- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

I get the following errors when try to collect events using the log analytics add on against azure. the query I use in the input is:
Log Analytics Query
AzureActivity | search *
and the query works if I run it in the workspace. any ideas?
07-18-2019 16:45:05.078 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" ERRORlocal variable 'data' referenced before assignment
07-18-2019 16:45:05.045 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" UnboundLocalError: local variable 'data' referenced before assignment
07-18-2019 16:45:05.045 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" for i in range(len(data["tables"][0]["rows"])):
07-18-2019 16:45:05.045 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" File "/opt/splunk/etc/apps/TA-ms-loganalytics/bin/input_module_log_analytics.py", line 86, in collect_events
07-18-2019 16:45:05.045 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" input_module.collect_events(self, ew)
07-18-2019 16:45:05.044 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" File "/opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py", line 96, in collect_events
07-18-2019 16:45:05.044 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" self.collect_events(ew)
07-18-2019 16:45:05.044 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" File "/opt/splunk/etc/apps/TA-ms-loganalytics/bin/ta_ms_loganalytics/modinput_wrapper/base_modinput.py", line 127, in stream_events
07-18-2019 16:45:05.044 +0000 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-ms-loganalytics/bin/log_analytics.py" Traceback (most recent call last):
tagging @jkat54
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

No, but literally 20 min after I posted this I found the log I should have been looking at and it says this:
2019-07-18 18:04:53,241 ERROR pid=61422 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="AzureActivityLogs" status="403" step="Post Query" response="{"error":{"message":"The provided credentials have insufficient access to perform the requested operation","code":"InsufficientAccessError"}}"
so it's pretty obvious it's a perms issue at this point. I'm waiting to hear back from the Azure group to fix it.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

No, but literally 20 min after I posted this I found the log I should have been looking at and it says this:
2019-07-18 18:04:53,241 ERROR pid=61422 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="AzureActivityLogs" status="403" step="Post Query" response="{"error":{"message":"The provided credentials have insufficient access to perform the requested operation","code":"InsufficientAccessError"}}"
so it's pretty obvious it's a perms issue at this point. I'm waiting to hear back from the Azure group to fix it.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Govcloud or not?
