You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python读取Azure Log Analytics遇InsufficientAccessError问题求助

问题:Python读取Azure Log Analytics日志遇权限不足错误

我尝试用Python读取Azure Log Analytics日志,代码如下:

AZURE_CLIENT_ID = ''
AZURE_CLIENT_SECRET = ''
AZURE_TENANT_ID = ''
workspace_id = ''
from azure.identity import ClientSecretCredential
from datetime import datetime
from azure.monitor.query import LogsQueryClient, LogsQueryStatus


start_time = datetime(2022, 1, 1)
end_time = datetime(2023, 1, 2)
credential  = ClientSecretCredential(
        client_id = AZURE_CLIENT_ID,
        client_secret = AZURE_CLIENT_SECRET,
        tenant_id = AZURE_TENANT_ID
    )

client = LogsQueryClient(credential)
query = "ContainerLog"

response = client.query_workspace(workspace_id=workspace_id,
                                  query=query, timespan=(start_time, end_time - start_time))

if response.status == LogsQueryStatus.PARTIAL:
    error = response.partial_error
    print('Results are partial', error.message)

elif response.status == LogsQueryStatus.SUCCESS:
    results = []
    for table in response.tables:
        for row in table.rows:
            results.append(dict(zip(table.columns, row)))
    print(convert_azure_table_to_dict(results))

执行后报错:

Traceback (most recent call last):
  File "c:\temp\x.py", line 24, in <module>
    response = client.query_workspace(workspace_id=workspace_id,
  File "C:\kourosh\venv\lib\site-packages\azure\core\tracing\decorator.py", line 78, in wrapper_use_tracer
    return func(*args, **kwargs)
  File "C:\kourosh\venv\lib\site-packages\azure\monitor\query\_logs_query_client.py", line 136, in query_workspace
    process_error(err, LogsQueryError)
  File "C:\kourosh\venv\lib\site-packages\azure\monitor\query\_helpers.py", line 141, in process_error
    raise HttpResponseError(message=error.message, response=error.response, model=model)
azure.core.exceptions.HttpResponseError: (InsufficientAccessError) The provided credentials have insufficient access to perform the requested operation
Code: InsufficientAccessError
Message: The provided credentials have insufficient access to perform the requested operation

我已为注册应用添加Log Analytics API -> Data.Read权限,请问错误原因是什么?

排查方向及解决方案
  • 管理员同意未授予:添加API权限后,必须点击授予管理员同意按钮,权限才会生效。前往Azure AD应用注册的“API权限”页面,确认该权限已获得租户管理员的同意。
  • 缺少工作空间IAM角色:仅API权限不够,还需给服务主体分配Log Analytics工作空间的读取者或Log Analytics Contributor角色。操作路径:Log Analytics工作空间 -> 访问控制(IAM) -> 添加角色分配 -> 选择对应角色 -> 选中你的服务主体 -> 完成分配。
  • 权限类型错误:确保添加的Data.Read是应用权限,而非委托权限。因为ClientSecretCredential属于服务主体认证,只能使用应用权限类型。
  • 工作空间ID有误:核对代码中workspace_id是否与目标Log Analytics工作空间的ID完全一致,避免输入错误。
  • 权限缓存延迟:刚修改权限后可能存在缓存,等待5-10分钟再重新运行代码,或重启本地环境清除缓存。

内容的提问来源于stack exchange,提问作者max

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 08:45:20