cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3646
Views
5
Helpful
2
Replies

Amp for Endpoints maximum time range

Diego Leitao
Frequent Visitor
Frequent Visitor

Hello,

I would like to know the maximum time range of device trajectory.

Is it just 30 days?

Thanks!

1 Accepted Solution

Accepted Solutions

Matthew Franks
Cisco Employee
Cisco Employee

Diego,

 

That is correct.  The limit on Device Trajectory (version 2) is 30 days.  The legacy Device Trajectory was 4,000 events but that is nearly phased out at this point.  If you would like additional storage, we recommend setting up an Event Stream with the API and ingesting the events with a SIEM.  

 

Information on setting up an API key is on page 218 of the User Guide:
https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20User%20Guide.pdf

 

Information on setting up an Event Stream can be found here:
https://api-docs.amp.cisco.com/api_actions/details?api_action=POST+%2Fv1%2Fevent_streams&api_host=api.amp.cisco.com&api_resource=EventStream&api_version=v1

 

Thanks,

Matt

View solution in original post

2 Replies 2

Matthew Franks
Cisco Employee
Cisco Employee

Diego,

 

That is correct.  The limit on Device Trajectory (version 2) is 30 days.  The legacy Device Trajectory was 4,000 events but that is nearly phased out at this point.  If you would like additional storage, we recommend setting up an Event Stream with the API and ingesting the events with a SIEM.  

 

Information on setting up an API key is on page 218 of the User Guide:
https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20User%20Guide.pdf

 

Information on setting up an Event Stream can be found here:
https://api-docs.amp.cisco.com/api_actions/details?api_action=POST+%2Fv1%2Fevent_streams&api_host=api.amp.cisco.com&api_resource=EventStream&api_version=v1

 

Thanks,

Matt

Thank you very much Matthew!!