Troubleshoot disconnected state of Sentinel data connector for Cisco AMP

Al2020s 0 Reputation points
2025-04-27T04:14:49.9733333+00:00

Follow the steps for ARM deployment according to https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/cisco-secure-endpoint-amp?source=recommendations
Connector was deployed but it is in the disconnected state.

All parameters in ARM template were entered accordingly. How can I troubleshoot it?

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,268 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Jyotishree Moharana 795 Reputation points Microsoft External Staff
    2025-04-28T17:45:12.9933333+00:00

    Hello @Al2020s,

    Few things can be checked to troubleshoot the issue.

    1. Under Data connector, check the last refresh time Cisco AMP for Endpoints, check if there are any error messages. Check the diagnostic logs for any error messages that would indicate the reason causing the issue.
    2. Check if the API key used for the connector is valid, verify AMP for Endpoints API endpoint is correct. You can test the connection to the API using Postman to confirm if it is accessible. Try re-authorizing i.e. removing and adding the API key again or you can regenerate API key from Cisco console and update in Sentinel. Verify that the API key has the necessary permissions (read permissions for events, alerts, etc.) to allow data collection. Check if AMP endpoint URL is correctly entered. The endpoint URL should match the one required by Cisco for the API (verify from Cisco AMP documentation).
    3. Check for any firewall or proxy rules setup in the server hosting the connector, if there is any blocking.
    4. From Cisco AMP Console ensure that the API Access is enabled for the required data. Check for any throttling issues that might affect the connection. Verify if the data sharing settings are configured correctly.
    0 comments No comments

  2. Al2020s 0 Reputation points
    2025-05-02T02:55:39.6766667+00:00

    Hello,

    Thank you all. The issue is resolved. I opened a case with Microsoft support: I was told that everything is set correctly but the issue was on their side, and they made some changes on backend. They did not provide me any details.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.