Good afternoon, Ma'am/Sir,
I am trying to figure if I could leverage Splunk to automate audit of admin-level logs in Oracle. How can I do that?
If you haven't already figured it out by now, there's a paper available for download here: http://apps.splunk.com/app/1538/ that lays it all out, step by step. It also details a lot of other ways to get data from Oracle and its log files into Splunk.
It should be pretty straightforward. If you write the Oracle Audit logs to OS files, it's quite easy to bring them into Splunk. From there, you can use normal Splunk log search, alerting, reporting, and other functionality on them.