All Apps and Add-ons

Cisco AMP for Endpoints Events - JSON Vulnerable Application Detected Incomplete

jscraig2006
Communicator

@samsnguy_cisco 
Hi Samson,

The current version 2.0.1of Cisco AMP for Endpoints Events seems to cut off the "Vulnerable Application Detected" JSON. It appears if there is a large amount of CVE info, it tends to leave the event incomplete and does not format the JSON correctly. I don't know if it is the behavior of the response or not. When running the python manually, it appears to do the same thing from api.amp.cisco.com. A limitation of the size of the JSON response.  Would this be correct?

 

Thanks,

 

John

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...