{"id":30179,"date":"2024-01-25T17:01:01","date_gmt":"2024-01-25T16:01:01","guid":{"rendered":"https:\/\/www.dbi-services.com\/blog\/?p=30179"},"modified":"2024-09-10T15:38:44","modified_gmt":"2024-09-10T13:38:44","slug":"sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams","status":"publish","type":"post","link":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/","title":{"rendered":"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams"},"content":{"rendered":"\n<p>I recently deployed a new logging solution at a customer for their OCI tenancy. They wanted to manage their audit logs using Microsoft Azure Sentinel. The solution I deployed is using OCI Streaming Service to gather all the logs and create an endpoint. Microsoft Sentinel will then connect to the endpoint to collect the logs. Let me share with you how to set it up. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-oci-streaming-service-setup\">OCI Streaming service setup<\/h2>\n\n\n\n<p>First of all, you will need an OCI API Key to perform the connection between Azure and OCI. It&#8217;s the first thing you should create when you want to implement this solution.<\/p>\n\n\n\n<p>Once your API Key is created you can create your streams. To completely setup the streams in OCI you will have to create three components : an OCI Stream Pool, an OCI Stream and an OCI Connector.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-oci-stream-pool-creation\">OCI Stream Pool creation<\/h2>\n\n\n\n<p>A stream can not exist without a Stream Pool, so the first step is to create one. Stream Pools are basically streams containers. As you will see in the screenshot below, our three components can be created from the same service page, just search for &#8220;Streaming&#8221; in your OCI search bar.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"459\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png\" alt=\"\" class=\"wp-image-30180\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-300x135.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-768x345.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1536x689.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image.png 1917w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"463\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1-1024x463.png\" alt=\"\" class=\"wp-image-30181\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1-1024x463.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1-300x136.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1-768x347.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1-1536x694.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1.png 1918w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>You can keep the defaults values here and then jump to creating the Streams. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"459\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-2-1024x459.png\" alt=\"\" class=\"wp-image-30182\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-2-1024x459.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-2-300x135.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-2-768x344.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-2-1536x689.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-2.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>When creating the stream, be sure to select the Stream Pool you created just before. You can also modify the stream settings as you want but for this example we will keep the default values. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-oci-connector-creation\">OCI Connector creation<\/h2>\n\n\n\n<p>We can finally create the connector, this is used to transfer the logs from OCI logging service (OCI Logs) to our Stream. <\/p>\n\n\n\n<p>Make sure that you select &#8220;Logging&#8221; as the source and &#8220;Streaming&#8221; as the target for the connector.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"462\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-103800-1024x462.png\" alt=\"\" class=\"wp-image-30184\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-103800-1024x462.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-103800-300x135.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-103800-768x347.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-103800-1536x694.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-103800.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>As source we want to select our &#8220;Audit&#8221; log group.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"267\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-4-1024x267.png\" alt=\"\" class=\"wp-image-30185\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-4-1024x267.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-4-300x78.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-4-768x200.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-4-1536x401.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-4.png 1867w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>And as a target we want to select the stream we created earlier.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"259\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-5-1024x259.png\" alt=\"\" class=\"wp-image-30186\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-5-1024x259.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-5-300x76.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-5-768x195.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-5-1536x389.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-5.png 1867w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>When creating the connector, you will see a message asking you to create a policy. This policy should be enough to make the connector work but during my tests it was not. As a workaround I had to allow all the users to use the streaming-service at the tenancy level. <\/p>\n\n\n\n<p>You can enable logs in the connector to have a better view of what is happening for troubleshooting but it will require that you have created a Log group before.  As you create the connector you might notice as well a &#8220;Function&#8221; block. This is can be used if you can to filter your logs before sending the to the Stream. In our case we will not use a Function.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-microsoft-azure-sentinel-setup\">Microsoft Azure Sentinel setup<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-workspace-setup\">Workspace setup<\/h2>\n\n\n\n<p>Now that OCI is fully setup we can jump to setting up the Azure part of this solution. In your Azure tenant, navigate to Sentinel via the search bar and create a new Sentinel workspace.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"514\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-6-1024x514.png\" alt=\"\" class=\"wp-image-30189\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-6-1024x514.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-6-300x151.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-6-768x386.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-6-1536x771.