Oracle-defined Sources

Oracle Log Analytics provides the following Oracle-defined sources that you can use.

Log Source Description Source Type Entity Types Source Identifier
AIX Audit Logs Files that store AIX audit records File Host (AIX) AixAuditLogSource
AIX Cron Logs Cron log files for AIX File Host (AIX) AixCronlogSource
AIX Dynamic System Optimizer Logs Dynamic System Optimizer log files for AIX File Host (AIX) AixAsologSource
AIX HACMP Cluster Logs HACMP Cluster log files for AIX File Host (AIX) AixClusterlogSource
AIX SU Logs Logs that capture SU (switch user) activity File Host (AIX) AixSUlogSource
AIX Syslog Logs Syslog log files for AIX File Host (AIX) AixSyslogSource
Apache Cassandra DB Garbage Collection Logs Apache Cassandra DB Garbage Collection Logs File CassandraDB ApacheCassandraGCLogSource
Apache Cassandra DB System Logs Apache Cassandra DB System Logs File CassandraDB ApacheCassandraSystemLogSource
Apache Hadoop Standard Logs Apache Hadoop Standard Logs File Hadoop DataNode, Hadoop NameNode, Hadoop Node Manager, Hadoop Resource Manager ApacheHadoopLogSource
Apache Hive Logs Collects the Apache Hive default logs File Apache Hive ApacheHiveLogSource
Apache HTTP Server Access Logs Access log files for Apache Web Server File Apache HTTP Server ApacheWebServerAccessLogSource
Apache HTTP Server Error Logs Error log files for Apache Web Server File Apache HTTP Server ApacheWebServerErrorLogSource
Apache HTTP Server SSL Access Logs SSL Access log files for Apache Web Server File Apache HTTP Server ApacheWebServerSSLAccessLogSource
Apache HTTP SSL Request Logs SSL Request log files for Apache Web Server File Apache HTTP Server ApacheWebServerSSLRequestLogSource
Apache Kafka Logs Apache Kafka Log Source that supports the Kafka default log format File Apache Kafka ApacheKafkaStandardLogSource
Apache Spark Logs Apache Spark Logs record job, stage, and task events, error events etc., useful for diagnosing failures, skew, timeouts, memory/GC pressure, and cluster resource issues. File Apache Spark ApacheSparkLogSource
Apache Tomcat Access Logs Apache Tomcat Access Logs File Tomcat ApacheTomcatAccessLogSource
Apache Tomcat Catalina Logs Apache Tomcat Catalina Logs File Tomcat ApacheTomcatCatalinaLogSource
Apache Tomcat Error Logs Apache Tomcat Error Logs File Tomcat ApacheTomcatErrorLogSource
Apache Tomcat Host Logs Apache Tomcat Host Logs File Tomcat ApacheTomcatHostLogSource
Apache Tomcat Manager Logs Format for the Apache Tomcat Manager Logs File Tomcat ApacheTomcatManagerLogSource
Apache Zookeeper Logs Apache Zookeeper log source File Apache ZooKeeper ApacheZookeeperLogSource
APM Signals Application Performance Monitoring (APM) Signals capture detailed spans, span events, span links and logs related to application behavior and health. They provide insights into response times, errors, resource usage, and transactions, enabling proactive detection of issues, measurement of user experience, and continuous optimization of application performance across diverse environments. APM APM Domain apmSignalsLogSource
ArcSight CEF Syslog Source ArcSight Common Event Format Syslog Source Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) ArcSightSyslogSource
ArcSight Common Event Format Source ArcSight Common Event Format Source File Host (Linux) ArcSightCEF
Asterisk IP PBX Full Logs Asterisk full logs provide the most detailed view of PBX activity, capturing notices, warnings, errors, verbose call traces, dialplan execution steps, SIP/IAX signaling, channel state changes, and module-level debugging. Generated through Asterisk’s logger.conf, these logs record comprehensive operational and call-processing events, making them essential for troubleshooting, performance analysis, and deep visibility into call flows. File Asterisk IP PBX asteriskFullLogSource
Asterisk IP PBX Queue Logs Asterisk Queue Logs capture detailed lifecycle events for calls handled by Asterisk call queues. They record how callers move through the queue, how agents interact with those calls, and how each call concludes. These logs provide granular visibility into queue performance, agent activity, and call-handling behavior for monitoring, analytics, and troubleshooting. File Asterisk IP PBX asteriskQueueLogSource
Automatic Storage Management Alert Logs Oracle Automatic Storage Management 11.1.+ DB Alert Logs File Automatic Storage Management Instance ASMDBAlertLogSource
Automatic Storage Management Trace Logs Oracle Automatic Storage Management 11.1+ DB Trace Log File File Automatic Storage Management Instance ASMDBTraceLogSource
AVDF Alert in Oracle Database AVDF Alert Stored in Oracle Database Database Oracle Database Instance, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing omc_AVDFAlertInOracleDBSource
AVDF Event in Oracle Database AVDF Event stored in Oracle Database Database Oracle Database Instance, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing AVDFEventInOracleDBSource
AVDFAlert Linux Syslog Standard AVDFAlert OS Syslog log files for Linux File Host (Linux) AVDFAlertLinuxSyslogSource
AWS EKS Authenticator Logs AWS Elastic Kubernetes Service (EKS) Authenticator logs represent the control plane component that EKS uses for Kubernetes RBAC authentication using IAM File Kubernetes Cluster ociEksAuthenticatorLogSource
Bluecoat Proxy Squid Logs Files that store Bluecoat Proxy Squid Logs File Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX), Host (Windows) BluecoatSquidLogSource
Bluecoat Proxy W3C Logs Files that store Bluecoat Proxy W3C Logs File Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX), Host (Windows) BluecoatW3cLogSource
Check Point Firewall LEA Syslog Logs Check Point Firewall log source that supports the LEA syslog format. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) CheckPointFirewallSyslogListenerSource
