OCI_Logs_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Attribute Value
Custom Log V1 Yes 🔶 — uses type-suffixed column names
Ingestion API Supported ✓ Yes

Contents

Schema (257 columns)

Source: KQL validation test schema

Column Name Type
data_action_s string
data_additionalDetails_description_s string
data_additionalDetails_homeRegionKey_s string
data_additionalDetails_id_s string
data_additionalDetails_imageId_s string
data_additionalDetails_isAccessable_b bool
data_additionalDetails_isFreeTier_b bool
data_additionalDetails_lifeCycleState_s string
data_additionalDetails_namespace_s string
data_additionalDetails_oracleMyServicesIdentifier_s string
data_additionalDetails_shape_s string
data_additionalDetails_type_s string
data_additionalDetails_userId_s string
data_additionalDetails_volumeId_s string
data_additionalDetails_X_Real_Port_d real
data_availabilityDomain_s string
data_bytesOut_d real
data_compartmentId_s string
data_compartmentName_s string
data_definedTags_Oracle_Tags_CreatedBy_s string
data_definedTags_Oracle_Tags_CreatedOn_t datetime
data_destinationAddress_s string
data_destinationPort_d real
data_endTime_d real
data_eventGroupingId_g string
data_eventGroupingId_s string
data_eventName_s string
data_flowid_s string
data_freeformTags_VCN_s string
data_identity_authType_s string
data_identity_callerId_s string
data_identity_callerName_s string
data_identity_consoleSessionId_s string
data_identity_credentials_s string
data_identity_ipAddress_s string
data_identity_principalId_s string
data_identity_principalName_s string
data_identity_tenantId_s string
data_identity_userAgent_s string
data_message_s string
data_packets_d real
data_protocol_d real
data_protocolName_s string
data_request_action_s string
data_request_headers_Accept_Encoding_s string
data_request_headers_Accept_Language_s string
data_request_headers_Accept_s string
data_request_headers_auth_info_s string
data_request_headers_Authorization_s string
data_request_headers_Cache_Control_s string
data_request_headers_Connection_s string
data_request_headers_Content_Length_s string
data_request_headers_Content_Type_s string
data_request_headers_Cookie_s string
data_request_headers_Date_s string
data_request_headers_If_None_Match_s string
data_request_headers_oci_original_url_s string
data_request_headers_oci_skip_authorization_for_splat_s string
data_request_headers_oci_splat_audited_s string
data_request_headers_oci_splat_generated_ocids_s string
data_request_headers_oci_splat_internal_context_s string
data_request_headers_opc_client_info_s string
data_request_headers_opc_obo_token_s string
data_request_headers_opc_principal_s string
data_request_headers_opc_request_id_s string
data_request_headers_opc_retry_token_s string
data_request_headers_Origin_s string
data_request_headers_Referer_s string
data_request_headers_sec_ch_ua_mobile_s string
data_request_headers_sec_ch_ua_s string
data_request_headers_Sec_Fetch_Dest_s string
data_request_headers_Sec_Fetch_Mode_s string
data_request_headers_Sec_Fetch_Site_s string
data_request_headers_Sec_Fetch_User_s string
data_request_headers_Upgrade_Insecure_Requests_s string
data_request_headers_User_Agent_s string
data_request_headers_x_content_sha256_s string
data_request_headers_x_date_s string
data_request_headers_X_Forwarded_For_s string
data_request_headers_X_Forwarded_Host_s string
data_request_headers_X_Forwarded_Port_s string
data_request_headers_X_Forwarded_Proto_s string
data_request_headers_X_OCI_LB_NetworkMetadata_s string
data_request_headers_X_OCI_LB_PrivateAccessMetadata_s string
data_request_headers_X_Oracle_Auth_Client_CN_s string
data_request_headers_X_Real_IP_s string
data_request_headers_X_Real_Port_s string
data_request_id_s string
data_request_parameters_accessLevel_s string
data_request_parameters_availabilityDomain_s string
data_request_parameters_compartmentId_s string
data_request_parameters_compartmentIdInSubtree_s string
data_request_parameters_endTime_s string
data_request_parameters_fields_s string
data_request_parameters_granularity_s string
data_request_parameters_id_s string
data_request_parameters_imageId_s string
data_request_parameters_includeSubcompartments_s string
data_request_parameters_instanceId_s string
