<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting errors when upgrading to Microsoft Azure Add-on version 2.1: &amp;quot;No logs ERROR401 Client Error&amp;quot;, &amp;quot;ERROR ExecProcessor&amp;quot;. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488440#M60116</link>
    <description>&lt;P&gt;I'm curious why it has "beta" instead of an api version, like v1.0, in the url that is returned in the error:&lt;BR /&gt;&lt;BR /&gt;
ERROR401 Client Error: Unauthorized for url: &lt;A href="https://graph.microsoft.com/beta/"&gt;https://graph.microsoft.com/beta/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 01 May 2020 19:10:27 GMT</pubDate>
    <dc:creator>mwyman_splunk</dc:creator>
    <dc:date>2020-05-01T19:10:27Z</dc:date>
    <item>
      <title>Getting errors when upgrading to Microsoft Azure Add-on version 2.1: "No logs ERROR401 Client Error", "ERROR ExecProcessor".</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488439#M60115</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I recently upgraded the Microsoft Azure Add-on TA to version 2.1.  Not only did it break the configuration, but there are also some added permissions that need to be applied on the Azure portal side.  I worked with someone on our Windows AD team who has the necessary access but he did not see what is referenced below in the details of the Add-on. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3757/"&gt;https://splunkbase.splunk.com/app/3757/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Microsoft Azure Active Directory Sign-ins   Microsoft Graph Read all audit log data&lt;BR /&gt;
    Windows Azure Active Directory  "(Application) Read directory data&lt;/P&gt;

&lt;P&gt;(Delegated) Read directory data"&lt;BR /&gt;
Microsoft Azure Active Directory Users  Microsoft Graph Read all audit log data&lt;BR /&gt;
    Windows Azure Active Directory  "(Application) Read directory data&lt;/P&gt;

&lt;P&gt;(Delegated) Read directory data"&lt;BR /&gt;
Microsoft Azure Active Directory Audit  Microsoft Graph Read all audit log data&lt;BR /&gt;
    Windows Azure Active Directory  "(Application) Read directory data&lt;/P&gt;

&lt;P&gt;(Delegated) Read directory data"&lt;/P&gt;

&lt;P&gt;These are the errors in the internal logs.  Any ideas?&lt;/P&gt;

&lt;P&gt;04-28-2020 15:58:03.014 -0400 &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-MS-AAD/bin/MS_AAD_audit.py" 

ERROR401 Client Error: Unauthorized for url: &lt;A href="https://graph.microsoft.com/beta/auditLogs/directoryAudits" target="test_blank"&gt;https://graph.microsoft.com/beta/auditLogs/directoryAudits&lt;/A&gt;?

$orderby=activityDateTime&amp;amp;$filter=activityDateTime+gt+2020-04-21T15:58:02.316173Z+and+activityDateTime+le+2020-04-28T19:51:02.559995Z
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 28 Apr 2020 20:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488439#M60115</guid>
      <dc:creator>njytrde</dc:creator>
      <dc:date>2020-04-28T20:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Getting errors when upgrading to Microsoft Azure Add-on version 2.1: "No logs ERROR401 Client Error", "ERROR ExecProcessor".</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488440#M60116</link>
      <description>&lt;P&gt;I'm curious why it has "beta" instead of an api version, like v1.0, in the url that is returned in the error:&lt;BR /&gt;&lt;BR /&gt;
ERROR401 Client Error: Unauthorized for url: &lt;A href="https://graph.microsoft.com/beta/"&gt;https://graph.microsoft.com/beta/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 19:10:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488440#M60116</guid>
      <dc:creator>mwyman_splunk</dc:creator>
      <dc:date>2020-05-01T19:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Getting errors when upgrading to Microsoft Azure Add-on version 2.1: "No logs ERROR401 Client Error", "ERROR ExecProcessor".</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488441#M60117</link>
      <description>&lt;P&gt;I'm curious why it has "beta" instead of an api version, like v1.0, in the url that is returned in the error:&lt;BR /&gt;&lt;BR /&gt;
ERROR401 Client Error: Unauthorized for url: &lt;A href="https://graph.microsoft.com/be"&gt;https://graph.microsoft.com/be&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2020 19:10:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488441#M60117</guid>
      <dc:creator>mwyman_splunk</dc:creator>
      <dc:date>2020-05-01T19:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Getting errors when upgrading to Microsoft Azure Add-on version 2.1: "No logs ERROR401 Client Error", "ERROR ExecProcessor".</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488442#M60118</link>
      <description>&lt;P&gt;So it turns out, the problem was, when I updated the TA version to 2.1 for Microsoft Azure Add-on for Splunk, the API permissions changed.&lt;/P&gt;

&lt;P&gt;Once Directory.Read.All and AuditLog.Read.All was added for the application and delegation for the microsoft graph, the logs started ingesting normally again. &lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2020 17:56:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-errors-when-upgrading-to-Microsoft-Azure-Add-on-version/m-p/488442#M60118</guid>
      <dc:creator>njytrde</dc:creator>
      <dc:date>2020-05-04T17:56:44Z</dc:date>
    </item>
  </channel>
</rss>