Cisco ASA Logs Standard Cisco Adaptive Security Appliance log files File Host (Linux) CiscoAsaSource
Cisco Syslog Listener Source Cisco Direct Syslog Listener Source Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) CiscoSyslogSource
Citrix NetScaler Logs Citrix NetScaler Log Source that supports the Syslog Format. This source should be associated to the host where the OMC Agent will listen for syslog messages. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX) NetscalerLogSource
Cloud Controller Manager Logs Cloud Controller Manager Logs File Kubernetes Cluster ociCloudControllerManagerLogSource
Clusterware Disk Monitor Logs Oracle Clusterware Disk Monitor Logs File Oracle Cluster Node CRSDiskmonLogSource
Clusterware Ready Services Alert Logs Oracle Clusterware 11.1+ Database Alert Logs File Oracle Cluster Node CRSAlertLogSource
Clusterware Ready Services Daemon Logs Oracle 11.1+ Clusterware Ready Services Daemon component log for RAC DB Instance File Oracle Cluster Node CRSDLogSource
CUPS Access Logs Common UNIX Printing System (CUPS) access log file is part of the logging system for the Common UNIX Printing System (CUPS). It records information about client requests, which is useful for auditing and troubleshooting printing issues. File CUPS cupsAccessLogSource
CUPS Error Logs CUPS (Common UNIX Printing System) Error Log records all CUPS events — ERROR, WARNING, INFO, and DEBUG — related to printer connections, job processing, filter/back‑end failures, authentication checks, and overall print system health. File CUPS cupsErrorLogSource
CyberArk Syslog Common Event Format Logs CyberArk log source that supports the syslog Comment Event Format Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) omc_cyberArkSyslogCefListenerSource
Database 19c Attention Logs Attention Logs for Oracle 19c Database File Oracle Database Instance, Automatic Storage Management Instance DBAttentionRegexLogSource
Database Alert Logs Oracle 11.1.+ Database Alert logs File Oracle Database Instance DBAlertLogSource
Database Alert Logs Stored in Database Alert logs stored in database, retrieved using V$DIAG_ALERT_EXT view Database Autonomous Data Warehouse, Autonomous Transaction Processing, Oracle Database Instance, Oracle Pluggable Database, Oracle Database, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development DBAlertLogsFromDBSource
Database Attention Logs Oracle Database Attention Logs introduced from DB 21, are special diagnostic logs designed to capture important database events such as critical errors, component failures, and configuration issues. These logs help DBAs quickly identify events that require immediate attention. File Oracle Database Instance, Automatic Storage Management Instance DBAttentionLogSource
Database Attention Logs Stored in Database 23ai These Database Attention logs are from V$DIAG_ALERT_EXT view stored in Database 23ai and higher Database Oracle Database Instance, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing ociSqlDb23AttnLogSource
Database Audit Logs Oracle Database Audit Log File. File Oracle Database Instance DBAuditLogSource
Database Audit XML Logs Oracle Database Audit XML Logs File Oracle Database Instance DBAuditXMLLogSource
Database Incident Dump Files Oracle 11.1+ Database Incident Dump File File Oracle Database Instance DBIncidentDumpSource
Database Listener Alert Logs Oracle 11.1+ Database Listener Alert Log File File Oracle Database Listener TNSAlertLogSource
Database Listener Trace Logs Oracle 11.1+ Database Listener Trace Log File File Oracle Database Listener TNSTraceLogSource
Database Trace Logs Oracle 11.1+ Database Trace Log File File Oracle Database Instance DBTraceLogSource
Database Trace Logs stored in Database Trace logs stored in V$DIAG_TRACE_FILE_CONTENTS database table Database Autonomous Data Warehouse, Autonomous Transaction Processing, Oracle Database Instance, Oracle Pluggable Database, Oracle Database, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development TraceLogsFromDBSource
Database XML Alert Logs Oracle 11.1.+ Database Alert logs in XML format File Oracle Database Instance DBAlertXMLLogSource
EBS Concurrent Manager Logs EBS Concurrent Manager Logs File EBS Concurrent Processing Node EbsConcurrentManagerSource
EBS Concurrent Request Logs This Source does not consider Request logs as written once and collects the logs as soon as the logs are available. All the logs are linked together by requestID and other properties extracted from the header. File EBS Concurrent Processing Node EbsConcurrentReqLogSource
EBS Conflict Resolution Manager Logs EBS Conflict Resolution Manager Logs File EBS Concurrent Processing Node EbsConflictResolutionMgrSource
EBS Internal Concurrent Manager Logs EBS Internal Concurrent Manager Logs File EBS Concurrent Processing Node EbsInternalConcurrentManagerSource
EBS Output Post Processor Logs EBS Output Post Processor Logs File EBS Concurrent Processing Node EBSOPPLogSource
EBS Transaction Manager Logs EBS Concurrent Processing Transaction Manager Logs File EBS Concurrent Processing Node EbsTransactionMgrSource
EBS Workflow Notification Mailer Logs EBS Workflow Notification Mailer Logs File EBS Workflow Notification Mailer EBSWFNotificationMailerLogSource
Eclipse Jetty Request Logs Eclipse Jetty Request (Access) Logs File Jetty Server jettyRequestLogSource
Eclipse Jetty Server Logs Eclipse Jetty Server Logs File Jetty Server jettyServerLogSource
Enterprise Manager API Gateway Access Logs Enterprise Manager API Gateway access logs provide a record of every incoming or outgoing request and response that passes through the gateway File OEM API Gateway emccApiGatewayAccessLogSource
Enterprise Manager API Gateway Application Logs Enterprise Manager API Gateway Application Logs File OCI API Gateway, OEM API Gateway ociEmccApiGatewayApplicationLogs
