Share via

Is there any oracle logs parser for azure sentinel we are not using oracle unified agent

Kumar, Deepak 16 Reputation points
2024-04-24T15:01:07.1466667+00:00

Is there any oracle logs parser for azure sentinel we are not using oracle unified agent

Microsoft Security | Microsoft Sentinel

1 answer

Sort by: Most helpful
  1. Clive Watson 7,951 Reputation points MVP Volunteer Moderator
    2024-04-24T16:36:44.8833333+00:00

    Hi, you can use the parsers that Oracle supply as a guide, however you'll have to adapt them to support your ingestion product and the schema it ingests. You may want to look at the ASIM guides as well, especially the column naming conventions. https://learn.microsoft.com/EN-US/AZURE/sentinel/normalization-parsers-overview

    Sample Oracle parser: https://github.com/Azure/Azure-Sentinel/blob/606b995237604929b290b502bf7c21313cd0441c/Solutions/OracleWebLogicServer/Parsers/OracleWebLogicServerEvent.yaml

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.