<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AMP for Endpoints Events Input: Cannot retrieve data despite correct credential input in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424185#M51787</link>
    <description>&lt;P&gt;Okay. Thanks for advice.&lt;/P&gt;</description>
    <pubDate>Sun, 16 Jun 2019 01:39:21 GMT</pubDate>
    <dc:creator>ksakagaw</dc:creator>
    <dc:date>2019-06-16T01:39:21Z</dc:date>
    <item>
      <title>Cisco AMP for Endpoints Events Input: Cannot retrieve data despite correct credential input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424183#M51785</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am setting up to "Cisco AMP for Endpoints Events Input" on windows 2016.&lt;BR /&gt;
I think the following 3 credentials are correct because I can retrieve information using curl command with these credential.&lt;/P&gt;

&lt;P&gt;-AMP for Endpoints API Host &lt;BR /&gt;
  -API Client ID &lt;BR /&gt;
  -API Key &lt;/P&gt;

&lt;P&gt;After I input the following credentials, I select "New Input" tab, The following message appears:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"Warning! We couldn’t retrieve the information from API with provided credentials. Please make sure the API host is accessible or re-configure the input with correct credentials."
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Did I miss some setting? &lt;BR /&gt;
Please advise me about the possible cause.&lt;/P&gt;

&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2019 16:46:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424183#M51785</guid>
      <dc:creator>ksakagaw</dc:creator>
      <dc:date>2019-06-15T16:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints Events Input: Cannot retrieve data despite correct credential input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424184#M51786</link>
      <description>&lt;P&gt;You would probably be better off posting to Cisco forums.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2019 23:15:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424184#M51786</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-06-15T23:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints Events Input: Cannot retrieve data despite correct credential input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424185#M51787</link>
      <description>&lt;P&gt;Okay. Thanks for advice.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2019 01:39:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424185#M51787</guid>
      <dc:creator>ksakagaw</dc:creator>
      <dc:date>2019-06-16T01:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints Events Input: Cannot retrieve data despite correct credential input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424186#M51788</link>
      <description>&lt;P&gt;Hi @ksakagaw,&lt;/P&gt;

&lt;P&gt;Try setting API Host should to api.eu.amp.cisco.com.&lt;/P&gt;

&lt;P&gt;seems like the same issue as : &lt;A href="https://answers.splunk.com/answers/697574/how-to-configure-cisco-amp-for-endpoints-events-in.html"&gt;https://answers.splunk.com/answers/697574/how-to-configure-cisco-amp-for-endpoints-events-in.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 08:46:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424186#M51788</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-18T08:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints Events Input: Cannot retrieve data despite correct credential input</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424187#M51789</link>
      <description>&lt;P&gt;Have a look into the logfile (in our install, this was the path, you might have to look for it)  /opt/splunk/var/log/splunk/amp4e_events_input.log&lt;/P&gt;

&lt;P&gt;look for SSL-errors (supposedly someone screwed up the certificate-handling when packing this app)&lt;/P&gt;

&lt;P&gt;did the Handshake-fix mentioned here: &lt;A href="https://github.com/Cisco-AMP/amp4e_splunk_events_input/issues/5" target="_blank"&gt;https://github.com/Cisco-AMP/amp4e_splunk_events_input/issues/5&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;did the ssl-shared-options-fix mentioned here: &lt;A href="https://github.com/Cisco-AMP/amp4e_splunk_events_input/issues/12" target="_blank"&gt;https://github.com/Cisco-AMP/amp4e_splunk_events_input/issues/12&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This atleast got the log to connect and say " INFO Amp4eEvents - Connected. Starting to consume."&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cisco-AMP-for-Endpoints-Events-Input-Cannot-retrieve-data/m-p/424187#M51789</guid>
      <dc:creator>alindkvist</dc:creator>
      <dc:date>2020-09-30T01:03:40Z</dc:date>
    </item>
  </channel>
</rss>