Enterprise Manager API Gateway LCM Logs Enterprise Manager API Gateway Lifecycle Management (LCM) Logs File OEM API Gateway emccApiGatewayLcmLogSouce
F5 Big IP ASM WAF Syslog CEF Logs F5 Big IP ASM Web Application Firewall log source which supports the syslog listener Common Event Format Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) omc_F5BigIPAsmWafCEFSyslogListenerSource
F5 Big IP Logs F5 Big IP log source that supports the syslog format. This source should be associated to the host where the OMC Agent will listen for syslog messages. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) BigIPLogSource
FMW BI Java Host Logs FMW BI Java Host Logs ODL oracle_bi_java_host FmwBiJhLogSource
FMW BI JBIPS Logs FMW BI JBIPS Logs ODL WebLogic Server FmwBiJbipsLogSource
FMW BI NQ Cluster Controller Logs FMW BI NQ Cluster Controller Logs ODL oracle_bi_cluster_controller FmwBiNqclusterLogSource
FMW BI NQ Query Logs FMW BI NQ Query Logs ODL oracle_bi_server FmwBiNqqueryLogSource
FMW BI NQ Scheduler Logs FMW BI NQ Scheduler Logs ODL oracle_bi_scheduler FmwBiNqschedulerLogSource
FMW BI NQ Server Logs FMW BI NQ Server Logs ODL oracle_bi_server FmwBiNqserverLogSource
FMW BI Presentation Services Logs FMW BI Presentation Services Logs ODL oracle_bi_presentation_services FmwBiSawlogLogSource
FMW BI Publisher Logs FMW BI Publisher Logs ODL WebLogic Server FmwBiBipublisherLogSource
FMW OAM Embedded LDAP Access Logs FMW OAM Embedded LDAP Access Logs File Oracle Access Management Server FmwOamEmbeddedLdapAccessLogSource
FMW OHS Access Logs (V11) FMW OHS Access Logs (V11) File Oracle HTTP Server FmwOhsAccessLogSource
FMW OHS Access Logs (V12) FMW OHS Access Logs (V12) File Oracle HTTP Server FmwOhsV12AccessLogSource
FMW OHS Admin Access Logs (V12) FMW OHS Admin Access Logs (V12) File Oracle HTTP Server FmwOhsV12AdminLogSource
FMW OHS Diagnostic Logs (V11) FMW OHS Diagnostic Logs (V11) ODL Oracle HTTP Server FmwOhsDiagLogSource
FMW OHS Error Logs FMW OHS Error Logs File Oracle HTTP Server FmwOhsErrorLogSource
FMW OHS OPMN Logs (V11) entryremoval File Oracle HTTP Server FmwOhsOpmnLogSource
FMW OHS Server Logs (V12) FMW OHS Server Logs (V12) ODL Oracle HTTP Server FmwOhsV12ServerLogSource
FMW OID Audit Logs FMW Oracle Internet Directory Audit Logs File Oracle Internet Directory FmwOidAuditLogSource
FMW OID Directory Control Logs FMW OID Directory Control Logs ODL Oracle Internet Directory FmwOidControlLogSource
FMW OID Directory Dispatcher Server Logs FMW OID Directory Dispatcher Server Logs ODL Oracle Internet Directory FmwOidDispdLogSource
FMW OID Directory Replication Server Logs FMW OID Directory Replication Server Logs ODL Oracle Internet Directory FmwOidRepldLogSource
FMW OID Directory Server Logs FMW OID Directory Server Logs ODL Oracle Internet Directory FmwOidLdapsLogSource
FMW OID Monitor Logs FMW OID Monitor Logs ODL Oracle Internet Directory FmwOidMonitorLogSource
FMW OID OPMN Logs FMW OID OPMN Logs File Oracle Internet Directory FmwOidOpmnLogSource
FMW WLS Node Manager Log FMW WLS Node Manager Log File WebLogic Domain, WebLogic Node Manager FmwWlsNodeManagerLogSource
FMW WLS Server Access Logs FMW WLS Server Access Logs File WebLogic Server FmwWlsServerAccessLogSource
FMW WLS Server Default Audit Recorder Event Logs WebLogic Server Default Audit Recorder Logs track security-related activities across the domain. They support monitoring, auditing, and compliance by recording authentication, authorization, configuration, and role management events, providing visibility into user actions and system behavior for investigation and governance purposes. File WebLogic Server fmwWlsDefAudRecLogSource
FMW WLS Server Diagnostic Logs WebLogic Server diagnostic logs capture ODL-formatted runtime messages for server components, helping administrators troubleshoot errors, warnings, performance issues, application behavior etc., ODL WebLogic Server FmwWlsServerDiagLogSource
FMW WLS Server Logs FMW WLS Server Logs File WebLogic Server FmwWlsServerLogSource
FMW WLS Server STDOUT Logs FMW WLS Server STDOUT Logs File WebLogic Server FmwWlsServerOutSource
Fortinet Log Event Logs Fortinet Log Event Logs File Host (Linux) FortinetSyslogFileSource
Fortinet Syslog Logs Fortinet log source that supports the syslog format Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) FortinetSyslogListenerSource
Fusion Apps Diagnostic Logs Fusion Apps Diagnostic Logs ODL WebLogic Server FaAppsServerDiagLogSource
Fusion Apps: ADF Audit Logs Fusion Apps: ADF Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsADFAuditLogSource
Fusion Apps: Enterprise Scheduler Service Request Logs Fusion Enterprise Scheduler Service (ESS) Requests represent scheduled or on-demand job submissions within Fusion Enterprise Scheduler Service. They define execution details such as parameters, timing, and submitter context, enabling automation of business processes, batch operations, and background tasks while providing tracking, status monitoring, and auditability of job execution. REST API Oracle Fusion Applications FusionAppsEssRequestLogSource
Fusion Apps: ESS Audit Logs Fusion Apps: ESS Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsESSAuditLogSource
Fusion Apps: HCM Payroll Audit Logs Fusion Apps: HCM Payroll Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsHCMPayrollAuditLogSource
Fusion Apps: HCM People Audit Logs Fusion Apps: HCM People Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsHCMPeopleAuditLogSource
Fusion Apps: MDS Audit Logs Fusion Apps: MDS Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsMDSAuditLogSource
Fusion Apps: OBIEE Audit Logs Fusion Apps: OBIEE Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsOBIEEAuditLogSource
Fusion Apps: ODI Audit Logs Fusion Apps: ODI Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsODIAuditLogSource
