Getting Data In

CISCO AMP for EndPoints Connection dropping

MSISplunk
Engager

I have installed the CISCO AMP CIM add-on and the CISCo Add-on for AMP for EndPoints inputs. I can create the inupts but I am not getting any data in Splunk.
I keep getting the following messages in the amp4e_events_input.log:
Connected. Starting to consume.
2018-01-15 15:28:39,399 INFO Amp4eEvents - Received response from ApiService (200)
2018-01-15 15:34:46,357 WARNING Amp4eEvents - Connection error (1516048486.36, : The AMQP connection was closed: ())! Reconnecting in about 3 seconds.

I have seen multiple INFO Amp4eEvents - Received response from ApiService (200) messages but I see no data in Splunk.

Any help anyone can offer is greatly appreciated.

0 Karma

arthurlarson
Observer

Our CiscoAMP was not showing up in Splunk until we re-downloaded the API key from the CiscoAMP portal as "Read/Write".  The "read only" API key did not work.  Also, we set up the logs to go to: index = "epav"

Note: we also had to re-configure the inputs after applying the R/W API by deleting the previous input.

0 Karma

ussina04
Explorer

i am also facing the issue but the logs has been written to the indexers but it will be written to index=main.

Also we have used heavy forwarder to install these apps

0 Karma

snort80
Explorer

Hi,

Has anyone found a solution to the above?

Thanks,

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...