Cisco AMP for Endpoints API V0 - Previously Cisco AMP Cloud V0
What is Discovered and Monitored
|Protocol||Logs Collected||Used For|
|CloudAMP API||End point malware activity||Security Monitoring|
In ADMIN > Device Support > Event Types, search for "FireAMP Cloud" in the Search field to see the event types associated with this device.
- Configure Cisco AMP Cloud V0
- Define Cisco FireAMP Cloud Credential in FortiSIEM
- Create IP Range to Credential Association, Test Connectivity, and Event Pulling
Configure Cisco AMP Cloud V0
- Login in https://auth.amp.cisco.com/.
- Click Accounts-> API Credentials.
- Click New API Credential.
- Input Application name and click Create.
- Record the API Client ID and API key. You will need them in a later step.
Define Cisco FireAMP Cloud Credential in FortiSIEM
Complete these steps in the FortiSIEM UI by first logging in to the FortiSIEM Supervisor node.
- Go to the ADMIN > Setup > Credentials tab.
- In Step 1: Enter Credentials:
- Follow the instructions in “Setting Credentials“ in the User's Guide to create a new credential.
- Enter these settings in the Access Method Definition dialog box and click Save:
Settings Description Name Enter a name for the credential, for example "FireAMP Cloud" Device Type Cisco FireAMP Cloud Access Protocol FireAMP Cloud API Password config Manual Client ID CiscoAMP Client ID
CiscoAMP API Key
Organization The organization the device belongs to. Description Description of the device.
Create IP Range to Credential Association, Test Connectivity, and Event Pulling
From the FortiSIEM Supervisor node, take the following steps (In ADMIN > Setup > Credentials).
- In Step 2: Enter IP Range to Credential Associations, click New to create a new mapping.
- Enter "api.amp.cisco.com" in the IP/Host Name field.
- Select the name of the credential created in Define Cisco FireAMP Cloud Credential in FortiSIEM from the Credentials drop-down list.
- Click Save.
- Select the entry just created and click the Test drop-down list and select Test Connectivity. A pop up will appear and show the Test Connectivity results.
The result is a success.
- Go to ADMIN > Setup > Pull Events and make sure an entry is created for Cisco FireAMP Cloud.
- Go to the ANALYTICS page to see the events.
[FireAMP_Cloud_Threat_Detected]:[eventSeverity]=PHL_CRITICAL, [connectorGUID]=12345,[date]=2015-11- 25T19:17:39+00:00,[detection]=W32.DFC.MalParent, [detectionId]=6159251516445163587,[eventId]=6159251516445163587, [eventType]=Threat Detected,[eventTypeId]=1090519054, [fileDispostion]=Malicious,[fileName]=rjtsbks.exe, [fileSHA256]=3372c1edab46837f1e973164fa2d726c5c5e17bcb888828ccd7c4dfcc234a370,