Fusion Apps: OPSS Audit Logs Fusion Apps: OPSS Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsOPSSAuditLogSource
Fusion Apps: Sign In - Sign Out Activity Logs Fusion Apps: Sign In - Sign Out Activity logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsSigninSignoutAuditLogSource
Fusion Apps: SOA Audit Logs Fusion Apps: SOA Audit Logs fetched through REST API call REST API Oracle Fusion Applications FusionAppsSOAAuditLogSource
Grafana Server JSON Logs Grafana Server JSON Logs File Grafana Server ociGrafanaJsonLogSource
Grafana Server Logs Grafana server logs in unstructured (key-value) format File Grafana Server ociGrafanaLogSource
HAProxy Logs HAProxy Logs collected through syslog listener Syslog Listener Host (Linux) ociHAProxyLogSource
IBM DB2 Audit Logs IBM DB2 Audit Log File. File IBM DB2 Database DB2AuditLogSource
IBM DB2 Diagnostic Logs IBM DB2 Diagnostic Logs File IBM DB2 Database IBMDB2DiagnosticLogSource
IBM QRadar Log Event Extended Format Logs IBM QRadar Log Event Extended Format Logs File Host (AIX), Host (Linux), Host (Solaris), Host (Windows) QRadarLEEF
IBM Websphere Application Server (Classic) Logs IBM Websphere Application Server (Classic) Logs In Basic Or Advanced Format File IBM Websphere Server WebsphereSystemOutLogSource
IBM Websphere Application Server (Classic) System Error IBM Websphere Application Server (Classic) System Error File IBM Websphere Server WebsphereSystemErrorLogSource
IDCS Audit API Logs Identity Cloud Service Audit log that are collected by REST API outside of Log Analytics File Oracle Identity Cloud Service omc_idcsAuditSource
Identity and Access Management Audit Database Source to fetch identity and access management (OAM) audit table rows from the database Database Oracle Database Instance, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing IdentityandAccessMgtauditDatabase
Ingress Nginx Controller Logs Ingress Nginx Controller File Host (Linux) ociIngressNginxControllerLogSource
Ipswitch WS_FTP Server Logs Ipswitch WS_FTP Server Logs File Ipswitch WS_FTP Server WSFTPLogSource
IPTable Logs IPTable log files for Linux File Host (Linux) omc_iptableLogSource
IPTraf Monitor Logs IPTraf Monitor Log File Host (Linux) IpTrafLogSource
Java Hotspot Dump Logs Source that will parse Java Hotspot Dump files. To use this source for continuous monitoring, please add one or more file patterns defining where the logs are located. File Host (Linux), Host (Windows), Host (AIX), Host (Solaris) orclJavaHotSpotDumpSource
JBOSS EAP Log Source JBOSS Enterprise Application Platform server log files. File JBoss Server JBossEAP64Source
Juniper SRX Syslog Logs Juniper SRX Log Source that uses the default syslog format. This source should be associated to the host where the OMC Agent will listen for syslog messages. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX) JuniperSRXSysLogSource
Ksplice Logs Ksplice log files for Linux File Host (Linux) KspliceLogSource
Kubernetes API Server Logs Kubernetes API Server Logs File Kubernetes Cluster ociK8sAPIServerLogSource
Kubernetes Audit Logs Kubernetes Audit Logs File Kubernetes Cluster ociK8sAuditLogSource
Kubernetes Autoscaler Logs Kubernetes Autoscaler Logs File Kubernetes Cluster ociK8sAutoscalerLogSource
Kubernetes AWS Node Logs AWS node manages the network connectivity between the Amazon EKS nodes and AWS services. File Kubernetes Cluster ociK8sAwsNodeLogSource
Kubernetes Container Generic Logs This source handles all Kubernetes container logs without a specific handling. This is a catch all source for container logs till a specific handling is added. File Kubernetes Cluster ociK8sContGenLogsSource
Kubernetes Container Status Logs The Container status information is extracted out of the Kubernetes Pod status object. File Kubernetes Cluster ociK8sContainerStatusLogSource
Kubernetes Controller Manager Logs Kubernetes Controller Manager Logs File Kubernetes Cluster ociK8sControllerManagerLogSource
Kubernetes Core DNS Logs CoreDNS is a flexible, extensible DNS server that can serve as the Kubernetes cluster DNS File Kubernetes Cluster ociK8sCoreDNSLogSource
Kubernetes CronJob Object Logs A CronJob creates Jobs on a repeating schedule. One CronJob object is like one line of a crontab (cron table) file. It runs a job periodically on a given schedule, written in Cron format File Kubernetes Cluster ociK8sCronjobObjLogSource
Kubernetes CSI Controller Logs The CSI controller is responsible for managing the lifecycle of volumes. File Kubernetes Cluster ociK8sCsiControllerLogSource
Kubernetes CSI Node Driver Logs The CSI node-driver-registrar is a sidecar container that fetches driver information (using NodeGetInfo ) from a CSI endpoint and registers it with the kubelet on that node using the kubelet plugin registration mechanism. File Kubernetes Cluster ociK8sCsiNodeDriverLogSource
Kubernetes DaemonSet Object Logs Kubernetes DaemonSet Object Logs File Kubernetes Cluster ociK8sDaemonsetobjLogSource
Kubernetes Deployment Object Logs A Deployment provides declarative updates for Pods and ReplicaSets. If a desired state in a Deployment is provided then the Deployment Controller changes the actual state to the desired state at a controlled rate. File Kubernetes Cluster ociK8sDeployementObjLogSource
Kubernetes DNS Autoscaler Logs Log Source For Kubernetes DNS Autoscaler Logs. An Autoscaler Pod runs a client that polls the Kubernetes API server for the number of nodes and cores in the cluster. A desired replica count is calculated and applied to the DNS backends based on the current schedulable nodes and cores and the given scaling parameters. File Kubernetes Cluster ociK8sDNSAutoscalerLogSource
Kubernetes Endpoint Logs These logs are derived from Kubernetes EndpointSlice Object logs. File Kubernetes Endpoint Slice ociK8sEndpointLogSource
