Getting Data In

Getting OCI Audit Logs into Splunk

adnankhan5133
Communicator

Hello,

Our infrastructure is currently hosted on Oracle Government Cloud and we are trying to determine a way to get the OCI Audit Logs sent to our Splunk instance. Given that OCI GovCloud has a limited number of services, we can not leverage the Service Connector Hub to send the OCI Audit Logs to an OCI Streaming Service or to Object Storage. Both Streaming Service and Object Storage would have been quick wins for us because Splunk has add-ons (https://splunkbase.splunk.com/app/4616/, https://splunkbase.splunk.com/app/5222/) with built-in Audit Log sourcetyping that can facilitate the ingestion of the OCI Audit Logs from these locations.

The other option is to leverage our Splunk HF to leverage the REST API input to directly query the OCI Audit Log Service to get the logs. There is a TA (https://splunkbase.splunk.com/app/1546/) that can assist with this, so I believe this is probably the best approach.

Does anyone have any other suggestions on how we can proceed with this? The goal is to get the OCI Audit logs sent to Splunk. The limitation is that we're using OCI GovCloud (US), which does not provide a key service that could have simplified our approach to routing the audit logs to Splunk.

Labels (3)
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...