Getting Data In

Getting OCI Audit Logs into Splunk

adnankhan5133
Communicator

Hello,

Our infrastructure is currently hosted on Oracle Government Cloud and we are trying to determine a way to get the OCI Audit Logs sent to our Splunk instance. Given that OCI GovCloud has a limited number of services, we can not leverage the Service Connector Hub to send the OCI Audit Logs to an OCI Streaming Service or to Object Storage. Both Streaming Service and Object Storage would have been quick wins for us because Splunk has add-ons (https://splunkbase.splunk.com/app/4616/, https://splunkbase.splunk.com/app/5222/) with built-in Audit Log sourcetyping that can facilitate the ingestion of the OCI Audit Logs from these locations.

The other option is to leverage our Splunk HF to leverage the REST API input to directly query the OCI Audit Log Service to get the logs. There is a TA (https://splunkbase.splunk.com/app/1546/) that can assist with this, so I believe this is probably the best approach.

Does anyone have any other suggestions on how we can proceed with this? The goal is to get the OCI Audit logs sent to Splunk. The limitation is that we're using OCI GovCloud (US), which does not provide a key service that could have simplified our approach to routing the audit logs to Splunk.

Labels (3)
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...