All Apps and Add-ons

AMP for Endpoints Event Inputs App

plao
Explorer

Hi

I was able to install and configure the AMP for Endpoints Event Inputs App for all Event Types and Groups. However, not sure why, when I do a search in Splunk, index=* sourcetype="cisco:amp:event", I can only see AMP4E events like from 8 hours ago, I am not able to see any of the recent AMP4E events

Labels (1)
0 Karma

plao
Explorer

Now all of a sudden, starting around 3:19pm, I started seeing some AMP4E events in Splunk

 

But they are coming in very slowly (not anything close to real time at all)

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...