All Apps and Add-ons

How to integrate Oracle Secure Global Desktop (SGD) logs in Splunk and make them CIM compatible?

pinVie
Path Finder

Hi all,

Has any one of you integrated logs from Oracle SGD?

Actual integration is easily done via Syslog, but making sense of all these logs is really hard.
I'm currently trying to make these logs CIM compatible, but I don't really know how to do this without proper documentation - and afaik there is no documentation regarding the logs.

Have you already done this, is there a Splunk app, do you know of any documentation? - all information is helpful.

Thank you !

chris
Motivator

Hi pinVie did you manage to integrate those logs? Any chance of sharing what logs you integrated? Regards Chris

0 Karma

tmuth_splunk
Splunk Employee
Splunk Employee

I used to work at Oracle and spent a LOT of time as a user of SGD, though I know little about the admin side. However, here are some doc links to get you started if you haven't already found them:

Global Table of Contents for 5.2: http://docs.oracle.com/cd/E51728_01/index.html
Monitoring and Logging Section: http://docs.oracle.com/cd/E51728_01/E51731/html/monitoring-logging.html
Gateway Logging and Diagnostics: http://docs.oracle.com/cd/E51728_01/E51733/html/gateway-logging-diagnostics.html
Enterprise Manager Plugin (might give you an idea what to monitor): http://docs.oracle.com/cd/E51728_01/E52284/html/plugin-monitoring.html
EM Plugin > Metrics Definitions: http://docs.oracle.com/cd/E51728_01/E52284/html/plugin-metrics-ref.html
Web Service API > Datastore > Item Constants (might define some ambiguous items): http://docs.oracle.com/cd/E51728_01/E51735/html/constant-values.html#com.tarantella.tta.webservices....

Wish I had an "easy-button" for you, but hopefully this will move you one step closer.

woodcock
Esteemed Legend
0 Karma

pinVie
Path Finder

Yes I do know splunkbase - thank you.
But if I am not wrong there is no app for Oracle SGD on splunkbase, right?

0 Karma

woodcock
Esteemed Legend

Not under "SGD" and when I typed in the whole phrase, I got tired of clicking after 5 pages. You should be more motivated than I am, though, to click all the way through.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...