All Apps and Add-ons

Cisco AMP for Endpoints Events Input is not having any input. Stuck at Please wait.

Path Finder

Cisco AMP for Endpoints Events Input is stuck at "Please Wait" for all the tabs, Input, New Input and Configuration.

I can not perform any configuration or Input.

0 Karma


I know its been awhile for this question. I had the same issue.
1. Validate that outbound http is allowed from your splunk server
2. curl -k -X GET -H 'accept:application/json' -H 'content-type:application/json' --compressed -H 'Accept-Encoding:gzip,deflate' -u <THIRD_PARTY_API_KEY>:<API_KEY> ''

If you get a list of computers back then you are good.
Locate under etc\apps\amp4e_events_input\bin\pika\adapters and look for DO_HANDSHAKE = True and change it to False
Restart Splunk


Hey @jet1276,

Please refer this doc and also check if the pre-requisites are met

0 Karma

Path Finder

Hi @deepashri_123,

I have gone through all the details and pre-requisites and all the properties are met.

I have all the details from API, key and Clinet ID. But the only thing is after installing the App I am not getting the Input tab.

0 Karma


Are you using clustered environment or single instance?

0 Karma

Path Finder


It's running on Single instance. And I even tried installing in different versions of splunk. But everywhere I'm getting the same result.

0 Karma
Get Updates on the Splunk Community!

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...