All Apps and Add-ons

How can Oracle database activities be monitored by Splunk 4.1?

knight_rehan
Explorer

I am looking for a way to monitor oracle database activities using Splunk v4.1. Can I get some help in this regard?

Tags (2)

altink
Builder

If you are using Oracle Unified Audit (starting with Oracle 12c R1), you can use the following

Oracle Unified Audit App for Splunk

https://splunkbase.splunk.com/app/6172/ 

best regards
Altin

0 Karma

pmdba
Builder

Hi. There is are examples of Oracle activity monitoring in the white paper "Real-Time Oracle 11g Log File Analysis" available at http://pmdba.files.wordpress.com/2013/05/real-time-oracle-11g-log-file-analysis.pdf. Hopefully this will help; I think it is a little more specific "how to" than the Splunk documentation. A lot of different data input methods are described, including log files, TCP, and Splunk DB Connect, as well as lookup tables, sample searches and reports, and dashboards.

0 Karma

bvamos
Explorer

I have uploaded a new App (Splunk for Oracle Audit Trails) what can parse and analyze Oracle Audit Trails sent via syslog. It is not yet visible on SplunkBase but I hope it will be available soon.

0 Karma

bvamos
Explorer

Splunk for Oracle Audit Trails is available for download from: http://splunk-base.splunk.com/apps/36943/oracle-audit-trail

0 Karma

knight_rehan
Explorer

Thanks for the reply Christian 😃 I'm actually looking for a way to audit the database activities e.g. what queries are performed on a specific table(s). I'm not interested in the content of the table.

0 Karma

simuvid
Splunk Employee
Splunk Employee

What do you mean by activities? Events that are listed in the Oracle DB Manager?

As far as I am aware the Oracle DB Manager stores information's in a file, something like a logfile. This directory or file can be included as a data input.

Or just plain DB content?

If you like to read out informations from within a DB direct this App might be a help:

http://www.splunkbase.com/apps/All/4.x/Add-On/app:Example+lookup+using+a+Database

Hope that helps.

Cheers,

Christian

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...