Hello @Al2020s,
Few things can be checked to troubleshoot the issue.
- Under Data connector, check the last refresh time Cisco AMP for Endpoints, check if there are any error messages. Check the diagnostic logs for any error messages that would indicate the reason causing the issue.
- Check if the API key used for the connector is valid, verify AMP for Endpoints API endpoint is correct. You can test the connection to the API using Postman to confirm if it is accessible. Try re-authorizing i.e. removing and adding the API key again or you can regenerate API key from Cisco console and update in Sentinel. Verify that the API key has the necessary permissions (read permissions for events, alerts, etc.) to allow data collection. Check if AMP endpoint URL is correctly entered. The endpoint URL should match the one required by Cisco for the API (verify from Cisco AMP documentation).
- Check for any firewall or proxy rules setup in the server hosting the connector, if there is any blocking.
- From Cisco AMP Console ensure that the API Access is enabled for the required data. Check for any throttling issues that might affect the connection. Verify if the data sharing settings are configured correctly.