Getting 401 unauthorized in backend Google Workspace add-on logs. is there something messing in the Docs for this?
https://splunk.github.io/splunk-add-on-for-google-workspace/
Also is there an "impersonate" that is coded in the python scripts?
Thanks
Hi @formicas
Just to check - has this ever worked for you? ie is this a new installation or has it stopped working / been upgraded?
Did you work through the steps at https://splunk.github.io/splunk-add-on-for-google-workspace/Configureinputs1/ to create a service account?
In _internal are there any other errors or can you supply a more specific/verbose error relating to the issue that we can debug?
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
new - setup, we followed the github doc.
in _internal:
<HttpError 401 when requesting https://admin.googleapis.com/admin/reports/v1/activity/users/all/applications/adminstartTime=2025-10-27T14%3A22%3A37.000Z&endTime=2025-10-27T14%3A22%3A41.000Z&maxResults=1000&alt=json returned "Access denied. You are not authorized to read activity records.". Details: "[{'message': 'Access denied. You are not authorized to read activity records.', 'domain': 'global', 'reason': 'authError', 'location': 'Authorization', 'locationType': 'header'}]">