<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues getting logs from Microsoft Log Analytics Add-on in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377024#M45764</link>
    <description>&lt;P&gt;Hoping you can help me @jkat54.  We are working with the Azure team on testing the pull of log from the Cloud to one of their standalone Search Heads.  They provided the inputs from Azure (Workspace ID, Subscription, Tenant, etc) with the exception of the Log Analytics query.  Is that something they are supposed to define or set and provide to us, or something we are just supposed to define for searching?  I just put SecurityBaseline in there because it is required, but get nothing.  I have tried SecurityEvent as well and a few other examples in the documentation.  Also, what would you recommend we set for the Interval and Start Date to test?  &lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2019 13:18:32 GMT</pubDate>
    <dc:creator>kforr74</dc:creator>
    <dc:date>2019-07-11T13:18:32Z</dc:date>
    <item>
      <title>Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377024#M45764</link>
      <description>&lt;P&gt;Hoping you can help me @jkat54.  We are working with the Azure team on testing the pull of log from the Cloud to one of their standalone Search Heads.  They provided the inputs from Azure (Workspace ID, Subscription, Tenant, etc) with the exception of the Log Analytics query.  Is that something they are supposed to define or set and provide to us, or something we are just supposed to define for searching?  I just put SecurityBaseline in there because it is required, but get nothing.  I have tried SecurityEvent as well and a few other examples in the documentation.  Also, what would you recommend we set for the Interval and Start Date to test?  &lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 13:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377024#M45764</guid>
      <dc:creator>kforr74</dc:creator>
      <dc:date>2019-07-11T13:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377025#M45765</link>
      <description>&lt;P&gt;Tons of errors for me, with almost every query I put In here&lt;/P&gt;

&lt;P&gt;file=base_modinput.py:log_error:307 | Get error when collecting events.&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ms-loganalytics/bin/ta_ms_loganalytics/modinput_wrapper/base_modinput.py", line 127, in stream_events&lt;BR /&gt;
    self.collect_events(ew)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py", line 96, in collect_events&lt;/P&gt;

&lt;P&gt;file=connectionpool.py:_make_request:400 | &lt;A href="https://api.loganalytics.io:443" target="_blank"&gt;https://api.loganalytics.io:443&lt;/A&gt; "POST /v1/workspaces/SPZE2HSTPRD001OMSLogAnalytics/query HTTP/1.1" 404 84&lt;/P&gt;

&lt;P&gt;TokenRequest:No user_id passed for cache query&lt;/P&gt;

&lt;P&gt;file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA-ms-loganalytics/storage/collections/data/TA_ms_loganalytics_checkpointer/SoftPro_Log_Analytics_Input HTTP/1.1" 404 140&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:13:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377025#M45765</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2020-09-30T01:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377026#M45766</link>
      <description>&lt;P&gt;See this:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/700795/v103-seeing-a-get-error-when-collecting-events.html"&gt;https://answers.splunk.com/answers/700795/v103-seeing-a-get-error-when-collecting-events.html&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tested with several other searches - and all fail when requesting SecurityEvent - eg :

 SecurityEvent
 | top 10 by TimeGenerated

fails - and

 AzureActivity
 | top 10 by TimeGenerated

writes to index
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 11 Jul 2019 13:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377026#M45766</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-11T13:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377027#M45767</link>
      <description>&lt;P&gt;I recommend whatever suites you for start date and interval.&lt;/P&gt;

&lt;P&gt;Just note that azure storage underneath this is "eventual consistency", and that's why we added the lag to it.&lt;/P&gt;

&lt;P&gt;Most users have reported lag of 15 - 30 minutes works well with intervals of 15 or 30 minutes.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 13:51:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377027#M45767</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-11T13:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377028#M45768</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;  The errors have reduces when I use &lt;BR /&gt;
AzureActivity&lt;BR /&gt;
top 10 by TimeGenerated&lt;BR /&gt;
as the query, however, I am still receiving errors and nothing in the index yet:&lt;/P&gt;

