I am trying to perform a POC for a project while trying to integrate the Microsoft Log Analytics Add-on to the Splunk Enterprise free version.
After following steps as in https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-create-service-principa..., I have been getting the error below…..
Team could you please help me on this? What could be wrong?
2018-10-05 13:47:17,733 ERROR pid=27240 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="Test_New" status="403" step="Post Query" response="{"error":{"message":"The provided credentials have insufficient access to perform the requested operation","code":"InsufficientAccessError"}}"
Issue was with missing reader permission on created App at Tenant subscription level.
Issue was with missing reader permission on created App at Tenant subscription level.
@sharma11031988 If your problem is resolved, please accept the answer to help future readers.
You might not be getting the level of responses you want here because your question "what could be wrong" is answered within the message you posted: "Insufficient Access Error".
This is an error on the Microsoft side, likely meaning you have some configuration problem in Azure.
Edit: https://www.splunk.com/blog/2018/04/20/splunking-microsoft-azure-monitor-data-part-1-azure-setup.htm... may be helpful.
Thanks Sam,
To be honest i am fairly new to azure thus this naive question :). However yes it was certainly limitation on my azure account role and app permission. Thanks for pushing me in right direction.
Cheers to Splunking!!!
No problem 🙂
Would you mind posting the solution though for future folks? - especially if the documentation that you mentioned was lacking something important.