cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
507
Views
1
Helpful
6
Replies

Cisco Secure Endpoint API Integration to custom SIEM

Dinobravo69
Level 1
Level 1

Hello,

I want to forward the alerts generated from Cisco Secure Endpoint to my custom SIEM.

Which type of API would best fit in this case?

 

Thanks,

 

Dino

6 Replies 6

If you're building your own API query thing, eventstream. https://developer.cisco.com/docs/secure-endpoint/eventstream/

There's an elastic beat for it if you're using Elastic. Logrythym has one too... There may be others with similar things.

Tried to setup the event stream api but no logs are coming in, is there any documentation, FAQ or relevant videos for these kind of issues?

And question, the ioc api is not the actual alerts on the EDR console (successfully deployed this one, but only IOC information is displayed and not the actual alert), which one would be used for specifically and only the alerts generated in the secure endpoint console.

 

Thanks,

 

Dino

Start here.

https://developer.cisco.com/amp-for-endpoints/


This is closer to the actual page you want( on my phone so I'm not seeing everything)
https://developer.cisco.com/docs/secure-endpoint/v1-api-reference-event/

bharatpoojary
Level 1
Level 1

You can use microsoft graph api.

Not using azure.

if you have azure premium P1 licence that's enough.