Fortinet white logo
Fortinet white logo

External Systems Configuration Guide

Cisco AMP for Endpoints API V0 - Previously Cisco AMP Cloud V0

Cisco AMP for Endpoints API V0 - Previously Cisco AMP Cloud V0

What is Discovered and Monitored

Protocol Logs Collected Used For
CloudAMP API End point malware activity Security Monitoring

Event Types

In ADMIN > Device Support > Event Types, search for "FireAMP Cloud" in the Search field to see the event types associated with this device.

Configuration

Configure Cisco AMP Cloud V0
  1. Login in https://auth.amp.cisco.com/.
  2. Click Accounts-> API Credentials.

  3. Click New API Credential.

  4. Input Application name and click Create.

  5. Record the API Client ID and API key. You will need them in a later step.

Define Cisco FireAMP Cloud Credential in FortiSIEM

Complete these steps in the FortiSIEM UI by first logging in to the FortiSIEM Supervisor node.

  1. Go to the ADMIN > Setup > Credentials tab.
  2. In Step 1: Enter Credentials:
    1. Follow the instructions in “Setting Credentials“ in the User's Guide to create a new credential.
    2. Enter these settings in the Access Method Definition dialog box and click Save:
    1. Settings Description
      Name Enter a name for the credential, for example "FireAMP Cloud"
      Device Type Cisco FireAMP Cloud
      Access Protocol FireAMP Cloud API
      Password config Manual
      Client ID CiscoAMP Client ID

      Client Secret

      CiscoAMP API Key

      Organization The organization the device belongs to.
      Description Description of the device.
  • Create IP Range to Credential Association, Test Connectivity, and Event Pulling

    From the FortiSIEM Supervisor node, take the following steps (In ADMIN > Setup > Credentials).

    1. In Step 2: Enter IP Range to Credential Associations, click New to create a new mapping.
      1. Enter "api.amp.cisco.com" in the IP/Host Name field.
      2. Select the name of the credential created in Define Cisco FireAMP Cloud Credential in FortiSIEM from the Credentials drop-down list.
      3. Click Save.

    2. Select the entry just created and click the Test drop-down list and select Test Connectivity. A pop up will appear and show the Test Connectivity results.

      The result is a success.

    3. Go to ADMIN > Setup > Pull Events and make sure an entry is created for Cisco FireAMP Cloud.

    4. Go to the ANALYTICS page to see the events.

    Sample Events

    [FireAMP_Cloud_Threat_Detected]:[eventSeverity]=PHL_CRITICAL, [connectorGUID]=12345,[date]=2015-11- 25T19:17:39+00:00,[detection]=W32.DFC.MalParent, [detectionId]=6159251516445163587,[eventId]=6159251516445163587, [eventType]=Threat Detected,[eventTypeId]=1090519054, [fileDispostion]=Malicious,[fileName]=rjtsbks.exe, [fileSHA256]=3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370,

    Cisco AMP for Endpoints API V0 - Previously Cisco AMP Cloud V0

    Cisco AMP for Endpoints API V0 - Previously Cisco AMP Cloud V0

    What is Discovered and Monitored

    Protocol Logs Collected Used For
    CloudAMP API End point malware activity Security Monitoring

    Event Types

    In ADMIN > Device Support > Event Types, search for "FireAMP Cloud" in the Search field to see the event types associated with this device.

    Configuration

    Configure Cisco AMP Cloud V0
    1. Login in https://auth.amp.cisco.com/.
    2. Click Accounts-> API Credentials.

    3. Click New API Credential.

    4. Input Application name and click Create.

    5. Record the API Client ID and API key. You will need them in a later step.

    Define Cisco FireAMP Cloud Credential in FortiSIEM

    Complete these steps in the FortiSIEM UI by first logging in to the FortiSIEM Supervisor node.

    1. Go to the ADMIN > Setup > Credentials tab.
    2. In Step 1: Enter Credentials:
      1. Follow the instructions in “Setting Credentials“ in the User's Guide to create a new credential.
      2. Enter these settings in the Access Method Definition dialog box and click Save:
    1. Settings Description
      Name Enter a name for the credential, for example "FireAMP Cloud"
      Device Type Cisco FireAMP Cloud
      Access Protocol FireAMP Cloud API
      Password config Manual
      Client ID CiscoAMP Client ID

      Client Secret

      CiscoAMP API Key

      Organization The organization the device belongs to.
      Description Description of the device.
  • Create IP Range to Credential Association, Test Connectivity, and Event Pulling

    From the FortiSIEM Supervisor node, take the following steps (In ADMIN > Setup > Credentials).

    1. In Step 2: Enter IP Range to Credential Associations, click New to create a new mapping.
      1. Enter "api.amp.cisco.com" in the IP/Host Name field.
      2. Select the name of the credential created in Define Cisco FireAMP Cloud Credential in FortiSIEM from the Credentials drop-down list.
      3. Click Save.

    2. Select the entry just created and click the Test drop-down list and select Test Connectivity. A pop up will appear and show the Test Connectivity results.

      The result is a success.

    3. Go to ADMIN > Setup > Pull Events and make sure an entry is created for Cisco FireAMP Cloud.

    4. Go to the ANALYTICS page to see the events.

    Sample Events

    [FireAMP_Cloud_Threat_Detected]:[eventSeverity]=PHL_CRITICAL, [connectorGUID]=12345,[date]=2015-11- 25T19:17:39+00:00,[detection]=W32.DFC.MalParent, [detectionId]=6159251516445163587,[eventId]=6159251516445163587, [eventType]=Threat Detected,[eventTypeId]=1090519054, [fileDispostion]=Malicious,[fileName]=rjtsbks.exe, [fileSHA256]=3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370,