Skip to main content

Overview

The Cisco AMP integration enables ThreatAware to collect data from your Cisco AMP system.
Connection Method: API Setup Time: 15 minutes Access Required: Administrator account

Setup instructions

1

Log in to Cisco AMP Console

2

Identify API Endpoint

  • The API endpoint is determined by your console’s URL, such as:
  • api.amp.cisco.com
  • api.apjc.amp.cisco.com
  • api.eu.amp.cisco.com
  • For example, if your console URL is amp.cisco.com, then your API Endpoint is api.amp.cisco.com.
3

Create API Credentials

  • Navigate to Accounts > API Credentials within the Cisco AMP console.
  • Click New API Credential and provide an application name, e.g., “ThreatAware Integration.”
  • Set Scope to Read & Write.
  • Copy the Client ID and API Key generated.
4

Input Details in ThreatAware

  • In ThreatAware, go to Integrations and select Cisco AMP.
  • Enter the API Endpoint, Client ID, and API Key into the appropriate fields.

Input details

Cisco AMP endpoint URL.
Client ID generated in Cisco AMP.
Secure key associated with the Client ID.

Verification and troubleshooting

In ThreatAware, confirm the Integration Status shows as Active after configuration.
  • Invalid API Endpoint: Ensure the correct regional endpoint is entered.
  • Permission Issues: Confirm the API credentials have Read & Write scope enabled.
  • For API scope and permission requirements, consult the Cisco AMP API Documentation.
  • API Endpoint and credentials are region-specific, so confirm the endpoint matches your account’s location.