Overview
The Cisco AMP integration enables ThreatAware to collect data from your Cisco AMP system.Connection Method: API
Setup Time: 15 minutes
Access Required: Administrator account
Setup instructions
1
Log in to Cisco AMP Console
- Access the Cisco AMP Console with an administrator account.
2
Identify API Endpoint
- The API endpoint is determined by your console’s URL, such as:
api.amp.cisco.comapi.apjc.amp.cisco.comapi.eu.amp.cisco.com- For example, if your console URL is
amp.cisco.com, then your API Endpoint isapi.amp.cisco.com.
3
Create API Credentials
- Navigate to Accounts > API Credentials within the Cisco AMP console.
- Click New API Credential and provide an application name, e.g., “ThreatAware Integration.”
- Set Scope to Read & Write.
- Copy the Client ID and API Key generated.
4
Input Details in ThreatAware
- In ThreatAware, go to Integrations and select Cisco AMP.
- Enter the API Endpoint, Client ID, and API Key into the appropriate fields.
Input details
API Endpoint
API Endpoint
Cisco AMP endpoint URL.
Client ID
Client ID
Client ID generated in Cisco AMP.
API Key
API Key
Secure key associated with the Client ID.
Verification and troubleshooting
Verification
Verification
In ThreatAware, confirm the Integration Status shows as Active after configuration.
Troubleshooting
Troubleshooting
- Invalid API Endpoint: Ensure the correct regional endpoint is entered.
- Permission Issues: Confirm the API credentials have Read & Write scope enabled.
Important notes and links
- For API scope and permission requirements, consult the Cisco AMP API Documentation.
- API Endpoint and credentials are region-specific, so confirm the endpoint matches your account’s location.