Troubleshoot disconnected state of Sentinel data connector for Cisco AMP

Al2020s 5 Reputation points
2025-04-27T04:14:49.9733333+00:00

Follow the steps for ARM deployment according to https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/cisco-secure-endpoint-amp?source=recommendations
Connector was deployed but it is in the disconnected state.

All parameters in ARM template were entered accordingly. How can I troubleshoot it?

Microsoft Security | Microsoft Sentinel
{count} votes

2 answers

Sort by: Most helpful
  1. Al2020s 5 Reputation points
    2025-05-02T02:55:39.6766667+00:00

    Hello,

    Thank you all. The issue is resolved. I opened a case with Microsoft support: I was told that everything is set correctly but the issue was on their side, and they made some changes on backend. They did not provide me any details.

    1 person found this answer helpful.
    0 comments No comments

  2. Jyotishree Moharana 1,845 Reputation points Microsoft External Staff Moderator
    2025-04-28T17:45:12.9933333+00:00

    Hello @Al2020s,

    Few things can be checked to troubleshoot the issue.

    1. Under Data connector, check the last refresh time Cisco AMP for Endpoints, check if there are any error messages. Check the diagnostic logs for any error messages that would indicate the reason causing the issue.
    2. Check if the API key used for the connector is valid, verify AMP for Endpoints API endpoint is correct. You can test the connection to the API using Postman to confirm if it is accessible. Try re-authorizing i.e. removing and adding the API key again or you can regenerate API key from Cisco console and update in Sentinel. Verify that the API key has the necessary permissions (read permissions for events, alerts, etc.) to allow data collection. Check if AMP endpoint URL is correctly entered. The endpoint URL should match the one required by Cisco for the API (verify from Cisco AMP documentation).
    3. Check for any firewall or proxy rules setup in the server hosting the connector, if there is any blocking.
    4. From Cisco AMP Console ensure that the API Access is enabled for the required data. Check for any throttling issues that might affect the connection. Verify if the data sharing settings are configured correctly.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.