Oracle Cloud Infrastructure (OCI)
You can integrate Oracle Cloud Infrastructure (OCI) with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
OCI product overview
Oracle Cloud Infrastructure (OCI) is Oracle's set of cloud services — including networking, compute, storage, database, and platform services — for building and running applications and workloads in a highly available hosted environment.
What we ingest
Sophos XDR collects Oracle Cloud Infrastructure logs via OCI Streaming: you use the OCI Connector Hub to route the selected logs to an OCI Stream, which Sophos XDR ingests from the stream pool. The following log categories are collected:
- Audit activity: OCI Audit logs across services (API and administrative operations).
- Load balancer and WAF activity: OCI load balancer access logs and Web Application Firewall logs.
- Intrusion detections: OCI Network Firewall (NGFW) intrusion detections.
- Network flows1: VCN flow logs and Network Firewall traffic.
Event and data types
We ingest the following event and data types from OCI:
- Audit activity: OCI Audit events — general, Object Storage, File Storage, Events service, and site-to-site VPN — covering API and administrative operations, with the caller identity, resource, and action. Normalized to cloud audit telemetry.
- Load balancer and WAF activity: OCI load balancer access logs and Web Application Firewall logs, including the request, action, and endpoints. Normalized to HTTP telemetry.
- Intrusion detections: OCI Network Firewall (NGFW) intrusion detections, including the signature and endpoints. Normalized to network intrusion detection telemetry.
- Network flows1: VCN flow logs and Network Firewall traffic, including source and destination addresses and ports. Normalized to netflow telemetry.
Data provided by this integration
Data provided by OCI gets normalized to the following schemas:
cloudaudithttpnetflow1nids
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
- Overview of Streaming
- Creating an Identity Domain
- Creating a Compartment
- Creating a Group
- Adding Users
- Service Log Reference
- Creating a Connector
- Regions and Availability Domains
-
Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview. ↩↩↩