All Apps and Add-ons

How to integrate Oracle Secure Global Desktop (SGD) logs in Splunk and make them CIM compatible?

pinVie
Path Finder

Hi all,

Has any one of you integrated logs from Oracle SGD?

Actual integration is easily done via Syslog, but making sense of all these logs is really hard.
I'm currently trying to make these logs CIM compatible, but I don't really know how to do this without proper documentation - and afaik there is no documentation regarding the logs.

Have you already done this, is there a Splunk app, do you know of any documentation? - all information is helpful.

Thank you !

chris
Motivator

Hi pinVie did you manage to integrate those logs? Any chance of sharing what logs you integrated? Regards Chris

0 Karma

tmuth_splunk
Splunk Employee
Splunk Employee

I used to work at Oracle and spent a LOT of time as a user of SGD, though I know little about the admin side. However, here are some doc links to get you started if you haven't already found them:

Global Table of Contents for 5.2: http://docs.oracle.com/cd/E51728_01/index.html
Monitoring and Logging Section: http://docs.oracle.com/cd/E51728_01/E51731/html/monitoring-logging.html
Gateway Logging and Diagnostics: http://docs.oracle.com/cd/E51728_01/E51733/html/gateway-logging-diagnostics.html
Enterprise Manager Plugin (might give you an idea what to monitor): http://docs.oracle.com/cd/E51728_01/E52284/html/plugin-monitoring.html
EM Plugin > Metrics Definitions: http://docs.oracle.com/cd/E51728_01/E52284/html/plugin-metrics-ref.html
Web Service API > Datastore > Item Constants (might define some ambiguous items): http://docs.oracle.com/cd/E51728_01/E51735/html/constant-values.html#com.tarantella.tta.webservices....

Wish I had an "easy-button" for you, but hopefully this will move you one step closer.

woodcock
Esteemed Legend
0 Karma

pinVie
Path Finder

Yes I do know splunkbase - thank you.
But if I am not wrong there is no app for Oracle SGD on splunkbase, right?

0 Karma

woodcock
Esteemed Legend

Not under "SGD" and when I typed in the whole phrase, I got tired of clicking after 5 pages. You should be more motivated than I am, though, to click all the way through.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...