Getting Data In

How to configure Cisco AMP for Endpoints Events input

Kayoko
New Member

I tried to configure the AMP for Endpoints API Access on the Cisco AMP for Endpoints Events input app. However the configuration information is not working properly.
I got error message which is stated "Warning! We couldn’t retrieve the information from API with provided credentials. Please make sure the API host is accessible or re-configure the input with correct credentials."

AMP for Endpoints API Host: api.amp.cisco.com
API Client ID : entered the client ID generated by Cisco AMP (API Client have read and write scope)
API Key: entered the secret API key generated by Cisco AMP

If there is any instruction for setting of Cisco AMP for Endpoints Events input app?

Best Regards,

Tags (2)
0 Karma

jdamico1092
New Member

I'm also experiencing the same issue. I've verified connectivity and key access by using the curl command. Both return the expected output. Any ideas? The endpoint I'm using is api.amp.cisco.com which should be correct.

0 Karma

troja007
New Member

Any solution for this?? My splunk instance shows the same problem.

0 Karma

aamer86
Path Finder

Hi I just resolved this and thought to share it

first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com

Try this as a start

if it doesn't work let me know as i got it working

0 Karma

aamer86
Path Finder

Hi I just resolved this and thought to share it

first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com

Try this as a start

if it doesn't work let me know as i got it working

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...