AQUILA - Cisco Secure Endpoint Integration

Introduction

Cisco Secure Endpoint is a cloud-delivered, advanced endpoint detection and response (EDR) solution. It provides visibility and protection across multiple control points, enabling organizations to rapidly detect, contain, and remediate advanced threats.


Assumptions

The procedures in this guide assume that a Log Collector has already been set up.


Requirements

This integration is designed for collecting Cisco Secure Endpoint logs.

Supported Dataset

Generating Client ID and API Key

To collect logs via the Secure Endpoint API, you must first generate API credentials:

  1. Log in to your AMP for Endpoints Console.

  2. Navigate to Accounts > Organization Settings.

  3. Under Features, click Configure API Credentials.

  4. Generate and copy the Client ID and Secure API Key.

 Important: You can only copy your API Key at the time of creation. It cannot be retrieved later. Store it securely.


Secure Endpoint Logs

Secure Endpoint API Capabilities

The Secure Endpoint API can be used to retrieve and manage detailed information, including:


Top Use Cases

API Response Format

The Secure Endpoint API provides responses in three key objects:


To enable log collection from the Cisco Secure Endpoint API, provide the following information to CyTech Support:

 

 

If you need further assistance, kindly contact support@cytechint.com for prompt assistance and guidance. 


Revision #1
Created 3 October 2025 13:38:36 by Richmond Abella
Updated 3 October 2025 13:42:44 by Richmond Abella