Skip to main content
Oracle Cloud Infrastructure Add-on for Splunk app icon

Oracle Cloud Infrastructure Add-on for Splunk

The Oracle Cloud Infrastructure Add-on for Splunk collects and normalizes logs from Oracle Cloud Infrastructure environments using a pull-based OCI Streaming API method. The add-on ingests OCI Audit logs, VCN Flow Logs, Cloud Guard problems, Load Balancer access logs, and Object Storage events, mapping them to the Common Information Model (CIM) Change, Network Traffic, and Alerts data models. It provides field extractions and event normalization for six distinct source types, enabling visibility into authentication activity, network traffic patterns, security findings, and infrastructure changes across an OCI tenancy.Built by WAN MUHAMMAD HELMI BIN WAN ISMAIL
splunk product badge

Default Version 1.0.0

August 29, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4

CIM Version: 8.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Oracle Cloud Infrastructure Add-on for Splunk collects and normalizes logs from Oracle Cloud Infrastructure environments using a pull-based OCI Streaming API method. The add-on ingests OCI Audit logs, VCN Flow Logs, Cloud Guard problems, Load Balancer access logs, and Object Storage events, mapping them to the Common Information Model (CIM) Change, Network Traffic, and Alerts data models. It provides field extractions and event normalization for six distinct source types, enabling visibility into authentication activity, network traffic patterns, security findings, and infrastructure changes across an OCI tenancy.