I tried to configure the AMP for Endpoints API Access on the Cisco AMP for Endpoints Events input app. However the configuration information is not working properly.
I got error message which is stated "Warning! We couldn’t retrieve the information from API with provided credentials. Please make sure the API host is accessible or re-configure the input with correct credentials."
AMP for Endpoints API Host: api.amp.cisco.com
API Client ID : entered the client ID generated by Cisco AMP (API Client have read and write scope)
API Key: entered the secret API key generated by Cisco AMP
If there is any instruction for setting of Cisco AMP for Endpoints Events input app?
Best Regards,
I'm also experiencing the same issue. I've verified connectivity and key access by using the curl command. Both return the expected output. Any ideas? The endpoint I'm using is api.amp.cisco.com which should be correct.
Any solution for this?? My splunk instance shows the same problem.
Hi I just resolved this and thought to share it
first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com
Try this as a start
if it doesn't work let me know as i got it working
Hi I just resolved this and thought to share it
first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com
Try this as a start
if it doesn't work let me know as i got it working