Splunk was unable to pull logs from Azure after the secret expired. After replacing the secret value, we are met with the error Unable to obtain access token in the audit logs.
1) Why do we have this error?
2) Do we need to resetup the whole azure app + inputs when the secret expires?
Splunk was unable to pull logs from Azure after the secret expired. After replacing the secret value, we are met with the error Unable to obtain access token in the audit logs.
1) Why do we have this error? 2) Do we need to resetup the whole azure app + inputs when the secret expires?