Skip to main content

Cisco AMP API Integration with Chronicle Forwarder/SecOps

  • March 25, 2025
  • 3 replies
  • 72 views

horongshen
Forum|alt.badge.img+1

I have a log source integration for a customer for Cisco AMP via API. How do i go about doing this?

I have managed to get the API Key and Secret Key on Cisco AMP. I tried to find relevant information on the Google documentation, https://cloud.google.com/chronicle/docs/soar/marketplace-integrations/cisco-amp?hl=en but this is for SOAR which is not what i want. Do anyone here have any clue or point me the right direction please? Thank you!

3 replies

dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • March 25, 2025

There is not a direct 3rd party API for Cisco AMP.  

You can use a webhook or you could send that data to a storage bucket in GCP or AWS.  


horongshen
Forum|alt.badge.img+1
  • Author
  • New Member
  • March 27, 2025

Thanks @dnehoda is there some kind of a read-up or guide available for using webhook for cisco amp?


cmorris
Staff
Forum|alt.badge.img+10
  • Staff
  • March 27, 2025

Thanks @dnehoda is there some kind of a read-up or guide available for using webhook for cisco amp?


Not for Cisco AMP specifically, but for webhooks in general - https://cloud.google.com/chronicle/docs/administration/feed-management#setup-webhook

You can add it through SIEM Settings > Feeds: