Installation

Cisco AMP Input is not working...

navan1
Explorer

Hello all,

When we try to create a Cisco AMP4ep input, it is not allowing us to create one. The save button isn't working, see attached. I tried to create the input, but it is not working either. See the attachment.

Splunk Version : 9.0.4.1

Cisco AMP for endpoints input version : 3.0.0

Current input(created manually)
-------------------------------------------

[amp4e_events_input]
api_host = api.amp.cisco.com
api_id = API pin
disabled = 0
eai_app_name = search
eai_user_name = admin
rcvbuf = 1572864

[amp4e_events_input://SPLUNK]
api_host = api.amp.cisco.com
api_id = api pin
index = my_index
source = amp4e_events_input://cisco_amp
sourcetype = cisco:amp:event
stream_name = Splunk_amp4ep

 

Can anyone help with the correct input?

Regards,
Nav

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@navan1 - There could be a number of reasons for this but you could start with this:

  • Delete the whole App from the backend. And re-install it and then try creating the input again.

 

  • Check the browser console logs and splunkd.logs and the Add-on specific log files to find more information about the issue.

 

I hope this helps!! Consider upvoting!!!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...