Our CiscoAMP was not showing up in Splunk until we re-downloaded the API key from the CiscoAMP portal as "Read/Write". The "read only" API key did not work. Also, we set up the logs to go to: index = "epav" Note: we also had to re-configure the inputs after applying the R/W API by deleting the previous input.
... View more