# Cisco AMP for Endpoints API Integration

To integrate **Cisco AMP for Endpoints (now part of Cisco Secure Endpoint)** with **Elastic, follow these general steps:**

##### <span style="color: rgb(53, 152, 219);">**Get Cisco AMP API Credentials**</span>

You need to enable API access from the Cisco Secure Endpoint console.

- Log in to: <a class="cursor-pointer" data-end="425" data-start="363" rel="noopener" target="_new">https://console.amp.cisco.com</a>
- Go to **Accounts &gt; API Credentials**
- Click **Create API Credential**
- Choose **"Read &amp; Write"** or at minimum **"Read-only"**
- Save:
    
    
    - `Client ID`
    - `API Key`

These will be used to pull events from the AMP API.

##### <span style="color: rgb(53, 152, 219);">**Integrate on AQUILA**</span>

1. Log in to **[CyTech - AQUILA](https://cytechint.io/)**. Choose **Cyber Monitoring** and click the **small arrow icon** to redirect you to the Cyber Monitoring Dashboard.

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/gJqiCpD7Puwe6BCH-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/gJqiCpD7Puwe6BCH-image.png)

2\. In the dashboard, choose **Cyber Incident Management (SIEM and XDR)**.

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/ChCabqtdB7BToc5C-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/ChCabqtdB7BToc5C-image.png)

3\. Navigate through the leftmost top and click **Cyber Incident Monitoring**.

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/QUgb4SjtLXECWANE-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/QUgb4SjtLXECWANE-image.png)

4\. Navigate through **Settings&gt;Log Source&gt;Search Bar&gt;Add to Agent**.

[![cisco-secure-endpoint.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/Vfi4seGvDtckCMPv-cisco-secure-endpoint.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/Vfi4seGvDtckCMPv-cisco-secure-endpoint.png)

5\. Choose your **Log Collector**.

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/fd6dcSQhfh3hAxT3-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/fd6dcSQhfh3hAxT3-image.png)

6\. In the integration settings follow the instructions given below.

1. Click the **drop arrow** to display the contents. Make sure the Collect logs from the Cisco Secure Endpoint API is **Enabled.**
2. Click the other **drop arrow** to display the other contents needed for the integration setup. Input the Client ID and the API Key.
3. **Scroll down,** leave the other text fields to its default value and go to **Tags.** Click the **Tags** text field and add **cisco-secure\_endpoint** and **forwarded.**
4. Finally, click **Next** to install the log source integration.

[![cisco-secure-endpoint2.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/8tUOUxwRGHIZzxxC-cisco-secure-endpoint2.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/8tUOUxwRGHIZzxxC-cisco-secure-endpoint2.png)

[![cisco-secure-endpoint3.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/uC8vMozRsBzHWoP6-cisco-secure-endpoint3.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/uC8vMozRsBzHWoP6-cisco-secure-endpoint3.png)

[![cisco-secure-endpoint4.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/bhVAJJmfjb38Sqrl-cisco-secure-endpoint4.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/bhVAJJmfjb38Sqrl-cisco-secure-endpoint4.png)

[![cisco-secure-endpoint5.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/J5ZhAhpkaH46xRxW-cisco-secure-endpoint5.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/J5ZhAhpkaH46xRxW-cisco-secure-endpoint5.png)

7\. Wait for the **Successfull** window to display, this will confirm the successfull integration.

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/bPXsUbIJSaGHmL83-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/bPXsUbIJSaGHmL83-image.png)

*If you need further assistance, kindly contact our support at **support@cytechint.com** for prompt assistance and guidance.*