Kubernetes EndpointSlice Object Logs In Kubernetes, an EndpointSlice contains references to a set of network endpoints. File Kubernetes Endpoint Slice ociK8sEndpointSliceObjLogSource
Kubernetes etcd Logs Kubernetes etcd Logs File Kubernetes Cluster ociK8sEtcdLogSource
Kubernetes Event Object Logs Kubernetes events are objects that provide insight into what is happening inside a cluster, such as what decisions were made by scheduler or why some pods were evicted from the node, etc File Kubernetes Cluster ociK8sEventObjLogSource
Kubernetes Flannel Logs flannel is a virtual networking layer designed specifically for containers. Each host in a flannel cluster runs an agent called flanneld. It assigns each host a subnet, which acts as the IP address pool for containers running on the host. File Kubernetes Cluster ociK8sFlannelLogSource
Kubernetes Job Object Logs A Job creates one or more Pods and will continue to retry execution of the Pods until a specified number of them successfully terminate. As pods successfully complete, the Job tracks the successful completions. When a specified number of successful completions is reached, the task (ie, Job) is complete File Kubernetes Cluster ociK8sJobobjLogSource
Kubernetes Kubelet Logs Kubelet is responsible for running containers on the node. Kubelet Logs are collected through syslog. File Kubernetes Cluster ociK8sKubeletLogSource
Kubernetes Namespace Object Logs Namespaces provides a mechanism for isolating groups of resources within a single cluster. File Kubernetes Cluster ociK8sNamespaceObjLogSource
Kubernetes Node Object Logs A Node is a worker machine in Kubernetes and may be either a virtual or a physical machine, depending on the cluster. Each Node is managed by the control plane. File Kubernetes Cluster ociK8sNodeObjLogSource
Kubernetes Object Change Logs Logs for tracking Kubernetes Object spec changes as derived by Log Analytics service File Kubernetes Cluster ociK8sObjectChangeLogSource
Kubernetes Object Logs Generic source for handling Kubernetes Object Logs File Kubernetes Cluster ociK8sObjectLogSource
Kubernetes Persistent Volume Claim Object Logs A PersistentVolumeClaim (PVC) is a request for storage by a user. It is similar to a Pod. Pods consume node resources and PVCs consume PV resources. File Kubernetes Cluster ociK8sPersistentVolClaimObjLogSource
Kubernetes Persistent Volume Object Logs A PersistentVolume (PV) is a piece of storage in the cluster that has been provisioned by an administrator or dynamically provisioned using Storage Classes. File Kubernetes Cluster ociK8sPersistentVolObjLogSource
Kubernetes Pod Object Logs Pods are the smallest deployable units of computing that you can create and manage in Kubernetes. These logs represent the Pod status information that is collected periodically File Kubernetes Cluster ociK8sPodObjLogSource
Kubernetes Proxy Logs Log Source For Kubernetes Proxy Logs. Kube Proxy is responsible for load balancing the services File Kubernetes Cluster ociK8sProxyLogSource
Kubernetes ReplicaSet Object Logs A ReplicaSet's purpose is to maintain a stable set of replica Pods running at any given time. As such, it is often used to guarantee the availability of a specified number of identical Pods. File Kubernetes Cluster ociK8sReplicaSetObjLogSource
Kubernetes Scheduler Logs Kubernetes Scheduler Logs File Kubernetes Cluster ociK8sSchedulerLogSource
Kubernetes Service Object Logs Service is a method for exposing a network application that is running as one or more Pods in a cluster. File Kubernetes Service ociK8sServiceObjLogSource
Kubernetes StatefulSet Object Logs StatefulSet is the workload API object used to manage stateful applications. Manages the deployment and scaling of a set of Pods, and provides guarantees about the ordering and uniqueness of these Pods File Kubernetes Cluster ociK8sStatefulobjLogSource
Kubernetes TCP Connect Logs Logs capturing TCP connects from all the Kubernetes worker nodes and used in generating Network view (application topology) for the Kubernetes Monitoring Solution File Host (Linux) ociK8sTcpConnectTraceLogSource
Linux Audit Logs Files that store os-level audit records File Host (Linux) AuditLogSource
Linux Cron Logs Log files that store history and operational logs related to cron daemon activities. Cron is used to schedule commands to run. File Host (Linux) LinuxCronLogSource
Linux DNF (Dandified Yum) logs DNF logs record all activities related to the DNF (Dandified Yum) package manager in Linux systems, including package installations, updates, and errors. File Host (Linux) linuxDnfLogSource
Linux Exadata Cell Alert Logs Exadata Cell Alert log files for Linux File Host (Linux) LinuxExadataCellAlertlogSource
Linux Exadata Cell Management Server Logs Exadata Cell Management Server log files for Linux File Host (Linux) LinuxExadataMSlogSource
Linux Exadata Cell Management Server Trace Logs Exadata Cell Management Server trace log files for Linux File Host (Linux) LinuxExadataMSTracelogSource
Linux Kernel Journald Logs Linux Kernel Logs (journalctl) capture kernel-level system logs managed by systemd, recording events from the Linux kernel for monitoring, troubleshooting, and auditing. Logs are collected using "journalctl -k --no-pager -o short-iso --utc", producing UTC timestamps. By default, only new kernel records are fetched using a cursor and collected via passwordless sudo. One can customize the command to retrieve all messages (--allmsg), disable sudo (--nosudo), or bypass cursor (--nocursor) based collection. OS Command Host (Linux) linuxJournalctlLogSource
Linux Mail Delivery Logs Log files for Linux Mail daemon delivered messages File Host (Linux) LinuxMailLogSource
