All Apps and Add-ons

Splunk addon for Azure error : ERROR401 Client Error: Unauthorized for url

dvarghes
Explorer

Hello,

I have been trying to use the Azure app for Splunk for fetching the "Azure billing" and "Azure compute" information. However, I am getting "ERROR401 Client Error: Unauthorized for url" error while enabling the data input :

03-24-2020 09:27:35.646 +0000 ERROR ExecProcessor - message from "python azure_consumption.py" ERROR401 Client Error: Unauthorized for url: 
https://management.azure.com/subscriptions/xxxxxxx/providers/Microsoft.Consumption/usageDetails?xxxx...

All the required API permissions have been already added. Please help what is missing.

=====================

Azure Active Directory Graph (1)
User.Read
Delegated

Sign in and read user profile

Granted for Default Directory
Azure Service Management (1)
user_impersonation
Delegated

Access Azure Service Management as organization users (preview)

Granted for Default Directory
Microsoft Graph (9)
Analytics.Read
Delegated

Read user activity statistics

AuditLog.Read.All
Delegated
Read audit log data

AuditLog.Read.All
Application
Read all audit log data

Directory.Read.All
Delegated
Read directory data

Directory.Read.All
Application
Read directory data

Reports.Read.All
Delegated
Read all usage reports

SecurityEvents.Read.All
Delegated
Read your organization’s security events
User.Read
Delegated

Sign in and read user profile

Granted for Default Directory
User.Read.All
Application
Read all users' full profiles

0 Karma

dvarghes
Explorer

Any help with this ?

0 Karma

dvarghes
Explorer

Any help with this ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...