How to integrate ORACLE 12.1.0.2 logs to Azure Sentinel??

%3CLINGO-SUB%20id%3D%22lingo-sub-2789632%22%20slang%3D%22en-US%22%3EHow%20to%20integrate%20ORACLE%2012.1.0.2%20logs%20to%20Azure%20Sentinel%3F%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2789632%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20like%20to%20know%26nbsp%3BHow%20to%20integrate%20ORACLE%2012.1.0.2%20logs%20to%20Azure%20Sentinel%3F%3F%20The%20server%20is%20on-premise%2C%20what%20are%20the%20possible%20options%20available.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20see%20there%20are%20no%20out%20of%20the%20box%20data%20connectors%20for%20this%2C%20an%20expedited%20response%20is%20much%20appreciated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3EFahad.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2793878%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20integrate%20ORACLE%2012.1.0.2%20logs%20to%20Azure%20Sentinel%3F%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2793878%22%20slang%3D%22en-US%22%3EDoing%20a%20bit%20of%20research%20I%20came%20across%20following%20two%20solutions%3A%3CBR%20%2F%3E%3CBR%20%2F%3ESolution%201%3A%20Oracle%20Database%20Audit%20(Preview)%3CBR%20%2F%3ECurrently%20Oracle%20Database%20audit%20solution%20is%20currently%20in%20preview%20mode%2C%20wait%20until%20its%20available%20for%20public.%3CBR%20%2F%3E%3CBR%20%2F%3ESolution%202%3A%20Use%20Logstash%3CBR%20%2F%3ESearched%20one%20video%20on%20youtube%20that%20talks%20about%20using%20Logstash%20in%20general%2C%20it%20uses%20JDBC%20input%20plugin%20to%20connect%20to%20database%2C%20read%20the%20table%20in%20which%20the%20database%20is%20writing%20the%20logs%20and%20use%20output%20plugin%20to%20forward%20it%20to%20azure%20sentinel.%3CBR%20%2F%3E%3CBR%20%2F%3EAny%20other%20options%20available%3F%3C%2FLINGO-BODY%3E
Contributor

Hello,

 

I would like to know How to integrate ORACLE 12.1.0.2 logs to Azure Sentinel?? The server is on-premise, what are the possible options available. 

 

I see there are no out of the box data connectors for this, an expedited response is much appreciated.

 

Thanks

Fahad.

1 Reply
Doing a bit of research I came across following two solutions:

Solution 1: Oracle Database Audit (Preview)
Currently Oracle Database audit solution is currently in preview mode, wait until its available for public.

Solution 2: Use Logstash
Searched one video on youtube that talks about using Logstash in general, it uses JDBC input plugin to connect to database, read the table in which the database is writing the logs and use output plugin to forward it to azure sentinel.

Any other options available?