Forum Discussion

krobson's avatar
krobson
Copper Contributor
Mar 02, 2022

GCP IAM Connector

Hi,

I've been trying to use the GCP IAM connector in Sentinel.  I have enabled the cloud logging api, enabled the audit logs, created a service account, with the following roles -
Cloud API Gateway Management Service Agent
Cloud API Gateway Service Agent
Logging Admin
Monitoring Alert Policy Editor
Monitoring Services Editor
Private Logs Viewer.

 

Created  a key and downloaded the json.  Installed the  the GCPIAM function with the required parameters but get a 403 error. 

Exception while executing function: Functions.AzureFunctionGCPIAM ---> Microsoft.Azure.WebJobs.Script.Workers.Rpc.RpcException : Result: Failure Exception: Forbidden: 403 POST https://logging.googleapis.com/v2/entries:list?prettyPrint=false: The caller does not have permission

 Has anyone else had this issue?

Resources