Cisco amp endpoint events configuration


Hi All,

I am new here and got an issue when I tried to connect Cisco AMP.

Infos: Splunk Enterprise Version:8.0.3

Cisco AMP for Endpoints Events Input Version: 1.1.8

I have configured Cisco AMP (API host:, key, and ID: correct), splunk has internet access, and firewall rules are correct. 

Still, when I try to make a new input I've got an error messsage: "Warning! It appears your configuration is incomplete, so you will not be able to create any inputs. Please update your configuration."   

Do you have any idea? (tried the refresh)



Labels (1)
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>