data_request_parameters_isBanner_s string
data_request_parameters_isMergeEnabled_s string
data_request_parameters_lifecycleState_s string
data_request_parameters_limit_s string
data_request_parameters_name_s string
data_request_parameters_operatingSystem_s string
data_request_parameters_operatingSystemVersion_s string
data_request_parameters_page_s string
data_request_parameters_param0_s string
data_request_parameters_protocol_s string
data_request_parameters_serviceName_s string
data_request_parameters_shape_s string
data_request_parameters_sortBy_s string
data_request_parameters_sortOrder_s string
data_request_parameters_startTime_s string
data_request_parameters_streamPoolId_s string
data_request_parameters_subnetId_s string
data_request_parameters_tenancy_s string
data_request_parameters_userId_s string
data_request_parameters_vcnId_s string
data_request_path_s string
data_resourceId_s string
data_response_headers_Access_Control_Allow_Credentials_s string
data_response_headers_access_control_allow_methods_s string
data_response_headers_Access_Control_Allow_Origin_s string
data_response_headers_Access_Control_Expose_Headers_s string
data_response_headers_Cache_Control_s string
data_response_headers_Connection_s string
data_response_headers_Content_Encoding_s string
data_response_headers_Content_Length_s string
data_response_headers_Content_Security_Policy_s string
data_response_headers_Content_Type_s string
data_response_headers_Date_s string
data_response_headers_Etag_s string
data_response_headers_Location_s string
data_response_headers_oci_splat_authorization_verify_content_s string
data_response_headers_opc_limit_s string
data_response_headers_opc_next_page_s string
data_response_headers_opc_prev_page_s string
data_response_headers_opc_previous_page_s string
data_response_headers_Opc_Request_Id_s string
data_response_headers_opc_work_request_id_s string
data_response_headers_Pragma_s string
data_response_headers_Strict_Transport_Security_s string
data_response_headers_Timing_Allow_Origin_s string
data_response_headers_Transfer_Encoding_s string
data_response_headers_Vary_s string
data_response_headers_x_api_id_s string
data_response_headers_X_Content_Type_Options_s string
data_response_headers_X_Frame_Options_s string
data_response_headers_X_Xss_Protection_s string
data_response_payload_id_s string
data_response_payload_resourceName_s string
data_response_responseTime_t datetime
data_response_status_s string
data_sourceAddress_s string
data_sourcePort_d real
data_startTime_d real
data_stateChange_current_agentConfig_areAllPluginsDisabled_b bool
data_stateChange_current_agentConfig_isManagementDisabled_b bool
data_stateChange_current_agentConfig_isMonitoringDisabled_b bool
data_stateChange_current_agentConfig_pluginsConfig_s string
data_stateChange_current_availabilityConfig_recoveryAction_s string
data_stateChange_current_availabilityDomain_s string
data_stateChange_current_compartmentId_s string
data_stateChange_current_configuration_s string
data_stateChange_current_definedTags_Oracle_Tags_s string
data_stateChange_current_definedTags_s string
data_stateChange_current_displayName_s string
data_stateChange_current_faultDomain_s string
data_stateChange_current_fingerprint_s string
data_stateChange_current_freeformTags_s string
data_stateChange_current_id_s string
data_stateChange_current_imageId_s string
data_stateChange_current_Instance_agentConfig_s string
data_stateChange_current_Instance_availabilityConfig_s string
data_stateChange_current_Instance_availabilityDomain_s string
data_stateChange_current_Instance_compartmentId_s string
data_stateChange_current_Instance_definedTags_s string
data_stateChange_current_Instance_displayName_s string
data_stateChange_current_Instance_extendedMetadata_s string
data_stateChange_current_Instance_faultDomain_s string
data_stateChange_current_Instance_freeformTags_s string
data_stateChange_current_Instance_id_s string
data_stateChange_current_Instance_imageId_s string
data_stateChange_current_Instance_instanceOptions_s string
data_stateChange_current_Instance_launchMode_s string
data_stateChange_current_Instance_launchOptions_s string
data_stateChange_current_Instance_lifecycleState_s string
data_stateChange_current_Instance_metadata_s string
