Getting Data In
Highlighted

CISCO AMP for EndPoints Connection dropping

Engager

I have installed the CISCO AMP CIM add-on and the CISCo Add-on for AMP for EndPoints inputs. I can create the inupts but I am not getting any data in Splunk.
I keep getting the following messages in the amp4eeventsinput.log:
Connected. Starting to consume.
2018-01-15 15:28:39,399 INFO Amp4eEvents - Received response from ApiService (200)
2018-01-15 15:34:46,357 WARNING Amp4eEvents - Connection error (1516048486.36, : The AMQP connection was closed: ())! Reconnecting in about 3 seconds.

I have seen multiple INFO Amp4eEvents - Received response from ApiService (200) messages but I see no data in Splunk.

Any help anyone can offer is greatly appreciated.

0 Karma
Highlighted

Re: CISCO AMP for EndPoints Connection dropping

Explorer

Hi,

Has anyone found a solution to the above?

Thanks,

0 Karma
Highlighted

Re: CISCO AMP for EndPoints Connection dropping

Explorer

i am also facing the issue but the logs has been written to the indexers but it will be written to index=main.

Also we have used heavy forwarder to install these apps

0 Karma