07-17-2019 06:10 PM - edited 02-20-2020 09:09 PM
Hi All,
We have just procured numerous Cisco security solutions including;
Absolutely loving the potential capability this has brought to our organization from a security standpoint, awesome!
I have got AMP up and running with a few test machines, all is looking pretty good.
What i would like to know is, how do i configure AMP to automatically submit files for analysis in Threat Grid?
I can right click on a file/host in AMP and see Threat Grid as an option, i can also see that nothing has been "automatically"uploaded for analysis;
Thanks heaps in advance folks!
Solved! Go to Solution.
07-18-2019 12:59 AM
Hi,
You don't need to manually configure it,Its enabled by default. Not all the unknown files will be submitted. Only the low prevalence files may be submitted by AMP if it decided to do so.
07-19-2019 12:06 AM
Hello @Warren Sullivan - Corp,
just to be clear. you also have to activate automatically file upload on the AMP for endpoints console, after you have configured the TG connection.
1) Go to Analysis -> Prevalence.
2) Enable the groups for automatically submission.
Otherwise, no file from the endpoint will automatically uploaded for analysis.
Greetings,
Thorsten
07-17-2019 08:46 PM
07-17-2019 10:23 PM
Hi Fancesco,
I already have it configured, as you can see below;
But what i'm wondering is how do you configure AMP to upload threats for analysis automatically? without user intervention....
07-18-2019 12:59 AM
Hi,
You don't need to manually configure it,Its enabled by default. Not all the unknown files will be submitted. Only the low prevalence files may be submitted by AMP if it decided to do so.
02-09-2024 03:45 PM
So I just got into Secure Endpoint and Secure Malware Analytics, and I noticed the "Default Key" in Endpoints doesn't match the API key in Malware Analytics. So I went ahead and pasted the correct key ... now it says that I cannot submit files for analysis again in over 292277024 years. Our sun might explode by then.
02-09-2024 08:47 PM
Hi,
This issue in most cases was due to expired Threat Grid license and was resolved once the license was renewed and new API was generated.
Also if this is new or renewed license perhaps created today 02/09/2024 I would try regenerate new API Key tomorrow. Please log in as ORG Admin and regenerate the API and then try apply again in the Secure Endpoint portal. If you still run in to a issue please contact Threat Grid provisioning team to verify your license. Cisco Threat Grid Provisioning <tg-provisioning@cisco.com>
Regards,
Roman
07-18-2019 08:36 AM
07-19-2019 12:06 AM
Hello @Warren Sullivan - Corp,
just to be clear. you also have to activate automatically file upload on the AMP for endpoints console, after you have configured the TG connection.
1) Go to Analysis -> Prevalence.
2) Enable the groups for automatically submission.
Otherwise, no file from the endpoint will automatically uploaded for analysis.
Greetings,
Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide