sevco.io

Cisco Secure Endpoint (fka AMP)

Overview

Cisco Secure Endpoint (formaly known as AMP for Endpoints) is a single-agent solution that provides comprehensive protection, detection, response, and user access coverage to defend against threats to your endpoints.

Available Integrations

ServicesSupported Asset Type(s)Integration Type
Secure EndpointDevicesSource

⚠️

Please review the configuration instructions in the section below before setting up permissions for apps.

Why You Should Integrate

Integrating with Cisco Secure Endpoint will provide visibility into devices with the agent installed to identify your endpoint coverage and state.

How Does the Integration Work

This integration pulls computers objects from Cisco Secure Endpoint.

This data is only used internally; we do not share it with any parties outside of Sevco. Refer to our privacy policy for details.

Configuration

  1. Configure the Access Schema
FieldDescriptionExample
Server Endpoint*The URL used to pull information.https://api.amp.cisco.com
Client ID*The Client ID generated in the Secure Endpoints Console.ABCDEF0123456789
API key*The Client Password (aka API key) generated in the Secure Endpoints Console.***********************
  1. Add an Integration: Select the integration(s) you'd like to add. See links for details on additional configuration required.

    • Collect devices
  2. Configure General Information: OPTIONAL: You can use the following fields to provide additional information about your configuration.

FieldDescriptionExample
'Name (optional)'Uniquely identifiable attribute of the configuration to delineate other similar configurations with the existing organization.'DMZ network'
'Contact Person (optional)'A placeholder to input a name or email address of a contact associated with the integration.'Jane Doe'
`Link to Console (optional)'A placeholder to input a link to the console of the product Sevco is integrating with for quick reference and access when configuring or editing the integration.'www.product.com/devices'
  1. Activate Config: Select "Activate" to enable this configuration and begin pulling data.

Source Documentation

Creating credentials

You'll be asked to provide source credentials that Sevco will use to connect to Cisco Secure Endpoint. The following link will step you through creating an a Client ID and API Key to configure the integration, Secure Endpoint API - Generating Client ID and API Key

Required Permissions

The following permissions are required:

  • Scope: Read to devices

API Documentation

Secure Endpoint API - Overview

Contact Us

If you're having problems integrating a source, or if you've found something wrong in this document, please email us at [email protected].

Tags: cloud, epp