cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5258
Views
0
Helpful
4
Replies

Does Endpoint AMP send syslog event ?

peter.peng
Level 1
Level 1

Hi Sir:

    Does Endpoint AMP send syslog event  or send the log by any methods ?

 

4 Replies 4

David Janulik
Cisco Employee
Cisco Employee

Hello,

 

AMP agent sends events to AMP console, for further details. The typical Syslog is not paired in any way with AMP agent. If Security Operation wants such output, need to use API. With REST API you are able to pull data, or run them regulary using e.g. cron jobs.

 

Hope that answers your question

 

David

Cyber security escalation engineer

AlexPi
Level 1
Level 1

I think this is what you need: Overview of the Cisco AMP for Endpoints API

 

 

------------------------------------------------------------------
If this was helpful, please vote as helpful by clicking on the star icon below.
-------------------------------------

jefburke
Cisco Employee
Cisco Employee

Hi Peter,


Neil and Evgeny have an Endpoint Security Ask The Expert thread going right now. It has a good focus on AMP. You should try posting this question and others there!

Here is the link: https://community.cisco.com/t5/advanced-threats/ask-the-expert-endpoint-security-the-daunting-challenges-of-the/td-p/3736946

I may not be able to help much, be he can!

Hi Jefburke:

    OK, Thanks for your help.