Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
danog
Participant

R80.30 API Access for Threat Prevention Stats

Jump to solution

Hi. Each month I give my manager a report that includes a screenshot of the Threat Prevention statistics from the MGMT server (number of high risk attacks, prevented attacks, etc). Now the aim is to see if this data can be collected automatically via an API.

I see on the Threat Prevention API Guide that it mentions API web service. I'm working with my data engineering colleagues on this but I'm not sure where to start. Firstly, is this particular information accessible via API? Would I have to give external access to the MGMT server as we'd be collecting data from an external location? 

The API guide seems to relate to something else that we're not looking to implement. Any advice would be appreciated!

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

The Threat Prevention API is mostly about submitting files to be emulated to find out if it’s malicious or not.
Reporting (statistics, etc) is all on the management server.
Those statistics are correlated from the logs and the like and are available as SmartEvent reports but not currently consumable via API.
You can consume logs via API in the most recent versions and potentially generate your own statistics or export your logs via syslog to a SIEM and have that generate the relevant statistics.

View solution in original post

2 Replies
PhoneBoy
Admin
Admin

The Threat Prevention API is mostly about submitting files to be emulated to find out if it’s malicious or not.
Reporting (statistics, etc) is all on the management server.
Those statistics are correlated from the logs and the like and are available as SmartEvent reports but not currently consumable via API.
You can consume logs via API in the most recent versions and potentially generate your own statistics or export your logs via syslog to a SIEM and have that generate the relevant statistics.

View solution in original post

danog
Participant

Hi PhoneBoy. Thanks very much for clarifying!

0 Kudos