All Apps and Add-ons

Cisco Secure Endpoint events

cwilmoth
Path Finder

We have configured the Cisco Security Cloud app with a Secure Endpoint input. The input works and we are getting some data, but not all of the same data that we got through the old Cisco AMP for Endpoints add-on. In the documentation for Cisco Security Cloud, there is a (mandatory) option to select Event Types when configuring the input. And it says that you can configure multiple Event Types here. We do not see this option when setting it up on our Splunk Cloud search head. Is this a bug?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...