Getting Data In

Getting OCI Audit Logs into Splunk

adnankhan5133
Communicator

Hello,

Our infrastructure is currently hosted on Oracle Government Cloud and we are trying to determine a way to get the OCI Audit Logs sent to our Splunk instance. Given that OCI GovCloud has a limited number of services, we can not leverage the Service Connector Hub to send the OCI Audit Logs to an OCI Streaming Service or to Object Storage. Both Streaming Service and Object Storage would have been quick wins for us because Splunk has add-ons (https://splunkbase.splunk.com/app/4616/, https://splunkbase.splunk.com/app/5222/) with built-in Audit Log sourcetyping that can facilitate the ingestion of the OCI Audit Logs from these locations.

The other option is to leverage our Splunk HF to leverage the REST API input to directly query the OCI Audit Log Service to get the logs. There is a TA (https://splunkbase.splunk.com/app/1546/) that can assist with this, so I believe this is probably the best approach.

Does anyone have any other suggestions on how we can proceed with this? The goal is to get the OCI Audit logs sent to Splunk. The limitation is that we're using OCI GovCloud (US), which does not provide a key service that could have simplified our approach to routing the audit logs to Splunk.

Labels (3)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...