↳ Source GitHubConnecteur
Oracle Cloud Infrastructure (via Codeless Connector Framework)
Description
The Oracle Cloud Infrastructure (OCI) data connector provides the capability to ingest OCI Logs from [OCI Stream](https://docs.oracle.com/iaas/Content/Streaming/Concepts/streamingoverview.htm) into Microsoft Sentinel using the [OCI Streaming REST API](https://docs.oracle.com/iaas/api/#/streaming/streaming/20180418).
- Statut déclaré
- 1
- Auteur / éditeur déclaré
- Microsoft
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Types de données
Permissions déclarées
Read and Write permissions are required.
Workspace
Workspace
OCI Streaming API access
Access to the OCI Streaming API through a API Signing Keys is required.
OCI IAM Policy
The OCI user associated with the API signing key must have sufficient IAM permissions to consume data from the OCI Stream. The API key provides authentication only; an IAM policy is required for authorization. At minimum, configure: Allow group <group-name> to use stream-pull in compartment <compartment-name>.
Instructions du connecteur
Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.
Connect to OCI Streaming API to start collecting Event logs in Microsoft Sentinel
1) Log in to the OCI console and access the navigation menu.
2) In the navigation menu, go to "Analytics & AI" -> "Streaming".
3) Click "Create Stream".
4) Select an existing "Stream Pool" or create a new one.
5) Enter the following details:
- "Stream Name"
- "Retention"
- "Number of Partitions"
- "Total Write Rate"
- "Total Read Rate" (based on your data volume)
6) In the navigation menu, go to "Logging" -> "Service Connectors".
7) Click "Create Service Connector".
8) Enter the following details:
- "Connector Name"
- "Description"
- "Resource Compartment"
9) Select the "Source": "Logging".
10) Select the "Target": "Streaming".
11) (Optional) Configure "Log Group", "Filters", or use a "custom search query" to stream only the required logs.
12) Configure the "Target" by selecting the previously created stream.
13) Click "Create".
14) Follow the documentation to create a [Private Key and API Key Configuration File](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/apisigningkey.htm). Save the Pem File, pass phrase (Optional, it is not set when using the OCI console to generate the API signing key pair) and fingerprint in a secured place for use when connect.
Add stream
Add Oracle Cloud Infrastructure Data Stream
Open Analytics & AI -> Streaming -> choose your stream -> copy the OCID from the Stream Details page.
Stream OCID
Open Analytics & AI -> Streaming -> choose your stream -> copy the Message Endpoint from the Stream Details page.
Public Message Endpoint of the stream (Service Endpoint Base URL)
Cursor Type
Individual Cursor
Group Cursor (preview)
Partition Id / Group name : The partition ID uses zero-based indexing. For example, if a stream has 3 partitions, the valid partition IDs are 0, 1, or 2.
Group cursors allow you to read from all partitions simultaneously. When using a group cursor (preview), provide the group name (can be any string) instead of individual partition IDs. (the group will be created automatically by the platform when you start reading).
Partition Id / Group name
Open Governance & Administration -> Account Management -> Tenancy Details -> copy the Tenancy OCID from the Tenancy details page.
Tenant ID
Open Identity & Security -> Identity -> Domains -> My profile -> copy the User OCID from the Details panel of My Profile page.
User ID
Pem File Content
Fingerprint
If your PEM file is not encrypted, leave Pass Phrase as blank.
Pem File Pass Phrase (Optional)
Contenus associés
Liens établis à partir des identifiants déclarés et des manifests des solutions.
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
9800e51↗- Identifiant source
OracleCloudInfraConnector
GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC