Cisco AMP for Endpoints API

GET /v1/computers

Description

Query Parameters

Name Type Example Values Description
hostname[] String Demo_Qakbot_1
limit Integer 10
offset Integer 20
internal_ip String 104.21.179.27
external_ip String 152.58.0.128
group_guid[] GUID b077d6bc-bbdf-42f7-8838-a06053fbd98a

Show Response Fields

Name Type Description
version String
metadata.links.self String
metadata.results.total Integer
metadata.results.current_item_count Integer
metadata.results.index Integer
metadata.results.items_per_page Integer
data Array
data[].connector_guid GUID
data[].hostname String
data[].active Boolean
data[].links.computer String
data[].links.trajectory String
data[].links.group String
data[].connector_version String
data[].operating_system String
data[].internal_ips Array
data[].internal_ips[] String
data[].external_ip String
data[].group_guid GUID
data[].install_date String (Time ISO8601)
data[].network_addresses Array
data[].network_addresses[].mac String
data[].network_addresses[].ip String
data[].policy.guid GUID
data[].policy.name String
data[].last_seen String (Time ISO8601)
data[].faults Array
data[].isolation.available Boolean
data[].isolation.status String
Write
Preview

Examples

Fetch list of computers
Fetch list of computers filtered by hostname
Fetch list of computers filtered by internal_ip
Fetch list of computers filtered by external_ip
Fetch list of computers filtered by group_guid

Fetch list of computers

Request

Requires Authorization
GET /v1/computers
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/computers'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3306
x-ratelimit-remaining: 2739
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-08-02T18:40:25Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/computers"
    },
    "results": {
      "total": 28,
      "current_item_count": 28,
      "index": 0,
      "items_per_page": 500
    }
  },
  "data": [
    {
      "connector_guid": "552c40f8-afc1-4eae-85cf-b70c9644a3fe",
      "hostname": "Demo_Qakbot_1",
      "active": true,
      "links": {
        "computer": "https://api.eu.amp.cisco.com/v1/computers/552c40f8-afc1-4eae-85cf-b70c9644a3fe",
        "trajectory": "https://api.eu.amp.cisco.com/v1/computers/552c40f8-afc1-4eae-85cf-b70c9644a3fe/trajectory",
        "group": "https://api.eu.amp.cisco.com/v1/groups/b077d6bc-bbdf-42f7-8838-a06053fbd98a"
      },
      "connector_version": "6.3.1.10893",
      "operating_system": "Windows 7, SP 1.0",
      "internal_ips": [
        "104.21.179.27"
      ],
      "external_ip": "152.58.0.128",
      "group_guid": "b077d6bc-bbdf-42f7-8838-a06053fbd98a",
      "install_date": "2019-07-31T21:36:52Z",
      "network_addresses": [
        {
          "mac": "07:c5:09:18:62:af",
          "ip": "104.21.179.27"
        }
      ],
      "policy": {
        "guid": "89912c9e-8dbd-4c2b-a1d8-dee8a0c2bb29",
        "name": "Audit Policy"
      },
      "last_seen": "2019-03-01T17:49:17Z",
      "faults": [

      ],
      "isolation": {
        "available": false,
        "status": "not_isolated"
      }
    },
    {
      "connector_guid": "20a0ce9f-44d1-4cbb-ab04-8a0705448b72",
      "hostname": "Demo_Upatre",
      "active": true,
      "links": {
        "computer": "https://api.eu.amp.cisco.com/v1/computers/20a0ce9f-44d1-4cbb-ab04-8a0705448b72",
        "trajectory": "https://api.eu.amp.cisco.com/v1/computers/20a0ce9f-44d1-4cbb-ab04-8a0705448b72/trajectory",
        "group": "https://api.eu.amp.cisco.com/v1/groups/6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03"
      },
      "connector_version": "6.3.1.10893",
      "operating_system": "Windows 7, SP 1.0",
      "internal_ips": [
        "230.122.135.241"
      ],
      "external_ip": "69.226.122.127",
      "group_guid": "6c3c2005-4c74-4ba7-8dbb-c4d5b6bafe03",
      "install_date": "2019-08-02T16:00:18Z",
      "network_addresses": [
        {
          "mac": "3f:1e:b2:28:25:24",
          "ip": "230.122.135.241"
        }
      ],
      "policy": {
        "guid": "520c7c68-a637-43b1-b851-7830b0b336b6",
        "name": "Protect Policy"
      },
      "last_seen": "2019-03-01T17:49:16Z",
      "faults": [

