Skip to main content
Question

Chronicle API Integration issue

  • March 9, 2026
  • 1 reply
  • 40 views

soargeekexplorer
Forum|alt.badge.img+1

I am using workload identity for Chronicle api integration, I am getting error” unable to acquire impersonated credentials” . I think the issue is in adding the Principal. I am not sure what Principal needs to be added and how I can find it from scratch. I am not getting the principal in the error log also while testing the instance. Please help me with the steps how and which principal I can use and resolve the issue.

Thanks in advance :)

1 reply

D1dave
  • New Member
  • March 12, 2026

I am using workload identity for Chronicle api integration, I am getting error” unable to acquire impersonated credentials” . I think the issue is in adding the Principal. I am not sure what Principal needs to be added and how I can find it from scratch. I am not getting the principal in the error log also while testing the instance. Please help me with the steps how and which principal I can use and resolve the issue.

Thanks in advance :)

Hi need more information but a couple of questions:

  1. Did you set up a workload identity pool?
  2. Where is the Workload  is running , workloads different format for principles.
  3. Did you create a service account to use for impersonation.
  4.  If yes, did you give the service account this role -  roles/iam.serviceAccountTokenCreator
  5. If yes, did you bind the service account to the workload principle.