All Apps and Add-ons

After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?

sharma11031988
Explorer

I am trying to perform a POC for a project while trying to integrate the Microsoft Log Analytics Add-on to the Splunk Enterprise free version.

After following steps as in https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-create-service-principa..., I have been getting the error below…..

Team could you please help me on this? What could be wrong?

2018-10-05 13:47:17,733 ERROR pid=27240 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="Test_New" status="403" step="Post Query" response="{"error":{"message":"The provided credentials have insufficient access to perform the requested operation","code":"InsufficientAccessError"}}"
Tags (1)
0 Karma
1 Solution

sharma11031988
Explorer

Issue was with missing reader permission on created App at Tenant subscription level.

View solution in original post

0 Karma

sharma11031988
Explorer

Issue was with missing reader permission on created App at Tenant subscription level.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@sharma11031988 If your problem is resolved, please accept the answer to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma

samhays
Path Finder

You might not be getting the level of responses you want here because your question "what could be wrong" is answered within the message you posted: "Insufficient Access Error".

This is an error on the Microsoft side, likely meaning you have some configuration problem in Azure.

Edit: https://www.splunk.com/blog/2018/04/20/splunking-microsoft-azure-monitor-data-part-1-azure-setup.htm... may be helpful.

0 Karma

sharma11031988
Explorer

Thanks Sam,

To be honest i am fairly new to azure thus this naive question :). However yes it was certainly limitation on my azure account role and app permission. Thanks for pushing me in right direction.

Cheers to Splunking!!!

0 Karma

samhays
Path Finder

No problem 🙂

Would you mind posting the solution though for future folks? - especially if the documentation that you mentioned was lacking something important.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...