Getting Data In

How to configure Cisco AMP for Endpoints Events input

Kayoko
New Member

I tried to configure the AMP for Endpoints API Access on the Cisco AMP for Endpoints Events input app. However the configuration information is not working properly.
I got error message which is stated "Warning! We couldn’t retrieve the information from API with provided credentials. Please make sure the API host is accessible or re-configure the input with correct credentials."

AMP for Endpoints API Host: api.amp.cisco.com
API Client ID : entered the client ID generated by Cisco AMP (API Client have read and write scope)
API Key: entered the secret API key generated by Cisco AMP

If there is any instruction for setting of Cisco AMP for Endpoints Events input app?

Best Regards,

Tags (2)
0 Karma

jdamico1092
New Member

I'm also experiencing the same issue. I've verified connectivity and key access by using the curl command. Both return the expected output. Any ideas? The endpoint I'm using is api.amp.cisco.com which should be correct.

0 Karma

troja007
New Member

Any solution for this?? My splunk instance shows the same problem.

0 Karma

aamer86
Path Finder

Hi I just resolved this and thought to share it

first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com

Try this as a start

if it doesn't work let me know as i got it working

0 Karma

aamer86
Path Finder

Hi I just resolved this and thought to share it

first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com

Try this as a start

if it doesn't work let me know as i got it working

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...