↳ Source GitHubConnecteur

Oracle Cloud Infrastructure (via Codeless Connector Framework)

Description

The Oracle Cloud Infrastructure (OCI) data connector provides the capability to ingest OCI Logs from [OCI Stream](https://docs.oracle.com/iaas/Content/Streaming/Concepts/streamingoverview.htm) into Microsoft Sentinel using the [OCI Streaming REST API](https://docs.oracle.com/iaas/api/#/streaming/streaming/20180418).
Statut déclaré
1
Auteur / éditeur déclaré
Microsoft

Sources déclarées

Métadonnées du fichier source. Aucune dépendance déduite du KQL.

Types de données

Permissions déclarées

Read and Write permissions are required.
Workspace
Workspace
OCI Streaming API access
Access to the OCI Streaming API through a API Signing Keys is required.
OCI IAM Policy
The OCI user associated with the API signing key must have sufficient IAM permissions to consume data from the OCI Stream. The API key provides authentication only; an IAM policy is required for authorization. At minimum, configure: Allow group <group-name> to use stream-pull in compartment <compartment-name>.

Instructions du connecteur

Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.

Connect to OCI Streaming API to start collecting Event logs in Microsoft Sentinel
1) Log in to the OCI console and access the navigation menu. 2) In the navigation menu, go to "Analytics & AI" -> "Streaming". 3) Click "Create Stream". 4) Select an existing "Stream Pool" or create a new one. 5) Enter the following details: - "Stream Name" - "Retention" - "Number of Partitions" - "Total Write Rate" - "Total Read Rate" (based on your data volume) 6) In the navigation menu, go to "Logging" -> "Service Connectors". 7) Click "Create Service Connector". 8) Enter the following details: - "Connector Name" - "Description" - "Resource Compartment" 9) Select the "Source": "Logging". 10) Select the "Target": "Streaming". 11) (Optional) Configure "Log Group", "Filters", or use a "custom search query" to stream only the required logs. 12) Configure the "Target" by selecting the previously created stream. 13) Click "Create". 14) Follow the documentation to create a [Private Key and API Key Configuration File](https://docs.oracle.com/en-us/iaas/Content/API/Concepts/apisigningkey.htm). Save the Pem File, pass phrase (Optional, it is not set when using the OCI console to generate the API signing key pair) and fingerprint in a secured place for use when connect.
Add stream
Add Oracle Cloud Infrastructure Data Stream
Open Analytics & AI -> Streaming -> choose your stream -> copy the OCID from the Stream Details page.
Stream OCID
Open Analytics & AI -> Streaming -> choose your stream -> copy the Message Endpoint from the Stream Details page.
Public Message Endpoint of the stream (Service Endpoint Base URL)
Cursor Type
Individual Cursor
Group Cursor (preview)
Partition Id / Group name : The partition ID uses zero-based indexing. For example, if a stream has 3 partitions, the valid partition IDs are 0, 1, or 2. Group cursors allow you to read from all partitions simultaneously. When using a group cursor (preview), provide the group name (can be any string) instead of individual partition IDs. (the group will be created automatically by the platform when you start reading).
Partition Id / Group name
Open Governance & Administration -> Account Management -> Tenancy Details -> copy the Tenancy OCID from the Tenancy details page.
Tenant ID
Open Identity & Security -> Identity -> Domains -> My profile -> copy the User OCID from the Details panel of My Profile page.
User ID
Pem File Content
Fingerprint
If your PEM file is not encrypted, leave Pass Phrase as blank.
Pem File Pass Phrase (Optional)

Contenus associés

Liens établis à partir des identifiants déclarés et des manifests des solutions.

Traçabilité de la source

GitHub

Les valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.

Identifiant source
OracleCloudInfraConnector
Autres fichiers source 2Solutions/Oracle Cloud Infrastructure/Data Connectors/Oracle_Cloud_Infrastructure_CCP/OCI_DataConnector_DataConnectorDefinition.jsonsource ↗Solutions/Oracle Cloud Infrastructure/Data/Solution_OCILogs.jsonsolution-membership ↗
GSTEP / SUIVI DU CATALOGUE

Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC

Dates de synchronisation GSTEP, distinctes des dates de publication du contenu source.