Linux Netstat Active Connections Logs Linux Netstat Active Connections Logs capture a point-in-time snapshot of active connections, including local and foreign (remote) IP:port pairs, connection states, queue sizes, and owning process details. The primary purpose is to identify connections to public foreign IPs. Each execution records host collection time as the timestamp (unless overwritten during ingestion). One can customize the command to filter by process name (-p) or foreign IP (-i). OS Command Host (Linux) linuxNetstatActiveConnLogSource
Linux Secure Logs Standard Security Trace log files for Oracle Linux, Ubuntu File Host (Linux) LinuxSecureLogSource
Linux Syslog Logs Standard OS Syslog log files for Oracle Linux, Ubuntu File Host (Linux) LinuxSyslogSource
Linux YUM Logs Logs for operational functions of YUM (Yellowdog Updater Modified package manager) File Host (Linux) LinuxYUMLogSource
Logging Analytics Detection Rule Logs Derived Log Source for Log Analytics Detection Rule Logs Derived Nil LoggingAnalyticsDetectionRuleLogs
McAfee Data Loss Prevention Endpoint McAfee Data Loss Prevention Endpoint data stored in database Database Microsoft SQL Server Database Instance McAfeeDat aLossPreventionEndpoint
McAfee ePolicy Orchestrator McAfee ePolicy Orchestrator events stored in database Database Microsoft SQL Server Database Instance McAfeeePolicyOrchestrator
McAfee VirusScan Enterprise Logs Source that supports McAfee VSE local log files File Host (Windows), Host (Linux) McAfeeVSELogSource
Microsoft .Net Log4Net Logs Source that supports Log4Net's default log format File Microsoft .NET Server MicrosoftDotNetLog4NetLogSource
Microsoft Active Directory Distributed File System Replication Logs Microsoft Active Directory Distributed File System Replication Logs File Microsoft Active Directory MsftADDfsrLogSource
Microsoft Active Directory Installation Wizard Logs Microsoft Active Directory Installation Wizard Logs File Microsoft Active Directory MsftADDcpromoLogSource
Microsoft Active Directory Netsetup Logs Microsoft Active Directory Netsetup Logs File Microsoft Active Directory MsftADNetsetupLogSource
Microsoft Active Directory NtFrsApi Logs Microsoft Active Directory NtFrsApi Logs File Microsoft Active Directory MsftADNtFrsApiLogSource
Microsoft DHCP (IPv4) Logs Microsoft DHCP Log Source that supports the DHCP CSV format File Host (Windows) MicrosoftDHCPv4LogSource
Microsoft DHCP (IPv6) Logs Microsoft DHCP (IPv6) Log Source that supports the DHCPv6 CSV format File Host (Windows) MicrosoftDHCPv6LogSource
Microsoft DNS Logs Log files that capture Microsoft DNS activity File Microsoft DNS Server MsftDNSLogSource
Microsoft Exchange Active Monitoring Trace Logs Microsoft Exchange Log Source that supports Microsoft Exchange's Active Monitoring Trace log format File Microsoft Exchange MSExchangeActiveMonitoringTraceLogSource
Microsoft Exchange Authentication Admin Logs Microsoft Exchange Log Source that supports Microsoft Exchange's Authentication Admin log format File Microsoft Exchange MSExchangeAuthAdminLogSource
Microsoft Exchange Database Availability Logs Microsoft Exchange Log Source that supports Microsoft Exchange's Database Availability log format File Microsoft Exchange MSExchangeDatabaseAvailabilityLogSource
Microsoft Exchange Diagnostics Service Logs Microsoft Exchange Log Source that supports Microsoft Exchange's Diagnostics Service log format File Microsoft Exchange MSExchangeDiagnosticsServiceLogSource
Microsoft Exchange Outlook Web Access Probe Logs Microsoft Exchange Log Source that supports Microsoft Exchange's Outlook Web Access log format File Microsoft Exchange MSExchangeOWAProbeLogSource
Microsoft IIS Log Source for FTP format logs Microsoft IIS Log Files with FTP format File Microsoft Internet Information Services Web Site, Microsoft Internet Information Services MsftFtpLogSource
Microsoft IIS Log Source for IIS format logs Microsoft IIS Log Files with IIS format File Microsoft Internet Information Services Web Site MsftIisLogSource
Microsoft IIS Log Source for NCSA format logs Microsoft IIS Log Files with NCSA format File Microsoft Internet Information Services Web Site MsftNcsaLogSource
Microsoft IIS Log Source for W3C format logs Microsoft IIS Log Files with W3C format File Microsoft Internet Information Services Web Site MsftW3cLogSource
Microsoft SharePoint Logs SharePoint Log Source that supports ULS logging format File Microsoft SharePoint MicrosoftSharePointLogSource
Microsoft SQL Server Agent Error Log Microsoft SQL Server Agent Error Log Files File Microsoft SQL Server Database Instance MsftSQLServerAgentLogSource
Microsoft SQL Server Error Log Source Microsoft SQL Server Error Log Files File Microsoft SQL Server Database Instance MsftSQLServerErrorLogSource
MongoDB Logs MongoDB Log Source for the standard Mongo logging format File MongoDB MongoDBLogSource
MySQL Database Audit JSON Logs MySQL Audit logs capture database activity in structured JSON, detailing queries, users, and connections for compliance, monitoring, and security analysis. File MySQL Database Instance OracleMySQLAuditLogSource
MySQL Database Audit XML Logs MySQL Database Audit XML Logs File MySQL Database Instance MySQLAuditXMLLogSource
MySQL Error Logs MySQL Error Logs File MySQL Database Instance MySQLErrorLogSource
MySQL Error Logs Stored in Database MySQL Error Logs Stored in Database Database MySQL Database Instance MySQLErrorDBLogSource
MySQL General Log Source Stored in Database Source to fetch general_log table rows using specified sql stored in database Database MySQL Database Instance MySQLGeneralLogfromDBSource
MySQL General Query Logs MySQL General Query Logs File MySQL Database Instance MySQLGeneralQueryLogSource
MySQL OpenTelemetry Logs MySQL Error, General, Slow, and Audit logs collected in OpenTelemetry (OTel) format provide structured, standardized database telemetry for centralized observability. They capture operational events, warnings and failures, query performance/latency details, and user or security actions. OTel formatting enables consistent parsing, correlation, and analysis across services, improving troubleshooting, monitoring, and compliance reporting. OpenTelemetry Host (Linux) MySQLopenTelemetryLogs
