Getting Data In

Getting OCI Audit Logs into Splunk

adnankhan5133
Communicator

Hello,

Our infrastructure is currently hosted on Oracle Government Cloud and we are trying to determine a way to get the OCI Audit Logs sent to our Splunk instance. Given that OCI GovCloud has a limited number of services, we can not leverage the Service Connector Hub to send the OCI Audit Logs to an OCI Streaming Service or to Object Storage. Both Streaming Service and Object Storage would have been quick wins for us because Splunk has add-ons (https://splunkbase.splunk.com/app/4616/, https://splunkbase.splunk.com/app/5222/) with built-in Audit Log sourcetyping that can facilitate the ingestion of the OCI Audit Logs from these locations.

The other option is to leverage our Splunk HF to leverage the REST API input to directly query the OCI Audit Log Service to get the logs. There is a TA (https://splunkbase.splunk.com/app/1546/) that can assist with this, so I believe this is probably the best approach.

Does anyone have any other suggestions on how we can proceed with this? The goal is to get the OCI Audit logs sent to Splunk. The limitation is that we're using OCI GovCloud (US), which does not provide a key service that could have simplified our approach to routing the audit logs to Splunk.

Labels (3)
Get Updates on the Splunk Community!

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...