I am configuring the Cisco AMP for Endpoints input on our IDM instance. When creating the input I am not able to specify the desired index for the data to go into. My only options are main, summary, and history. How do I specify my index?
How would that allow me to specify an index? The splunkbase app appears to not allow that.
Hi merzinger!
Have you tried to put the input into a private app and upload it? You need to pass the vetting but it should work.