MySQL Slow Query Logs MySQL Slow Query Logs File MySQL Database Instance MySQLSlowQueryLogSource
MySQL Slow Query Logs Stored in Database MySQL Slow Query Logs Stored in Database Database MySQL Database Instance MySQLSlowQueryDBLogSource
NetApp Syslog Logs Supports the NetApp syslog format. This source should be associated to the host where the OMC Agent will listen for syslog messages. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX) NetAppLogSource
NGINX Access Logs NGINX Load Balancer Access Logs File Nginx NGINXAccessLogSource
NGINX Error Logs NGINX Load Balancer Error Logs File Nginx NGINXErrorLogSource
Node.js Log4js Logs Node.js Log4js Logs are structured logs with timestamp, level, category, pid, and message that support MDC/context (e.g., reqId, userId), stack traces, rolling appenders, and console/HTTP outputs. Captures startup, routing, latency metrics, dependency errors, and unhandled exceptions for correlation. File Node.js NodejsLog4jsLogSource
NVD CVE API Logs Common Vulnerabilities and Exposures fetched through National Vulnerability Database CVE API REST API Host (Linux) nvdCveApiLogSource
NVidia Fabric Manager Log Fabric Manager Log files location on host excluding gz file types File Host (Linux) Nvidia_FabricManagerLogSource
NVIDIA GPU Health Check Logs NVIDIA GPU health check output in JSON format, including PCIe bus checks, GPU count verification, ECC status checks, and related health indicators. OS Command Host (Linux) nvidiaGPUHealthCheckLogSource
Nvidia Host Engine Logs Nvidia Host Engine Logs File Host (Linux) NvidiaHostEngineLogsource
NVIDIA System Management Interface Stats Logs NVIDIA System Management Interface (SMI) statistics with job details, collected by executing the nvidia-smi command OS Command Host (Linux) nvidiaSmiLogSource
Nvidia Validation Suite Logs Nvidia Validation Suite Logs File Host (Linux) NvidiaValidationSuiteLogSource
OC4J JVM Server logs Primary location of OC4J JVM Server log files File OC4J omc_OC4JLogSource
OC4J Web Site Access Logs OC4J Web Site Access Logs File OC4J omc_OC4JWebAccessLogSource
OCI Analytics Cloud (OAC) Audit Logs Oracle Analytics Cloud (OAC) Audit Logs record user and system actions affecting OAC configuration and access. Used for security monitoring, compliance, and change tracking (e.g., user login, role changes, resource updates). File OCI Analytics Cloud Instance ociAnalyticsCloudAuditLogSource
OCI Analytics Cloud (OAC) Diagnostic Logs OCI Analytics Cloud (OAC) Diagnostic Logs capture internal service and operational details for OAC. Used for troubleshooting, performance analysis, and service health monitoring (e.g., errors, warnings, processing events). File OCI Analytics Cloud Instance ociAnalyticsCloudDiagnosticLogSource
OCI API Gateway Access Logs OCI API Gateway Access Logs record a summary for every client request and response via the gateway: HTTP method, URI, protocol, status, response size, client IP, user agent, referrer, request duration, gateway OCID, and opcRequestId. Useful for usage analytics, auditing, and performance tracking. File OCI API Gateway ociApiGwAccessLogSource
OCI API Gateway Execution Logs Oracle Cloud Infrastructure API Gateway Execution Logs File OCI API Gateway ociApiGwExecLogSource
OCI Application Dependency Management Logs OCI Application Dependency Management (ADM) Logs File ADM Remediation Recipe ociAdmLogSource
OCI Application Performance Monitoring Dropped Logs OCI Application Performance Monitoring Dropped Logs File APM Domain ociAPMLogSource
OCI Audit Logs Oracle Cloud Infrastructure Audit Logs File Host (Linux) omc_ociAuditLogSource
OCI Cache Engine Logs OCI Cache is a fully managed Redis service engineered for exceptional scalability and consistent high availability to achieve submillisecond latency File OCI Cache ociCacheEngineLogSouce
OCI Cloud Guard Problems Oracle Cloud Infrastructure Cloud Guard Format from /ProblemSummary REST API endpoint. File OCI Cloud Guard ociCloudGuardRestAPILogSource
OCI Cloud Guard Query Results Logs OCI Cloud Guard Query Results Logs File OCI Cloud Guard ociCloudGuardQueryResultsLogSource
OCI Cloud Guard Raw Logs OCI Cloud Guard Raw Logs File OCI Cloud Guard ociCloudGuardRawLogSource
OCI Compute Cloud@Customer Infrastructure Logs Oracle Compute Cloud@Customer is a fully managed, rack-scale solution that brings OCI Compute and GPU services to on-premises data center. It enables cloud automation, GenAI workloads, and low-latency operations while meeting data residency and security needs. File Compute Cloud at Customer ociCCCInfraLogSource
OCI CPQ Performance Logs OCI CPQ (Configure, Price, Quote) performance logs record all user actions, including logins, logouts, commerce activities, and configuration changes. It captures both server and browser elapsed times, making these logs a vital resource for troubleshooting performance issues. REST API Oracle CPQ ociCpqPerformanceLogSource
OCI Data Flow Spark Diagnostic Logs Logs generated by the Apache Spark framework (driver and executors) File OCI Data Flow Application ociDataFlowSparkDiagLogs
OCI Data Integration Service Logs OCI Data Integration Service logs capture detailed records of data pipeline executions, including task runs, status, errors, and operational events. They provide visibility into data flows, enabling monitoring, troubleshooting, auditing, and performance analysis of integration activities within OCI environments. File Data Integration Service Workspace ociDataIntegrationServiceLogs
OCI Data Science Job Logs Data Science jobs enable custom tasks that you can apply any use case you have, such as data preparation, model training, hyperparameter tuning, batch inference, and so on File Data Science Job ociDataScienceJobLogSource