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-6.png 1643w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>When clicking on Create Microsoft Sentinel, you will be prompted to choose a workspace. If you do not have one yet, create one. For this example I will use a newly created workspace.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"240\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-7-1024x240.png\" alt=\"\" class=\"wp-image-30190\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-7-1024x240.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-7-300x70.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-7-768x180.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-7-1536x360.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-7.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>When the workspace is linked to Sentinel, we can go on and continue the setup. In the Sentinel page, select &#8220;Content Hub&#8221;, then search for &#8220;oracle&#8221; and select &#8220;Oracle Cloud Infrastructure&#8221;. Click on install to get the Sentinel plugin for OCI. When the installation is done, click again on &#8220;Oracle Cloud Infrastructure&#8221; to access the plugin setup page. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"506\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-141206-1024x506.png\" alt=\"\" class=\"wp-image-30192\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-141206-1024x506.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-141206-300x148.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-141206-768x379.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-141206-1536x758.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/Screenshot-2024-01-15-141206.png 1663w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In the plugin setup, select &#8220;Oracle Cloud Infrastructure (using Azure Functions)&#8221; and click on &#8220;open connector page&#8221; <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"512\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-9-1024x512.png\" alt=\"\" class=\"wp-image-30194\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-9-1024x512.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-9-300x150.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-9-768x384.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-9-1536x768.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-9.png 1630w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-azure-connector-setup\">Azure Connector setup<\/h2>\n\n\n\n<p>In the connector page, scroll down until you reach the deployment options the select the &#8220;Option 1&#8221; Azure Resource Manager Template then click on &#8220;Deploy to Azure&#8221;. The Azure template used here will deploy components to make the connector work. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"509\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-10-1024x509.png\" alt=\"\" class=\"wp-image-30195\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-10-1024x509.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-10-300x149.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-10-768x382.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-10-1536x764.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-10.png 1632w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>In the template page, you have to fill in a few information to make it work. You can find the &#8220;Sentinel Workspace id&#8221; and &#8220;Sentinel Shared Key&#8221; variables in your Azure connector page. The &#8220;User&#8221;, &#8220;Key_Content&#8221;, &#8220;Pass_phrase&#8221;, &#8220;Fingerprint&#8221;, &#8220;Tenancy&#8221; and &#8220;Region&#8221; are all variables coming from the API Key file configured in OCI at the beginning, note that the &#8220;pass_phrase&#8221; is optional and that the &#8220;key_content&#8221; is the content of your private key file generated with the API Key. You can find the &#8220;Message_Enpoint&#8221; and &#8220;Stream_OCID&#8221; in your Stream page in OCI.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"726\" height=\"693\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-12.png\" alt=\"\" class=\"wp-image-30197\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-12.png 726w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-12-300x286.png 300w\" sizes=\"auto, (max-width: 726px) 100vw, 726px\" \/><\/figure>\n\n\n\n<p>Once you have setup all your variables, click on &#8220;review+create&#8221; and wait for the Azure Function to deploy the other components. You can check if the Function is running by looking at Azure functions in your Azure Tenant.<\/p>\n\n\n\n<p>Once the connector is installed you should see it going up in your Azure page and you should see logs coming in. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"502\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-15-1024x502.png\" alt=\"\" class=\"wp-image-30202\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-15-1024x502.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-15-300x147.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-15-768x377.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-15-1536x754.png 1536w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-15.png 1667w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>To see the logs in your Azure Sentinel, go back to the Sentinel page, click on logs, select the custom table &#8220;OCI_logs_CL&#8221; and run the query.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"592\" src=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-14-1024x592.png\" alt=\"\" class=\"wp-image-30199\" srcset=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-14-1024x592.png 1024w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-14-300x173.png 300w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-14-768x444.png 768w, https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-14.png 1397w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The configuration is done,  you can now use this table to query your logs. Microsoft Azure Sentinel uses Kusto Query Language, if you need an introduction to this language I recommend that you visit this <a href=\"https:\/\/www.dbi-services.com\/blog\/first-steps-on-kusto-query-language-kql\/\">blog<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently deployed a new logging solution at a customer for their OCI tenancy. They wanted to manage their audit logs using Microsoft Azure Sentinel. The solution I deployed is using OCI Streaming Service to gather all the logs and create an endpoint. Microsoft Sentinel will then connect to the endpoint to collect the logs. [&hellip;]<\/p>\n","protected":false},"author":90,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3271,955],"tags":[1338,1375],"type_dbi":[],"class_list":["post-30179","post","type-post","status-publish","format-standard","hentry","category-azure","category-cloud","tag-azure","tag-oci"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Sending OCI logs to Microsoft Azure Sentinel with OCI Streams - dbi Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams\" \/>\n<meta property=\"og:description\" content=\"I recently deployed a new logging solution at a customer for their OCI tenancy. They wanted to manage their audit logs using Microsoft Azure Sentinel. The