<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Endpoint API Integration to custom SIEM in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5147951#M8451</link>
    <description>&lt;P&gt;if you have azure premium P1 licence that's enough.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2024 05:30:33 GMT</pubDate>
    <dc:creator>bharatpoojary</dc:creator>
    <dc:date>2024-07-22T05:30:33Z</dc:date>
    <item>
      <title>Cisco Secure Endpoint API Integration to custom SIEM</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5143752#M8421</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I want to forward the alerts generated from Cisco&amp;nbsp;Secure Endpoint to my custom SIEM.&lt;/P&gt;&lt;P&gt;Which type of API would best fit in this case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dino&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 18:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5143752#M8421</guid>
      <dc:creator>Dinobravo69</dc:creator>
      <dc:date>2024-07-11T18:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint API Integration to custom SIEM</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5143780#M8422</link>
      <description>If you're building your own API query thing, eventstream. &lt;A href="https://developer.cisco.com/docs/secure-endpoint/eventstream/" target="_blank"&gt;https://developer.cisco.com/docs/secure-endpoint/eventstream/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;There's an elastic beat for it if you're using Elastic.  Logrythym has one too...  There may be others with similar things.&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Jul 2024 19:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5143780#M8422</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-07-11T19:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint API Integration to custom SIEM</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5145410#M8437</link>
      <description>&lt;P&gt;You can use microsoft graph api.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 08:28:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5145410#M8437</guid>
      <dc:creator>bharatpoojary</dc:creator>
      <dc:date>2024-07-16T08:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint API Integration to custom SIEM</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5146956#M8443</link>
      <description>&lt;P&gt;Not using azure.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 20:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5146956#M8443</guid>
      <dc:creator>Dinobravo69</dc:creator>
      <dc:date>2024-07-18T20:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint API Integration to custom SIEM</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5146958#M8444</link>
      <description>&lt;P&gt;Tried to setup the event stream api but no logs are coming in, is there any documentation, FAQ or relevant videos for these kind of issues?&lt;/P&gt;&lt;P&gt;And question, the ioc api is not the actual alerts on the EDR console (successfully deployed this one, but only IOC information is displayed and not the actual alert), which one would be used for specifically and only the alerts generated in the secure endpoint console.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dino&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 20:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5146958#M8444</guid>
      <dc:creator>Dinobravo69</dc:creator>
      <dc:date>2024-07-18T20:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint API Integration to custom SIEM</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5146975#M8446</link>
      <description>Start here.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://developer.cisco.com/amp-for-endpoints/" target="_blank"&gt;https://developer.cisco.com/amp-for-endpoints/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;This is closer to the actual page you want( on my phone so I'm not seeing everything)&lt;BR /&gt;&lt;A href="https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-event/" target="_blank"&gt;https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-event/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Jul 2024 21:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5146975#M8446</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-07-18T21:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Endpoint API Integration to custom SIEM</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5147951#M8451</link>
      <description>&lt;P&gt;if you have azure premium P1 licence that's enough.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 05:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-endpoint-api-integration-to-custom-siem/m-p/5147951#M8451</guid>
      <dc:creator>bharatpoojary</dc:creator>
      <dc:date>2024-07-22T05:30:33Z</dc:date>
    </item>
  </channel>
</rss>

