All Apps and Add-ons

Oracle XE 10.2 event logs do not match the current extract pattern

abarbieri
New Member

Hello Balazs,

I am trying to use your app to analyze syslog events generated by Oracle XE 10.2. I believe the extract pattern in props.conf seems not be able to cope (i.e. no results generated by a query index="oracleaudit" | top oracle_actionname) with payloads like the following two examples:


<134>Jan  5 14:37:57 localhost Oracle Audit[9261]: ACTION : 'ALTER DATABASE OPEN'#012DATABASE USER: '/'#012PRIVILEGE : SYSDBA#012CLIENT USER: oracle#012CLIENT TERMINAL: #012STATUS: 0

<134>Jan  5 14:37:49 localhost Oracle Audit[9255]: ACTION : 'SELECT DECODE(null,'','Total System Global Area','') NAME_COL_PLUS_SHOW_SGA,   SUM(VALUE), DECODE (null,'', 'bytes','') units_col_plus_show_sga FROM V$SGA    UNION ALL    SELECT NAME NAME_COL_PLUS_SHOW_SGA , VALUE,    DECODE (null,'', 'bytes','') units_col_plus_show_sga FROM V$SGA'#012DATABASE USER: '/'#012PRIVILEGE : SYSDBA#012CLIENT USER: oracle#012CLIENT TERMINAL: #012STATUS: 0

using the simple query index="oracleaudit" does return the expected events.

Any insight?

Thanks,
andrea

Tags (1)
0 Karma

bvamos
Explorer

This version of Oracle is not yet supported. I'll take a look at it and put it on my roadmap...

0 Karma

abarbieri
New Member

I just realised I should have used 'Review' rather than 'Ask a Question' for the Oracle Audit Trail app.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...