data_stateChange_current_Instance_region_s string
data_stateChange_current_Instance_shape_s string
data_stateChange_current_Instance_shapeConfig_s string
data_stateChange_current_Instance_sourceDetails_s string
data_stateChange_current_Instance_systemTags_s string
data_stateChange_current_Instance_timeCreated_t datetime
data_stateChange_current_instanceId_s string
data_stateChange_current_instanceOptions_areLegacyImdsEndpointsDisabled_b bool
data_stateChange_current_isEnabled_s string
data_stateChange_current_keyId_s string
data_stateChange_current_keyValue_s string
data_stateChange_current_launchMode_s string
data_stateChange_current_launchOptions_bootVolumeType_s string
data_stateChange_current_launchOptions_firmware_s string
data_stateChange_current_launchOptions_isConsistentVolumeNamingEnabled_b bool
data_stateChange_current_launchOptions_isPvEncryptionInTransitEnabled_b bool
data_stateChange_current_launchOptions_networkType_s string
data_stateChange_current_launchOptions_remoteDataVolumeType_s string
data_stateChange_current_lifecycleDetails_s string
data_stateChange_current_lifecycleState_s string
data_stateChange_current_lifecyleDetails_s string
data_stateChange_current_LoadBalancers_s string
data_stateChange_current_logGroupId_s string
data_stateChange_current_logType_s string
data_stateChange_current_metadata_ssh_authorized_keys_s string
data_stateChange_current_region_s string
data_stateChange_current_retentionDuration_s string
data_stateChange_current_shape_s string
data_stateChange_current_shapeConfig_gpus_d real
data_stateChange_current_shapeConfig_localDisks_d real
data_stateChange_current_shapeConfig_maxVnicAttachments_d real
data_stateChange_current_shapeConfig_memoryInGBs_d real
data_stateChange_current_shapeConfig_networkingBandwidthInGbps_d real
data_stateChange_current_shapeConfig_ocpus_d real
data_stateChange_current_shapeConfig_processorDescription_s string
data_stateChange_current_sourceDetails_imageId_s string
data_stateChange_current_sourceDetails_sourceType_s string
data_stateChange_current_subnetIds_s string
data_stateChange_current_syslogUrl_s string
data_stateChange_current_systemTags_orcl_cloud_s string
data_stateChange_current_tenancyId_s string
data_stateChange_current_timeCreated_s string
data_stateChange_current_timeCreated_t datetime
data_stateChange_current_timeLastModified_s string
data_stateChange_current_timeUpdated_t datetime
data_stateChange_current_traceConfig_domainId_s string
data_stateChange_current_traceConfig_isEnabled_b bool
data_stateChange_current_userDisplayName_s string
data_stateChange_current_userId_s string
data_stateChange_current_userName_s string
data_status_s string
data_version_s string
dataschema_s string
id_g string
id_s string
oracle_compartmentid_s string
oracle_ingestedtime_t datetime
oracle_loggroupid_s string
oracle_logid_s string
oracle_tenantid_s string
oracle_vniccompartmentocid_s string
oracle_vnicocid_s string
oracle_vnicsubnetocid_s string
source_s string
specversion_s string
time_t datetime
TimeGenerated datetime
type_s string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
[DEPRECATED] Oracle Cloud Infrastructure

Content Items Using This Table (21)

Analytic Rules (10)

In solution Oracle Cloud Infrastructure:

Analytic Rule Selection Criteria
OCI - Discovery activity
OCI - Event rule deleted
OCI - Inbound SSH connection
OCI - Insecure metadata endpoint
OCI - Instance metadata access
OCI - Multiple instances launched
OCI - Multiple instances terminated
OCI - Multiple rejects on rare ports
OCI - SSH scanner
OCI - Unexpected user agent

Hunting Queries (10)

In solution Oracle Cloud Infrastructure:

Hunting Query Selection Criteria
OCI - Delete operations
OCI - Deleted users
OCI - Destination ports (inbound traffic)
OCI - Destination ports (outbound traffic)
OCI - Launched instances
OCI - New users
OCI - Terminated instances
OCI - Update activities
OCI - Updated instances
OCI - User source IP addresses

Workbooks (1)

In solution Oracle Cloud Infrastructure:

Workbook Selection Criteria
OracleCloudInfrastructureOCI

Parsers Using This Table (1)

Other Parsers (1)

Parser Solution Selection Criteria
OCILogs Oracle Cloud Infrastructure

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index