↳ GitHub sourceConnector

Oracle Cloud Infrastructure (via CCP) – Preview

Description

The Oracle Cloud Infrastructure (OCI) data connector provides the capability to ingest OCI Logs from [OCI Stream](https://docs.oracle.com/iaas/Content/Streaming/Concepts/streamingoverview.htm) into Microsoft Sentinel using the [OCI Streaming REST API](https://docs.oracle.com/iaas/api/#/streaming/streaming/20180418).
Declared author / publisher
Microsoft

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
OCI Streaming API access
Access to the OCI Streaming API through a API Signing Keys is required.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Connect to OCI Streaming API to start collecting Event logs in Microsoft Sentinel
1) Log in to the OCI console and access the navigation menu. 2) In the navigation menu, go to "Analytics & AI" → "Streaming". 3) Click "Create Stream". 4) Select an existing "Stream Pool" or create a new one. 5) Enter the following details: - "Stream Name" - "Retention" - "Number of Partitions" - "Total Write Rate" - "Total Read Rate" (based on your data volume) 6) In the navigation menu, go to "Logging" → "Service Connectors". 7) Click "Create Service Connector". 8) Enter the following details: - "Connector Name" - "Description" - "Resource Compartment" 9) Select the "Source": "Logging". 10) Select the "Target": "Streaming". 11) (Optional) Configure "Log Group", "Filters", or use a "custom search query" to stream only the required logs. 12) Configure the "Target" by selecting the previously created stream. 13) Click "Create". 14) Follow the documentation to create a [Private Key and API Key Configuration File](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/apisigningkey.htm).
Stream OCID
Service Endpoint Base URL
Cursor Type
Individual Cursor
Partition Id
Tenant ID
User ID
Pem File Content
Pass Phrase
Fingerprint

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
OCI-Connector-CCP-Definition
Additional source files 1Solutions/Oracle Cloud Infrastructure/Data Connectors/Oracle_Cloud_Infrastructure_CCP/azuredeploy_OCI_DataConnector_poller_connector.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.