      ],
      "isolation": {
        "available": false,
        "status": "not_isolated"
      }
    }
  ]
}

Fetch list of computers filtered by hostname

Request

Requires Authorization
GET /v1/computers?hostname[]=Demo_Qakbot_1&limit=10&offset=20
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/computers?hostname[]=Demo_Qakbot_1&limit=10&offset=20'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3304
x-ratelimit-remaining: 2737
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-08-02T18:40:25Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/computers?hostname[]=Demo_Qakbot_1&limit=10&offset=20",
      "prev": "https://api.eu.amp.cisco.com/v1/computers?hostname%5B%5D=Demo_Qakbot_1&limit=10&offset=0"
    },
    "results": {
      "total": 1,
      "current_item_count": 0,
      "index": 20,
      "items_per_page": 10
    }
  },
  "data": [

  ]
}

Fetch list of computers filtered by internal_ip

Request

Requires Authorization
GET /v1/computers?internal_ip=104.21.179.27&limit=10&offset=20
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/computers?internal_ip=104.21.179.27&limit=10&offset=20'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3304
x-ratelimit-remaining: 2735
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-08-02T18:40:25Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/computers?internal_ip=104.21.179.27&limit=10&offset=20",
      "prev": "https://api.eu.amp.cisco.com/v1/computers?internal_ip=104.21.179.27&limit=10&offset=0"
    },
    "results": {
      "total": 1,
      "current_item_count": 0,
      "index": 20,
      "items_per_page": 10
    }
  },
  "data": [

  ]
}

Fetch list of computers filtered by external_ip

Request

Requires Authorization
GET /v1/computers?external_ip=152.58.0.128&limit=10&offset=20
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/computers?external_ip=152.58.0.128&limit=10&offset=20'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3304
x-ratelimit-remaining: 2733
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-08-02T18:40:25Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/computers?external_ip=152.58.0.128&limit=10&offset=20",
      "prev": "https://api.eu.amp.cisco.com/v1/computers?external_ip=152.58.0.128&limit=10&offset=0"
    },
    "results": {
      "total": 1,
      "current_item_count": 0,
      "index": 20,
      "items_per_page": 10
    }
  },
  "data": [

  ]
}

Fetch list of computers filtered by group_guid

Request

Requires Authorization
GET /v1/computers?group_guid[]=b077d6bc-bbdf-42f7-8838-a06053fbd98a&limit=10&offset=20
Headers
accept: application/json
content-type: application/json
authorization: Basic FILTERED

cURL Edit, then copy and paste on your terminal

curl -X GET \
-H 'accept: application/json' \
-H 'content-type: application/json' \
--compressed -H 'Accept-Encoding: gzip, deflate' \
-u YOUR_API_CLIENT_ID \
'https://api.eu.amp.cisco.com/v1/computers?group_guid[]=b077d6bc-bbdf-42f7-8838-a06053fbd98a&limit=10&offset=20'

Response

Shortened for readability

strict-transport-security: max-age=31536000
content-type: application/json; charset=utf-8
status: 200 OK
x-ratelimit-limit: 3000
x-ratelimit-reset: 3303
x-ratelimit-remaining: 2731
x-frame-options: SAMEORIGIN
x-ratelimit-resetdate: 2019-08-02T18:40:25Z
transfer-encoding: chunked
{
  "version": "v1.2.0",
  "metadata": {
    "links": {
      "self": "https://api.eu.amp.cisco.com/v1/computers?group_guid[]=b077d6bc-bbdf-42f7-8838-a06053fbd98a&limit=10&offset=20",
      "prev": "https://api.eu.amp.cisco.com/v1/computers?group_guid%5B%5D=b077d6bc-bbdf-42f7-8838-a06053fbd98a&limit=10&offset=0"
    },
    "results": {
      "total": 1,
      "current_item_count": 0,
      "index": 20,
      "items_per_page": 10
    }
  },
  "data": [

  ]
}