solution I deployed is using OCI Streaming Service to gather all the logs and create an endpoint. Microsoft Sentinel will then connect to the endpoint to collect the logs. [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/\" \/>\n<meta property=\"og:site_name\" content=\"dbi Blog\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-25T16:01:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-10T13:38:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png\" \/>\n<meta name=\"author\" content=\"Adrien Devaux\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Adrien Devaux\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/\"},\"author\":{\"name\":\"Adrien Devaux\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/80889303f4b56d4e0d3637582fa1f705\"},\"headline\":\"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams\",\"datePublished\":\"2024-01-25T16:01:01+00:00\",\"dateModified\":\"2024-09-10T13:38:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/\"},\"wordCount\":851,\"commentCount\":0,\"image\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png\",\"keywords\":[\"Azure\",\"OCI\"],\"articleSection\":[\"Azure\",\"Cloud\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/\",\"url\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/\",\"name\":\"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams - dbi Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png\",\"datePublished\":\"2024-01-25T16:01:01+00:00\",\"dateModified\":\"2024-09-10T13:38:44+00:00\",\"author\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/80889303f4b56d4e0d3637582fa1f705\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage\",\"url\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image.png\",\"contentUrl\":\"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image.png\",\"width\":1917,\"height\":860},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.dbi-services.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#website\",\"url\":\"https:\/\/www.dbi-services.com\/blog\/\",\"name\":\"dbi Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.dbi-services.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/80889303f4b56d4e0d3637582fa1f705\",\"name\":\"Adrien Devaux\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/bc472273cc9807635382578d8967f63a3602eb717ab361bcf2c8ee9a59b682b0?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/bc472273cc9807635382578d8967f63a3602eb717ab361bcf2c8ee9a59b682b0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/bc472273cc9807635382578d8967f63a3602eb717ab361bcf2c8ee9a59b682b0?s=96&d=mm&r=g\",\"caption\":\"Adrien Devaux\"},\"url\":\"https:\/\/www.dbi-services.com\/blog\/author\/adriendevaux\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams - dbi Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/","og_locale":"en_US","og_type":"article","og_title":"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams","og_description":"I recently deployed a new logging solution at a customer for their OCI tenancy. They wanted to manage their audit logs using Microsoft Azure Sentinel. The solution I deployed is using OCI Streaming Service to gather all the logs and create an endpoint. Microsoft Sentinel will then connect to the endpoint to collect the logs. [&hellip;]","og_url":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/","og_site_name":"dbi Blog","article_published_time":"2024-01-25T16:01:01+00:00","article_modified_time":"2024-09-10T13:38:44+00:00","og_image":[{"url":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png","type":"","width":"","height":""}],"author":"Adrien Devaux","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Adrien Devaux","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#article","isPartOf":{"@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/"},"author":{"name":"Adrien Devaux","@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/80889303f4b56d4e0d3637582fa1f705"},"headline":"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams","datePublished":"2024-01-25T16:01:01+00:00","dateModified":"2024-09-10T13:38:44+00:00","mainEntityOfPage":{"@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/"},"wordCount":851,"commentCount":0,"image":{"@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png","keywords":["Azure","OCI"],"articleSection":["Azure","Cloud"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/","url":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/","name":"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams - dbi Blog","isPartOf":{"@id":"https:\/\/www.dbi-services.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage"},"image":{"@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage"},"thumbnailUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image-1024x459.png","datePublished":"2024-01-25T16:01:01+00:00","dateModified":"2024-09-10T13:38:44+00:00","author":{"@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/80889303f4b56d4e0d3637582fa1f705"},"breadcrumb":{"@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#primaryimage","url":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image.png","contentUrl":"https:\/\/www.dbi-services.com\/blog\/wp-content\/uploads\/sites\/2\/2024\/01\/image.png","width":1917,"height":860},{"@type":"BreadcrumbList","@id":"https:\/\/www.dbi-services.com\/blog\/sending-oci-logs-to-microsoft-azure-sentinel-with-oci-streams\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.dbi-services.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Sending OCI logs to Microsoft Azure Sentinel with OCI Streams"}]},{"@type":"WebSite","@id":"https:\/\/www.dbi-services.com\/blog\/#website","url":"https:\/\/www.dbi-services.com\/blog\/","name":"dbi Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.dbi-services.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.dbi-services.com\/blog\/#\/schema\/person\/80889303f4b56d4e0d3637582fa1f705","name":"Adrien Devaux","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/bc472273cc9807635382578d8967f63a3602eb717ab361bcf2c8ee9a59b682b0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/bc472273cc9807635382578d8967f63a3602eb717ab361bcf2c8ee9a59b682b0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bc472273cc9807635382578d8967f63a3602eb717ab361bcf2c8ee9a59b682b0?s=96&d=mm&r=g","caption":"Adrien Devaux"},"url":"https:\/\/www.dbi-services.com\/blog\/author\/adriendevaux\/"}]}},"_links":{"self":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/30179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/users\/90"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/comments?post=30179"}],"version-history":[{"count":5,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/30179\/revisions"}],"predecessor-version":[{"id":30482,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/posts\/30179\/revisions\/30482"}],"wp:attachment":[{"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/media?parent=30179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/categories?post=30179"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/tags?post=30179"},{"taxonomy":"type","embeddable":true,"href":"https:\/\/www.dbi-services.com\/blog\/wp-json\/wp\/v2\/type_dbi?post=30179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}