Getting Data In

Splunk Azure Storage Account not connecting

LinghGroove
Explorer

Hello,

I'm having troubles connection a Splunk instance with an Azure Storage Account. After the account was set i have configured my Splunk instance to connect with the Storage Account using the Splunk Add-on for Microsoft Cloud Services. 

When i enter the Account Name and the Account Secret it gives this error:
App-Err.PNG
This was configured from "Configuration" > "Azure Storage Account" > "Add".
I have controlled the Account Name and the Access Key, they are correct. Looking at the logs this was the only noticeble error that pops up:

 

log_level=ERROR pid=3270316 tid=MainThread file=storageaccount.py:validate:97 | Error <urllib3.connection.HTTPSConnection object at 0x7e14a4a8e940>: Failed to establish a new connection: [Errno -2] Name or service not known while verifying the credentials: Traceback (most recent call last):

 

other than this i saw some http requests with 502 error on the splunkd.log but i don't know if it is related. 
I have checked to see if the Splunk machine could reach the azure resourse and it can. It can also do api calls correctly. 
At this point i have no idea on what could cause this problem. 
Do you guys have any idea on what controls i could do to see where is the problem?
Did  i miss some configurations? Could it be some problems on the Azure side? If yes what controls should i do? 
(used the ufficial guide https://splunk.github.io/splunk-add-on-for-microsoft-cloud-services/Configurestorageaccount/)

Thanks a lot in advance for your help. 
 

Labels (2)
Tags (1)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hi! It looks like there's an authentication failure on the Azure side. You need to assign the correct permissions to the Azure app.

Before proceeding on configuring https://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/ConfigureappinAzureAD

ensure your storage account token (SAS) has the following privileges:

Use either Access key OR Shared Access Signature with:

  • Allowed services: Blob, Table
  • Allowed resource types: Service, Container, Object
  • Allowed permissions: Read, List



Please UpVote if this is helpful.

 
 
If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...