All Apps and Add-ons

Cisco AMP for Endpoints Events - JSON Vulnerable Application Detected Incomplete

jscraig2006
Communicator

@samsnguy_cisco 
Hi Samson,

The current version 2.0.1of Cisco AMP for Endpoints Events seems to cut off the "Vulnerable Application Detected" JSON. It appears if there is a large amount of CVE info, it tends to leave the event incomplete and does not format the JSON correctly. I don't know if it is the behavior of the response or not. When running the python manually, it appears to do the same thing from api.amp.cisco.com. A limitation of the size of the JSON response.  Would this be correct?

 

Thanks,

 

John

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...

Secure Your Future: Mastering Upgrade Readiness for Splunk 10

Spotlight: The Splunk Health Assistant Add-On  The Splunk Health Assistant Add-On is your ultimate companion ...

Observability Unlocked: Kubernetes & Cloud Monitoring with Splunk IM

Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team on ...