<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following &amp;quot;403 error&amp;quot;? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418188#M67433</link>
    <description>&lt;P&gt;@sharma11031988  If your problem is resolved, please accept the answer to help future readers.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Oct 2018 00:25:58 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2018-10-22T00:25:58Z</dc:date>
    <item>
      <title>After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418183#M67428</link>
      <description>&lt;P&gt;I am trying to perform a POC for a project while trying to integrate the Microsoft Log Analytics Add-on to the Splunk Enterprise free version.&lt;/P&gt;

&lt;P&gt;After following steps as in &lt;A href="https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-create-service-principal-portal"&gt;https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-create-service-principal-portal&lt;/A&gt;, I have been getting the error below…..&lt;/P&gt;

&lt;P&gt;Team could you please help me on this? What could be wrong?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-10-05 13:47:17,733 ERROR pid=27240 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="Test_New" status="403" step="Post Query" response="{"error":{"message":"The provided credentials have insufficient access to perform the requested operation","code":"InsufficientAccessError"}}"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 05 Oct 2018 18:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418183#M67428</guid>
      <dc:creator>sharma11031988</dc:creator>
      <dc:date>2018-10-05T18:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418184#M67429</link>
      <description>&lt;P&gt;You might not be getting the level of responses you want here because your question "what could be wrong" is answered within the message you posted: "Insufficient Access Error".  &lt;/P&gt;

&lt;P&gt;This is an error on the Microsoft side, likely meaning you have some configuration problem in Azure.&lt;/P&gt;

&lt;P&gt;Edit: &lt;A href="https://www.splunk.com/blog/2018/04/20/splunking-microsoft-azure-monitor-data-part-1-azure-setup.html"&gt;https://www.splunk.com/blog/2018/04/20/splunking-microsoft-azure-monitor-data-part-1-azure-setup.html&lt;/A&gt; &lt;EM&gt;may&lt;/EM&gt; be helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 21:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418184#M67429</guid>
      <dc:creator>samhays</dc:creator>
      <dc:date>2018-10-05T21:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418185#M67430</link>
      <description>&lt;P&gt;Thanks Sam,&lt;/P&gt;

&lt;P&gt;To be honest i am fairly new to azure thus this naive question :). However yes it was certainly limitation on my azure account role and app permission. Thanks for pushing me in right direction.&lt;/P&gt;

&lt;P&gt;Cheers to Splunking!!!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 22:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418185#M67430</guid>
      <dc:creator>sharma11031988</dc:creator>
      <dc:date>2018-10-05T22:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418186#M67431</link>
      <description>&lt;P&gt;No problem &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;

&lt;P&gt;Would you mind posting the solution though for future folks? - especially if the documentation that you mentioned was lacking something important.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 22:33:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418186#M67431</guid>
      <dc:creator>samhays</dc:creator>
      <dc:date>2018-10-05T22:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418187#M67432</link>
      <description>&lt;P&gt;Issue was with missing reader permission on created App at Tenant subscription level.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 23:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418187#M67432</guid>
      <dc:creator>sharma11031988</dc:creator>
      <dc:date>2018-10-21T23:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418188#M67433</link>
      <description>&lt;P&gt;@sharma11031988  If your problem is resolved, please accept the answer to help future readers.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 00:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/After-configuring-input-for-Splunk-Microsoft-Log-Analytics-Add/m-p/418188#M67433</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-10-22T00:25:58Z</dc:date>
    </item>
  </channel>
</rss>

