Skip to content

Oracle Cloud Infrastructure (OCI)

You can integrate Oracle Cloud Infrastructure (OCI) with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

OCI product overview

Oracle Cloud Infrastructure (OCI) is Oracle's set of cloud services — including networking, compute, storage, database, and platform services — for building and running applications and workloads in a highly available hosted environment.

What we ingest

Sophos XDR collects Oracle Cloud Infrastructure logs via OCI Streaming: you use the OCI Connector Hub to route the selected logs to an OCI Stream, which Sophos XDR ingests from the stream pool. The following log categories are collected:

  • Audit activity: OCI Audit logs across services (API and administrative operations).
  • Load balancer and WAF activity: OCI load balancer access logs and Web Application Firewall logs.
  • Intrusion detections: OCI Network Firewall (NGFW) intrusion detections.
  • Network flows1: VCN flow logs and Network Firewall traffic.

Event and data types

We ingest the following event and data types from OCI:

  • Audit activity: OCI Audit events — general, Object Storage, File Storage, Events service, and site-to-site VPN — covering API and administrative operations, with the caller identity, resource, and action. Normalized to cloud audit telemetry.
  • Load balancer and WAF activity: OCI load balancer access logs and Web Application Firewall logs, including the request, action, and endpoints. Normalized to HTTP telemetry.
  • Intrusion detections: OCI Network Firewall (NGFW) intrusion detections, including the signature and endpoints. Normalized to network intrusion detection telemetry.
  • Network flows1: VCN flow logs and Network Firewall traffic, including source and destination addresses and ports. Normalized to netflow telemetry.

Data provided by this integration

Data provided by OCI gets normalized to the following schemas:

  • cloudaudit
  • http
  • netflow 1
  • nids

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview