<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AMP for Endpoints Events Input : Unable to create input in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-events-input-unable-to-create-input/m-p/5143561#M8420</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1538229" target="_self"&gt;&lt;SPAN class=""&gt;Navaneethbr,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Did you resolve this issue, I'm facing the same issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I'm injesting logs from ciscoamp to heavy forwarder, but recently it stops receving logs from ciscoamp, and the same above error is shown when i check for the log file.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I would appreciate if you could help me resolve this issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2024 12:41:57 GMT</pubDate>
    <dc:creator>Muhammadibrahim69152</dc:creator>
    <dc:date>2024-07-11T12:41:57Z</dc:date>
    <item>
      <title>Cisco AMP for Endpoints Events Input : Unable to create input</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-events-input-unable-to-create-input/m-p/4862321#M7629</link>
      <description>&lt;P&gt;Hello Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get Cisco AMP4e logs to Splunk, while configuring the input I am getting below error.&lt;/P&gt;&lt;P&gt;Add-on -&amp;nbsp;Cisco AMP for Endpoints Events Input - 3.0.0&lt;/P&gt;&lt;P&gt;Splunk Version - 8.2.7&lt;BR /&gt;Note: The API host, ID and Key are correct. Verified with below command.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;url --request GET '&lt;A href="https://api.amp.cisco.com/v1/events" target="_blank" rel="noopener"&gt;https://api.amp.cisco.com/v1/events&lt;/A&gt;' -u 'my api id:my api key'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Error while creating the Input&lt;/P&gt;&lt;P&gt;Warning! We couldn’t retrieve the information from API with provided credentials. Please make sure the API host is accessible or re-configure the input with correct credentials.&lt;BR /&gt;&lt;BR /&gt;Error from&amp;nbsp;/opt/splunk/var/log/splunk/amp4e_events_input.log&lt;/P&gt;&lt;P&gt;2023-06-26 05:35:34,486 ERROR Amp4eEvents - SSLError(MaxRetryError("HTTPSConnectionPool(host='api.amp.cisco.com', port=443): Max retries exceeded with url: /v1/event_streams/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)')))"))&lt;BR /&gt;ssl_context=context,&lt;BR /&gt;File "/opt/splunk/lib/python3.7/site-packages/urllib3/util/ssl_.py", line 377, in ssl_wrap_socket&lt;BR /&gt;File "/opt/splunk/lib/python3.7/ssl.py", line 423, in wrap_socket&lt;BR /&gt;File "/opt/splunk/lib/python3.7/ssl.py", line 870, in _create&lt;BR /&gt;File "/opt/splunk/lib/python3.7/ssl.py", line 1139, in do_handshake&lt;BR /&gt;self._sslobj.do_handshake()&lt;BR /&gt;ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)&lt;BR /&gt;urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='api.amp.cisco.com', port=443): Max retries exceeded with url: /v1/event_types/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)')))&lt;BR /&gt;requests.exceptions.SSLError: HTTPSConnectionPool(host='api.amp.cisco.com', port=443): Max retries exceeded with url: /v1/event_types/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)')))&lt;BR /&gt;ssl_context=context,&lt;BR /&gt;File "/opt/splunk/lib/python3.7/site-packages/urllib3/util/ssl_.py", line 377, in ssl_wrap_socket&lt;BR /&gt;File "/opt/splunk/lib/python3.7/ssl.py", line 423, in wrap_socket&lt;BR /&gt;File "/opt/splunk/lib/python3.7/ssl.py", line 870, in _create&lt;BR /&gt;File "/opt/splunk/lib/python3.7/ssl.py", line 1139, in do_handshake&lt;BR /&gt;self._sslobj.do_handshake()&lt;BR /&gt;ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)&lt;BR /&gt;urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='api.amp.cisco.com', port=443): Max retries exceeded with url: /v1/event_types/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)')))&lt;BR /&gt;requests.exceptions.SSLError: HTTPSConnectionPool(host='api.amp.cisco.com', port=443): Max retries exceeded with url: /v1/event_types/ (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)')))&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Can anyone help with solution for this issue?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Navaneeth BR&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 11:08:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-events-input-unable-to-create-input/m-p/4862321#M7629</guid>
      <dc:creator>navaneethbr</dc:creator>
      <dc:date>2023-06-26T11:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints Events Input : Unable to create input</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-events-input-unable-to-create-input/m-p/4862354#M7630</link>
      <description>The python that Splunk AMP app doesn't trust the cert its seeing.&lt;BR /&gt;&lt;BR /&gt;Are you using WSA or Umbrella SIG where it's decrypting the web requests?  Set this destination to not be decrypted.&lt;BR /&gt;</description>
      <pubDate>Mon, 26 Jun 2023 11:49:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-events-input-unable-to-create-input/m-p/4862354#M7630</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-06-26T11:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints Events Input : Unable to create input</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-events-input-unable-to-create-input/m-p/5143561#M8420</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1538229" target="_self"&gt;&lt;SPAN class=""&gt;Navaneethbr,&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Did you resolve this issue, I'm facing the same issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I'm injesting logs from ciscoamp to heavy forwarder, but recently it stops receving logs from ciscoamp, and the same above error is shown when i check for the log file.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I would appreciate if you could help me resolve this issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 12:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-events-input-unable-to-create-input/m-p/5143561#M8420</guid>
      <dc:creator>Muhammadibrahim69152</dc:creator>
      <dc:date>2024-07-11T12:41:57Z</dc:date>
    </item>
  </channel>
</rss>

