All Apps and Add-ons

How can Oracle database activities be monitored by Splunk 4.1?

knight_rehan
Explorer

I am looking for a way to monitor oracle database activities using Splunk v4.1. Can I get some help in this regard?

Tags (2)

altink
Builder

If you are using Oracle Unified Audit (starting with Oracle 12c R1), you can use the following

Oracle Unified Audit App for Splunk

https://splunkbase.splunk.com/app/6172/ 

best regards
Altin

0 Karma

pmdba
Builder

Hi. There is are examples of Oracle activity monitoring in the white paper "Real-Time Oracle 11g Log File Analysis" available at http://pmdba.files.wordpress.com/2013/05/real-time-oracle-11g-log-file-analysis.pdf. Hopefully this will help; I think it is a little more specific "how to" than the Splunk documentation. A lot of different data input methods are described, including log files, TCP, and Splunk DB Connect, as well as lookup tables, sample searches and reports, and dashboards.

0 Karma

bvamos
Explorer

I have uploaded a new App (Splunk for Oracle Audit Trails) what can parse and analyze Oracle Audit Trails sent via syslog. It is not yet visible on SplunkBase but I hope it will be available soon.

0 Karma

bvamos
Explorer

Splunk for Oracle Audit Trails is available for download from: http://splunk-base.splunk.com/apps/36943/oracle-audit-trail

0 Karma

knight_rehan
Explorer

Thanks for the reply Christian 😃 I'm actually looking for a way to audit the database activities e.g. what queries are performed on a specific table(s). I'm not interested in the content of the table.

0 Karma

simuvid
Splunk Employee
Splunk Employee

What do you mean by activities? Events that are listed in the Oracle DB Manager?

As far as I am aware the Oracle DB Manager stores information's in a file, something like a logfile. This directory or file can be included as a data input.

Or just plain DB content?

If you like to read out informations from within a DB direct this App might be a help:

http://www.splunkbase.com/apps/All/4.x/Add-On/app:Example+lookup+using+a+Database

Hope that helps.

Cheers,

Christian

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...