All Apps and Add-ons

Cisco AMP for Endpoints Events Input: Why is the data not being received and we are receiving this error" ...The AMQP connection was closed..."?

clogssplunk
Explorer

Hi there,

We have the Cisco AMP for Endpoints Events Input 1.1.0 installed. Data is not being received and we see the following error message appearing.

Connection error (1518453972.9, : The AMQP connection was closed: ())! Reconnecting in about 3 seconds

I have confirmed that we can access api.amp.cisco.com using CURL. What am I missing?

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...