cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2682
Views
0
Helpful
1
Replies

Does Endpoint AMP send syslog event ?

peter.peng
Level 1
Level 1

Hi Sir:

   Does Endpoint AMP send syslog event ? or AMP can get any information by restFul or API ?

1 Accepted Solution

Accepted Solutions

David Janulik
Cisco Employee
Cisco Employee

Hello,

Security Ops rely on API to get e.g. syslog event. API call would let you get description of behavior indicators.  You should be able to pull the name, title, description and lots of other indicator data from it.

Go into your dashboard if you do not yet have an API key and you can establish one under Accounts > API Credentials.

 

Cisco AMP has gitub source to start with API.

https://github.com/CiscoSecurity/amp-01-basics

 

Or you can have a look at official documentation, as below:

https://api-docs.amp.cisco.com/

 

Regards

David

Cyber security escalation engineer

View solution in original post

1 Reply 1

David Janulik
Cisco Employee
Cisco Employee

Hello,

Security Ops rely on API to get e.g. syslog event. API call would let you get description of behavior indicators.  You should be able to pull the name, title, description and lots of other indicator data from it.

Go into your dashboard if you do not yet have an API key and you can establish one under Accounts > API Credentials.

 

Cisco AMP has gitub source to start with API.

https://github.com/CiscoSecurity/amp-01-basics

 

Or you can have a look at official documentation, as below:

https://api-docs.amp.cisco.com/

 

Regards

David

Cyber security escalation engineer