt;&lt;A href="https://api.amp.cisco.com/v1/events?event_type[]=1090519081&amp;amp;event_type[]=1107296272" target="_blank"&gt;https://api.amp.cisco.com/v1/events?event_type[]=1090519081&amp;amp;event_type[]=1107296272&lt;/A&gt;&amp;lt;&amp;gt;   ... etc.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;event types are OR'd, so you can put in as many as the url will take...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;________________________________&lt;BR /&gt;&lt;BR /&gt;This email is intended solely for the use of the individual to whom it is addressed and may contain information that is privileged, confidential or otherwise exempt from disclosure under applicable law. If the reader of this email is not the intended recipient or the employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this communication is strictly prohibited.&lt;BR /&gt;If you have received this communication in error, please immediately notify us by telephone and return the original message to us at the listed email address.&lt;BR /&gt;Thank You.</description>
      <pubDate>Fri, 07 Jun 2024 16:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/secure-endpoint-api-threat-detected/m-p/5127233#M8395</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-06-07T16:54:22Z</dc:date>
    </item>
  </channel>
</rss>

