Cisco-AMP / amp4e_splunk_events_input

BSD 2-Clause "Simplified" License
8 stars 12 forks source link

Streams created successfully but no events? #84

Open SecureCloudEngr opened 2 years ago

SecureCloudEngr commented 2 years ago

HI,

First, thanks for this great add-on!

Recently I've set this up and is able to create the input/stream successfully. I'm sure the API creds are all correctly, because I can run a query and see the streams created etc. And also I can use them to query events. However, I'm not seeing any events in my index. Anyone experience before and know what might be the problem? I've left the groups and events blank, so it should catch all.

Does the API runs at certain interval? Is it a pull or push? Is there anyway to debug or see the logs besides the amp4e_events_input.log?

Hope to hear from you guys soon. Thanks!

tanazy commented 2 years ago

Hi, same problem, no logs coming in

jdeanGit commented 1 year ago

Same problem here. Events were streaming into my index until 11/16/22. Didn't notice they had stopped until 5/2/23. I upgraded the app to latest version but it did not help. Additionally, the button to save a new is stuck on "Saving" before any parameters are entered into the form. Clicking it does nothing.