All Apps and Add-ons

Splunk Add-on for Microsoft Cloud Services: No permission to fetch Azure AD Audit data.

kmanson
Path Finder
No permission to fetch Azure AD Audit data. There might be some delay after changing the application permissions.
No permission to fetch Sharepoint Online Audit data. There might be some delay after changing the application permissions.
No permission to fetch Exchange Online Audit data. There might be some delay after changing the application permissions.

And yes, we have verified that the permissions below exist. Service Status and Operational Messages work, just not the rest. Any ideas?

http://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/ConfigureappinAzureAD#Create_an...

1 Solution

kmanson
Path Finder

Going to answer my own question since we got it working. I think it was because the permissions were granted after adding the account to Splunk.
Fixed by:
Removed Inputs config
Removed account config
Added account config
Added inputs config
Kept the certificate configuration as-is.

View solution in original post

kmanson
Path Finder

Going to answer my own question since we got it working. I think it was because the permissions were granted after adding the account to Splunk.
Fixed by:
Removed Inputs config
Removed account config
Added account config
Added inputs config
Kept the certificate configuration as-is.

andrewgarvin
New Member

Thank you!!! Removing and re-adding the account resolved this for me.

0 Karma

suarezry
Builder

This answer didn't work for me initially. After giving up in frustration I tried it again the next day for kicks and giggles...and it worked!!!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...