All Apps and Add-ons

Splunk addon for Azure error : ERROR401 Client Error: Unauthorized for url

dvarghes
Explorer

Hello,

I have been trying to use the Azure app for Splunk for fetching the "Azure billing" and "Azure compute" information. However, I am getting "ERROR401 Client Error: Unauthorized for url" error while enabling the data input :

03-24-2020 09:27:35.646 +0000 ERROR ExecProcessor - message from "python azure_consumption.py" ERROR401 Client Error: Unauthorized for url: 
https://management.azure.com/subscriptions/xxxxxxx/providers/Microsoft.Consumption/usageDetails?xxxx...

All the required API permissions have been already added. Please help what is missing.

=====================

Azure Active Directory Graph (1)
User.Read
Delegated

Sign in and read user profile

Granted for Default Directory
Azure Service Management (1)
user_impersonation
Delegated

Access Azure Service Management as organization users (preview)

Granted for Default Directory
Microsoft Graph (9)
Analytics.Read
Delegated

Read user activity statistics

AuditLog.Read.All
Delegated
Read audit log data

AuditLog.Read.All
Application
Read all audit log data

Directory.Read.All
Delegated
Read directory data

Directory.Read.All
Application
Read directory data

Reports.Read.All
Delegated
Read all usage reports

SecurityEvents.Read.All
Delegated
Read your organization’s security events
User.Read
Delegated

Sign in and read user profile

Granted for Default Directory
User.Read.All
Application
Read all users' full profiles

0 Karma

dvarghes
Explorer

Any help with this ?

0 Karma

dvarghes
Explorer

Any help with this ?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...