Cisco AMP For Endpoints python script to ingest AMQP messages to a local log file. This was originally setup for Sumo Logic, but can be used for other SIEMs.
Prerequisites
Four variables need to be input at the beginning of the script for this to work:
API_ID = ''
API_KEY = ''
AMQP_PW = ''
EVENT_STREAM_NAME = ''
You should also put in your user password in line 39
Setup
-Create an API account through the Cisco AMP For Enpoints Admin dashboard to get the ID and Key variables
-Make sure you have Python 3.7 installed, and pip'd the necessary packages.
-Then run the script ~> python ./AMP4e_events.py to confirm you are ingesting
-You can create a service to make sure this always running, I have it running now smoothly for my own Sumo Logic collector. Feel free to message if you need help!
Updates
-06/04/2019 reworked consume order
About
Cisco AMP For Endpoints python script to ingest AMQP messages to local log file. Good for SIEMs like Sumo Logic