All Apps and Add-ons

After configuring input for Splunk Microsoft Log Analytics Add-on, why am I getting the following "403 error"?

sharma11031988
Explorer

I am trying to perform a POC for a project while trying to integrate the Microsoft Log Analytics Add-on to the Splunk Enterprise free version.

After following steps as in https://docs.microsoft.com/en-us/azure/azure-resource-manager/resource-group-create-service-principa..., I have been getting the error below…..

Team could you please help me on this? What could be wrong?

2018-10-05 13:47:17,733 ERROR pid=27240 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="Test_New" status="403" step="Post Query" response="{"error":{"message":"The provided credentials have insufficient access to perform the requested operation","code":"InsufficientAccessError"}}"
Tags (1)
0 Karma
1 Solution

sharma11031988
Explorer

Issue was with missing reader permission on created App at Tenant subscription level.

View solution in original post

0 Karma

sharma11031988
Explorer

Issue was with missing reader permission on created App at Tenant subscription level.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@sharma11031988 If your problem is resolved, please accept the answer to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma

samhays
Path Finder

You might not be getting the level of responses you want here because your question "what could be wrong" is answered within the message you posted: "Insufficient Access Error".

This is an error on the Microsoft side, likely meaning you have some configuration problem in Azure.

Edit: https://www.splunk.com/blog/2018/04/20/splunking-microsoft-azure-monitor-data-part-1-azure-setup.htm... may be helpful.

0 Karma

sharma11031988
Explorer

Thanks Sam,

To be honest i am fairly new to azure thus this naive question :). However yes it was certainly limitation on my azure account role and app permission. Thanks for pushing me in right direction.

Cheers to Splunking!!!

0 Karma

samhays
Path Finder

No problem 🙂

Would you mind posting the solution though for future folks? - especially if the documentation that you mentioned was lacking something important.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...