&lt;P&gt;7/11/19&lt;BR /&gt;
3:49:21.776 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.776 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" ERRORlocal variable 'data' referenced before assignment&lt;BR /&gt;
host = ***** source =   /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
7/11/19&lt;BR /&gt;
3:49:21.747 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.747 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" UnboundLocalError: local variable 'data' referenced before assignment&lt;BR /&gt;
host = ***** source =   /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
7/11/19&lt;BR /&gt;
3:49:21.747 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.747 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py"     for i in range(len(data["tables"][0]["rows"])):&lt;BR /&gt;
host = ***** source =   /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
7/11/19&lt;BR /&gt;
3:49:21.747 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.747 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py"   File "/splunk/etc/apps/TA-ms-loganalytics/bin/input_module_log_analytics.py", line 86, in collect_events&lt;BR /&gt;
host = ***** source =   /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
7/11/19&lt;BR /&gt;
3:49:21.747 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.747 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py"     input_module.collect_events(self, ew)&lt;BR /&gt;
host = ***** source =   /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
7/11/19&lt;BR /&gt;
3:49:21.747 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.747 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py"   File "/opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py", line 96, in collect_events&lt;BR /&gt;
host =***** source =    /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
7/11/19&lt;BR /&gt;
3:49:21.747 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.747 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py"     self.collect_events(ew)&lt;BR /&gt;
host = ***** source =   /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
7/11/19&lt;BR /&gt;
3:49:21.747 PM&lt;BR /&gt;&lt;BR /&gt;
07-11-2019 15:49:21.747 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py"   File "/splunk/etc/apps/TA-ms-loganalytics/bin/ta_ms_loganalytics/modinput_wrapper/base_modinput.py", line 127, in stream_events&lt;BR /&gt;
host = ***** source =   /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:17:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377028#M45768</guid>
      <dc:creator>kforr74</dc:creator>
      <dc:date>2020-09-30T01:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377029#M45769</link>
      <description>&lt;P&gt;@jaxjohnny2000 got his working by using the workspace ID, you're already using the ID.  Have you tried using the name instead?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 02:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377029#M45769</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-12T02:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377030#M45770</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;As per our emails we found that the app is hardcoded for the non-Goverment Azure cloud, and you need the Gov Cloud version of the API instead.  &lt;/P&gt;

&lt;P&gt;In short you need to use this API:&lt;/P&gt;

&lt;P&gt;api.loganalytics.us&lt;/P&gt;

&lt;P&gt;and the app is trying to use this API:&lt;/P&gt;

&lt;P&gt;api.loganalytics.io&lt;/P&gt;

&lt;P&gt;To fix this you'll have to modify code in the app.&lt;/P&gt;

&lt;P&gt;Please modify TA-ms-loganalytics\bin\input_module_log_analytics.py as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE 45:        resource  = 'https://api.loganalytics.io/'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Becomes  (not actually used in the code that i see, but you can still update it)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE 45:        resource  = 'https://api.loganalytics.us/'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE 49:        token_response = context.acquire_token_with_client_credentials('https://api.loganalytics.io/', application_id, application_key)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Becomes&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Line 49:        token_response = context.acquire_token_with_client_credentials('https://api.loganalytics.us/', application_id, application_key)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE 59:        uri_base = 'https://api.loganalytics.io/'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Becomes:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LINE 59:        uri_base = 'https://api.loganalytics.us/'
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377030#M45770</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-30T01:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377031#M45771</link>
      <description>&lt;P&gt;For simplicity, i have updated the code and hosted it on pastebin so you can just copy and replace:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://pastebin.com/TYsV6iAa"&gt;https://pastebin.com/TYsV6iAa&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 17:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377031#M45771</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-15T17:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377032#M45772</link>
      <description>&lt;P&gt;I made those changes, and guess what, I am now getting logs!  Thanks again!&lt;/P&gt;

&lt;P&gt;7/15/19&lt;BR /&gt;
5:56:55.000 PM&lt;BR /&gt;&lt;BR /&gt;
{   [-] &lt;BR /&gt;
     Category:   Alert&lt;BR /&gt;&lt;BR /&gt;
     count_:     506&lt;BR /&gt;&lt;BR /&gt;
}&lt;BR /&gt;
Show as raw text&lt;BR /&gt;
host =  vac20logecs205.va.gov source =  log_analytics://splunk_va_azure_cloud sourcetype =  loganalytics&lt;BR /&gt;
7/15/19&lt;BR /&gt;
5:56:55.000 PM&lt;BR /&gt;&lt;BR /&gt;
{   [-] &lt;BR /&gt;
     Category:   Policy &lt;BR /&gt;
     count_:     430301 &lt;BR /&gt;
}&lt;BR /&gt;
Show as raw text&lt;BR /&gt;
host =  vac20logecs205.va.gov source =  log_analytics://splunk_va_azure_cloud sourcetype =  loganalytics&lt;BR /&gt;
7/15/19&lt;BR /&gt;
5:56:55.000 PM&lt;BR /&gt;&lt;BR /&gt;
{   [-] &lt;BR /&gt;
     Category:   Administrative &lt;BR /&gt;
     count_:     708207 &lt;BR /&gt;
}&lt;BR /&gt;
Show as raw text&lt;BR /&gt;
host =  vac20logecs205.va.gov source =  log_analytics://splunk_va_azure_cloud sourcetype =  loganalytics&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377032#M45772</guid>
      <dc:creator>kforr74</dc:creator>
      <dc:date>2020-09-30T01:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issues getting logs from Microsoft Log Analytics Add-on</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377033#M45773</link>
      <description>&lt;P&gt;Thanks for troubleshooting with me all the way through to the end!&lt;/P&gt;

&lt;P&gt;If you appreciate the effort I put in, feel free to let others know by recommending me on linkedin.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://linkedin.com/in/global-splunk-consultant"&gt;https://linkedin.com/in/global-splunk-consultant&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 18:27:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Issues-getting-logs-from-Microsoft-Log-Analytics-Add-on/m-p/377033#M45773</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2019-07-15T18:27:06Z</dc:date>
    </item>
  </channel>
</rss>

