↳ GitHub sourceConnector
Oracle Cloud Infrastructure (via CCP) – Preview
Description
The Oracle Cloud Infrastructure (OCI) data connector provides the capability to ingest OCI Logs from [OCI Stream](https://docs.oracle.com/iaas/Content/Streaming/Concepts/streamingoverview.htm) into Microsoft Sentinel using the [OCI Streaming REST API](https://docs.oracle.com/iaas/api/#/streaming/streaming/20180418).
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
OCI Streaming API access
Access to the OCI Streaming API through a API Signing Keys is required.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Connect to OCI Streaming API to start collecting Event logs in Microsoft Sentinel
1) Log in to the OCI console and access the navigation menu.
2) In the navigation menu, go to "Analytics & AI" → "Streaming".
3) Click "Create Stream".
4) Select an existing "Stream Pool" or create a new one.
5) Enter the following details:
- "Stream Name"
- "Retention"
- "Number of Partitions"
- "Total Write Rate"
- "Total Read Rate" (based on your data volume)
6) In the navigation menu, go to "Logging" → "Service Connectors".
7) Click "Create Service Connector".
8) Enter the following details:
- "Connector Name"
- "Description"
- "Resource Compartment"
9) Select the "Source": "Logging".
10) Select the "Target": "Streaming".
11) (Optional) Configure "Log Group", "Filters", or use a "custom search query" to stream only the required logs.
12) Configure the "Target" by selecting the previously created stream.
13) Click "Create".
14) Follow the documentation to create a [Private Key and API Key Configuration File](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/apisigningkey.htm).
Stream OCID
Service Endpoint Base URL
Cursor Type
Individual Cursor
Partition Id
Tenant ID
User ID
Pem File Content
Pass Phrase
Fingerprint
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
OCI-Connector-CCP-Definition
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC