Using Oracle Cloud Infrastructure with Microsoft Sentinel

Stephen Keating 20 Reputation points
2023-09-28T13:24:52.08+00:00

I am currently using the trial version of Microsoft Sentinel. I have created in OCI the necessary structure to collect logs from several Microsoft VMs I have in the Oracle Cloud, and would like to send these to Microsoft Sentinel. When I go into Content Hub in Microsoft Sentinel, I notice there is no connector for Oracle Cloud Infrastructure, even though this appears in a video I have seen on the subject. Is there any way to get this in the trial version, or is the connector only available in the paid for version of Sentinel? Also, is there any documentation for setting up a connection between Sentinel and OCI for the purpose of collecting logs?

Thanks

Stephen Keating

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,785 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Givary-MSFT 35,476 Reputation points Microsoft Employee
    2023-09-29T06:09:53.2166667+00:00

    @Stephen Keating Thank you for reaching out to us, As I understand you are looking for documentation to setup OCI (Oracle Cloud Infrastructure) with Microsoft Sentinel.

    You can refer to these links, detailed steps have been provided here -

    https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/oracle-cloud-infrastructure-using-azure-functions

    https://docs.oracle.com/en/learn/oci-logs-ms-azure-sentinel/index.html#introduction

    Not sure why you are not able to see OCI under Content hub, just like below, Billing is based on the volume of data analyzed in Microsoft Sentinel and stored in the Log Analytics workspace.

    User's image

    Let me know if the above links help you in configuring the OCI with Sentinel, if not we can connect offline to discuss further on the same.


  2. gba 0 Reputation points
    2024-09-10T01:42:10.98+00:00

    Is there a data connector to ingest cloud events ( https://github.com/cloudevents/spec) data into sentinel ? I am trying to pull events from Oracle cloud events data via a OCI streamingend point.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.