Please see the following:
Cisco AMP for Endpoints Events Input - https://splunkbase.splunk.com/app/3670/ 
Cisco AMP for Endpoints CIM Add-on - https://splunkbase.splunk.com/app/3686/ 
The Splunk app leverages the A4E Streaming Event API. This API requires read/write access. Also, it'll allow only five concurrent streams (a "stream", for this purpose, is the same as an "input" in the Splunk app - it's a set of event types and groups you'll pull from A4E). The streaming API doesn't do garbage collection, though, so when you delete an input in Splunk, you'd need to also manually delete the stream in the API; so keep an eye on that complexity." If you are still having trouble, you may want to reach out to Cisco TAC for support.
Please see the following:
Cisco AMP for Endpoints Events Input - https://splunkbase.splunk.com/app/3670/ 
Cisco AMP for Endpoints CIM Add-on - https://splunkbase.splunk.com/app/3686/ 
Please file issues on the development GitHub.
https://github.com/Cisco-AMP/amp4e_splunk_events_input/issues
 
		
		
		
		
		
	
			
		
		
			
					
		Seem can't get the Input to work. Keep getting timeout connecting. I have test manual telnet with port 443. It is working when test with telnet. Any advise?
