bpirone You may want to check the permissions of your application to make sure it has proper authorization. Are you using App-Only or UserDelegated API permissions?
In either permissions case, Application or Delegated Permissions, you need to have at least the Security Event Read permissions granted by the tenant admin. In the case of Delegated Permissions, besides the mentioned permissions, the user needs to be assigned as “Security Reader” by the tenant admin to be able to read the alerts.
For more details, please refer to step 9-12 of the add-on https://splunkbase.splunk.com/app/4564/#/details.
If permissions look good, then please check to see if you have any filters set up in your Inputs. Please send a screenshot of your Splunk log with error details if possible.