Cisco-AMP / amp4e_splunk_events_input

BSD 2-Clause "Simplified" License
8 stars 12 forks source link

Cisco Amp on private cloud splunk integration giving an error #49

Closed abdulshemeer166 closed 2 years ago

abdulshemeer166 commented 3 years ago

Unable to save the input getting error as below Input could not be saved: One of AMP for Endpoints API endpoints could not be reached (status 404). Please contact your Cisco AMP for Endpoints Administrator to resolve this issue. And in splunk the error is

2020-07-29 00:45:33,518 INFO Amp4eEvents - Controller - Creating the stream at API 2020-07-29 00:45:33,518 INFO Amp4eEvents - ApiService - creating stream with params {'name': u'event_streams', 'event_type': [u'553648130'], 'group_guid': []} 2020-07-29 00:45:33,604 INFO Amp4eEvents - Received response from ApiService (404) 2020-07-29 00:45:33,604 ERROR Amp4eEvents - API Error (status 404): {"version":"v1.0.0","metadata":{"links":{"self":"https://x.x.x.x/v1/event_streams/"}},"data":{},"errors":[{"error_code":404,"description":"Not Found","details":[]}]}

abdulshemeer166 commented 3 years ago

And also I tried to use the below curl which is generating the results

curl -k -H Content-Type:application/json https://11111111111111111111:11111111-1234-1234-1234-1234556788999@172.16.31.66/v1/computers

samsonnguyen commented 2 years ago

This is an issue with Secure Endpoints private cloud either not yet supporting the v1/event_streams api or the private cloud having the event_stream api enabled. Please contact your support for your Secure Endpoint private cloud