USM Anywhere™

Configuring the AlienApp for Cisco AMP

Role Availability Read-Only Analyst Manager

To use the AlienApp for Cisco Advanced Malware Protection (AMP) in USM Anywhere, you first need to log in to Cisco AMP to create the API credentials.

To get the API credentials from Cisco AMP

Follow the Cisco documentation on how to create API credentials to obtain the third-party API client identification and API key.

Connecting the Cisco AMP App in USM Anywhere

After you obtain the credentials, you must configure the connection within USM Anywhere.

To enable the AlienApp for Cisco AMP

  1. In USM Anywhere, go to Data Sources > AlienApps.
  2. Click the Available Apps tab.
  3. Search for the AlienApp, and then click the tile.
  4. Click Configure API.
  5. If you have more than one deployed USM Anywhere Sensor, select the sensor that you want to use for the enabled AlienApp.

    AlienApps operate through a deployed sensor and use APIs to integrate with the connected third-party technology. Select the sensor that can access the integration endpoint. The HTTPS connections to the API will originate from this sensor, so it is important to make sure the sensor has network access to the AlienApp API endpoints.

  6. In the EndPoint Host URL section, click the dropdown and select the appropriate URL for your region:

    • api.amp.cisco.com – North America region
    • api.apjc.amp.cisco.com – Asia Pacific, Japan, and China regions
    • api.eu.amp.cisco.com – Europe region
  7. Enter your information into the following fields:

    • Client ID
    • API Key
  8. In the Event Type ID field, you can specify the event types (separated by a comma) you want the AlienApp for Cisco AMP to collect.

    When the Event Type ID field is left blank, AlienApp for Cisco AMP collects all event types. See the Cisco AMP documentation for more details on event types.

  9. Click Save.
  10. Verify the connection.

    After USM Anywhere completes a successful connection to the Cisco AMP Representational State Transfer (REST) APIs, a icon displays in the Health column.

    If the icon appears, there is a problem with the connection. The Message column provides information about the issue. Repeat the steps to fix the configuration or troubleshoot your Cisco AMP connection.

Cisco AMP Event Collection

Once the AlienApp for Cisco AMP has been configured, you can chose to have USM Anywhere collect Cisco AMP events from the app on an hourly basis.

To configure Cisco AMP event collection

  1. Go to Settings > Scheduler.
  2. In the Job Scheduler, search for the Cisco AMP app on the Sensor it was deployed to.
  3. In the enabled column, click the icon to for the inactive Cisco AMP events job.

    The icon turns green and hourly event collection from Cisco AMP is enabled.