Getting Data In

Cisco AMP for Endpoints: How to get a clear view (via API) of how many agents are currently installed in the environment(Phone Home Event type)?

nicholas_bergma
New Member

App: Cisco AMP for Endpoints ver 1.1.0
Splunk: Cloud 6.6.3.2 (ES)

I'm attempting to find a way to get the total number of installed agents; I don't see a "phone home" event type, but is there another way to get a clear view (via API) of how many agents are currently installed in the environment?

My idea is to get this data into Splunk and create dashboards and reports indicating the total number of Agents and which group they're assigned to.

0 Karma

quihong
Path Finder

Yes. Check out the REST API MODULAR INPUT App on Splunkbase.

You'll need a create a custom response handler to parse out the data.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...