Getting Data In

How to configure Cisco AMP for Endpoints Events input

Kayoko
New Member

I tried to configure the AMP for Endpoints API Access on the Cisco AMP for Endpoints Events input app. However the configuration information is not working properly.
I got error message which is stated "Warning! We couldn’t retrieve the information from API with provided credentials. Please make sure the API host is accessible or re-configure the input with correct credentials."

AMP for Endpoints API Host: api.amp.cisco.com
API Client ID : entered the client ID generated by Cisco AMP (API Client have read and write scope)
API Key: entered the secret API key generated by Cisco AMP

If there is any instruction for setting of Cisco AMP for Endpoints Events input app?

Best Regards,

Tags (2)
0 Karma

jdamico1092
New Member

I'm also experiencing the same issue. I've verified connectivity and key access by using the curl command. Both return the expected output. Any ideas? The endpoint I'm using is api.amp.cisco.com which should be correct.

0 Karma

troja007
New Member

Any solution for this?? My splunk instance shows the same problem.

0 Karma

aamer86
Path Finder

Hi I just resolved this and thought to share it

first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com

Try this as a start

if it doesn't work let me know as i got it working

0 Karma

aamer86
Path Finder

Hi I just resolved this and thought to share it

first thing I noticed is
AMP for Endpoints API Host should be api.eu.amp.cisco.com

Try this as a start

if it doesn't work let me know as i got it working

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...