<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Azure Addon for Splunk throwing error &amp;quot;log_error:309 | _Splunk_ Unable to obtain access token&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549837#M91317</link>
    <description>&lt;P&gt;So far I have not been able to fix it. If I do, I will definitely post the fix.&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2021 12:48:17 GMT</pubDate>
    <dc:creator>jwalzerpitt</dc:creator>
    <dc:date>2021-04-29T12:48:17Z</dc:date>
    <item>
      <title>Microsoft Azure Addon for Splunk throwing error "log_error:309 | _Splunk_ Unable to obtain access token"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549366#M91270</link>
      <description>&lt;P&gt;After configuring the addon as specified in the document, the error logs are showing&amp;nbsp;"log_error:309 | _Splunk_ Unable to obtain access token".&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been unable to find what the root cause of this error might be.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The addon has been installed on the IDM.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me out with this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 18:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549366#M91270</guid>
      <dc:creator>akriti</dc:creator>
      <dc:date>2021-04-26T18:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Addon for Splunk throwing error "log_error:309 | _Splunk_ Unable to obtain access token"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549521#M91286</link>
      <description>&lt;P&gt;I was also getting this error as well so I created a new client secret and double checked API permissions and I am now getting this error message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/aob_py3/modinput_wrapper/base_modinput.py", line 128, in stream_events&lt;BR /&gt;self.collect_events(ew)&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/MS_AAD_signins.py", line 92, in collect_events&lt;BR /&gt;input_module.collect_events(self, ew)&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/input_module_MS_AAD_signins.py", line 86, in collect_events&lt;BR /&gt;sign_in_response = azutils.get_items_batch(helper, access_token, url)&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_azure_utils/utils.py", line 55, in get_items_batch&lt;BR /&gt;raise e&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_azure_utils/utils.py", line 49, in get_items_batch&lt;BR /&gt;r.raise_for_status()&lt;BR /&gt;File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/aob_py3/requests/models.py", line 940, in raise_for_status&lt;BR /&gt;raise HTTPError(http_error_msg, response=self)&lt;BR /&gt;requests.exceptions.HTTPError: 403 Client Error: Forbidden for url: &lt;A href="https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&amp;amp;$filter=createdDateTime+gt+2021-04-26T16:06:15.458362Z+and+createdDateTime+le+2021-04-27T19:59:15.673961Z" target="_blank"&gt;https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&amp;amp;$filter=createdDateTime+gt+2021-04-26T16:06:15.458362Z+and+createdDateTime+le+2021-04-27T19:59:15.673961Z&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 20:08:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549521#M91286</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2021-04-27T20:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Addon for Splunk throwing error "log_error:309 | _Splunk_ Unable to obtain access token"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549688#M91298</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/103102"&gt;@jwalzerpitt&lt;/a&gt;&amp;nbsp;, thanks so much for letting me know! I followed what you did and I'm now getting the exact same error as you (&lt;SPAN&gt;HTTPError: 403 Client Error: Forbidden for url&lt;/SPAN&gt;).&amp;nbsp; I'm trying to troubleshoot it now.&lt;/P&gt;&lt;P&gt;Were you able to fix it?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 20:37:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549688#M91298</guid>
      <dc:creator>akriti</dc:creator>
      <dc:date>2021-04-28T20:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Addon for Splunk throwing error "log_error:309 | _Splunk_ Unable to obtain access token"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549837#M91317</link>
      <description>&lt;P&gt;So far I have not been able to fix it. If I do, I will definitely post the fix.&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 12:48:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/549837#M91317</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2021-04-29T12:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Addon for Splunk throwing error "log_error:309 | _Splunk_ Unable to obtain access token"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/551390#M91521</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/103102"&gt;@jwalzerpitt&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to fix the error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Added the Directory.Read.All in the API permissions along with the other permissions mentioned in the addon document for the sign-in input.&lt;/P&gt;&lt;P&gt;Earlier I had configured the API permissions with the type "delegated" on the Azure Portal but after changing it to type "Application" I'm getting all the sign-in data.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 20:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/551390#M91521</guid>
      <dc:creator>akriti</dc:creator>
      <dc:date>2021-05-12T20:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Azure Addon for Splunk throwing error "log_error:309 | _Splunk_ Unable to obtain access token"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/551445#M91526</link>
      <description>&lt;P&gt;Thx for the reply and info, but I actually opened a case with Microsoft about this and they said the issue was on their side and that they just fixed it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had all permissions and configs set correctly, but once they fixed their issue, sign in events/logs started to flow in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 12:10:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Microsoft-Azure-Addon-for-Splunk-throwing-error-quot-log-error/m-p/551445#M91526</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2021-05-13T12:10:46Z</dc:date>
    </item>
  </channel>
</rss>

