on 07-08-201909:21 PM - edited on 02-24-202010:10 PM by Monica Lluis
Question
When I run a search in AMP4E console, I get results showing that a file was encountered recently by a number of hosts in my environment. When I do the same search in Cisco Threat Response (CTR), no targets are returned, and I get the error message:
"There was a client error in the AMP module: API client does not have write access [403]"
Why is this and how can I fix it?
Answer
This condition is likely due to the combination of an AMP API key that is set as read-only, combined with setting the AMP module in CTR as "Act in the Name of the Active User". When CTR calls AMP for results, a dynamic API key is created using your native credentials, which lacks the privileges to find hosts in the AMP environment.
Workaround
You can either:
1. Disable the setting "Act in the Name of the Active User", and you should see all the hosts you're expecting in your query, or
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: