All Apps and Add-ons

Cisco AMP for Endpoints Config

merzinger
Splunk Employee
Splunk Employee

I am configuring the Cisco AMP for Endpoints input on our IDM instance.  When creating the input I am not able to specify the desired index for the data to go into.  My only options are main, summary, and history.  How do I specify my index?

Labels (1)
Tags (1)
0 Karma

merzinger
Splunk Employee
Splunk Employee

How would that allow me to specify an index?  The splunkbase app appears to not allow that.

0 Karma

diogofgm
SplunkTrust
SplunkTrust

Hi merzinger!
Have you tried to put the input into a private app and upload it? You need to pass the vetting but it should work. 

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...