cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Update on Recent notifications for Event Steaming APIs for AMP for Endpoints console

1279
Views
0
Helpful
0
Comments

Symptoms

If you are encountering an issue with the AMP Event Stream and are unable to connect to an event stream resource using the AMQP protocol or Splunk AMP for Endpoints Event Stream Input app.

Diagnosis

During a recent update to address issues with the event streaming API, the queue credentials may have been reset.

Solution

There are two ways by which you can reset the Event Stream: -

1) If you are using the Splunk App:

Within the Splunk console or heavy forwarder with the AMP for Endpoints Events Input app installed:

Determine which inputs are not working and delete them - noting the existing event types and groups selections:

Splunk console > AMP for Endpoints Events Input > Inputs > Delete

Finally, re-create them using the same event types and groups selections

Splunk console > AMP for Endpoints Events Input > New Input (enter in data) > Save


2) In case you are not using Splunk App, you can reset the Event Stream using the REST API

List out the event streams on your organization using the REST API:

GET v1/event_streams

Determine which event streams are no longer working. If you do not have the existing credentials, you will have to delete and re-create the stream: 

DELETE v1/event_streams/{:id}

Create the new event stream using the REST API:
POST v1/event_streams

Please ignore the message if you have validated that your event streams are working properly. We apologize for any inconvenience and appreciate your patience as we continue to improve our product functionality.

Content for Community-Ad