OCI Data Science ML Application Access Logs Oracle Cloud Infrastructure (OCI) Data Science ML Application Access Logs record incoming requests made to machine learning applications hosted in OCI Data Science. These logs help track application usage, monitor performance, and troubleshoot issues within deployed ML models. File Data Science ML Application Instance ociDSMLAppAccessLogSource
OCI Data Science Model Deployment Logs Model deployments are a managed resource in the OCI Data Science service to be used to deploy machine learning models as HTTP endpoints in OCI File Data Science Model Deployment ociDataScienceModelDeploymentLogSource
OCI Data Science Pipeline Resource Logs OCI Data Science Pipeline resource service logs capture operational events related to pipeline lifecycle management within the OCI Data Science service. These logs record actions such as pipeline creation, updates, deletions, step executions, state transitions, and failures. They help track orchestration behavior, execution status, dependency handling, and service-level errors. The logs are used for auditing, troubleshooting failed runs, monitoring automation workflows. File Data Science Pipeline ociDSPplResLogSource
OCI DevOps Build Logs Logs providing information on various OCI DevOps builds for all the pipelines inside a project File OCI DevOps Build Run ociDevOpsBuildLogSource
OCI DevOps Deployment Logs Logs providing information on various OCI DevOps deployments for all the pipelines inside a project File OCI DevOps Deployment ociDevOpsLogSource
OCI Edge WAF Caching Logs WAF Edge Caching Logs provide details on cache operations at the Edge WAF, such as hits, misses, and object statuses, supporting analysis of content delivery and cache policies. These logs are archived in OCI Object Storage after an SR is filed on the WAF service team and then must be collected into Log Analytics using an Object Collection Rule. File OCI Web Application Firewall ociEdgeWAFCachingLogSource
OCI Edge WAF Lua Logs WAF Edge Lua Logs capture activity from Lua scripts running on OCI’s Edge Web Application Firewall, including execution traces, custom rule actions, and diagnostics to help monitor and refine security policies. These logs are stored in OCI Object Storage after a Service Request (SR) with the WAF team and require setting up Log Analytics Object Collection Rule for further analysis or integration with security tools. File OCI Web Application Firewall ociEdgeWAFLuaLogSource
OCI Email Delivery Logs OCI Email Delivery Logs File OCI Email Delivery ociEmailDeliveryLogSource
OCI Events Logs Oracle Cloud Infrastructure (OCI) Event Logs capture records of system and resource activities, such as state changes, API calls, and alerts. They enable monitoring, troubleshooting, and auditing by providing structured, near real-time insights into events across OCI services. File OCI Events Service Rule ociEventsLogSource
OCI Function Logs Oracle Cloud Infrastructure Function logs capture execution details of serverless functions, including invocation events, input/output data, runtime messages, errors, and performance metrics, enabling monitoring, debugging, and analysis of function behavior within OCI environments. File OCI Function ociFunctionLogsSource
OCI GoldenGate Error Logs OCI GoldenGate Error Logs File GoldenGate Deployment ociGoldenGateErrorLogSource
OCI GoldenGate Process Logs GoldenGate Process Logs (Contains logs from Administration Service, Distribution Service, Performance Metrics Service, Receiver Service, Extract/Replicate Events, etc) File GoldenGate Deployment ociGoldenGateProcessLogSource
OCI Integration - HITL Activity Stream Logs OCI Integration Human in the Loop (HITL) activity stream logs capture workflow task activity, assignments, approvals, payloads, and process state changes for auditing, monitoring, and troubleshooting. File OIC Integration ociHitlAuditLogSource
OCI Integration Activity Stream Logs Oracle Cloud Infrastructure Integration (OIC) Activity Stream logs capture detailed records of integration flow executions, including triggers, processing steps, message exchanges, statuses, and errors, enabling monitoring, troubleshooting, and auditing of integration activities within OCI environments. File OIC Integration ociIntegrationActStreamLogSource
OCI Key Management Crypto Logs Oracle Cloud Infrastructure (OCI) Key Management Service (KMS) allows users to manage and control encryption keys for data stored in OCI. File Vault ociKeyMgmtCryptoLogSource
OCI Load Balancer Access Logs OCI Load Balancer Access logs record details of client requests processed by the load balancer, including source and destination information, request methods, response codes, latency, and traffic statistics, enabling monitoring, performance analysis, and troubleshooting of application traffic within OCI environments. File OCI Load Balancer ociLoadBalancerAccessLogSource
OCI Load Balancer Error Logs Oracle Cloud Infrastructure Load Balancer Error Logs File OCI Load Balancer ociLoadBalancerErrorLogSource
OCI Media Flow Service Logs OCI Media Flow Service Logs File Media Workflow Job, Media Workflow ociMediaFlowLogSource
OCI Network Firewall Threat Logs OCI Network Firewall Threat Logs File Network Firewall ociNetworkFirewallThreatLogSource
OCI Network Firewall Traffic Logs OCI Network Firewall Traffic Logs File Network Firewall ociNetworkFirewallTrafficLogSource
OCI Network Firewall Tunnel Logs OCI Network Firewall Tunnel Logs File Network Firewall ociNetworkFirewallTunnelInspectionLogSource
OCI Object Storage Access Logs Oracle Cloud Infrastructure Object Storage Service Access Logs File OCI Object Storage Bucket ociObjectStorageAccessLogSource
OCI PostgreSQL Service Logs OCI PostgreSQL JSON service logs provide structured log records generated by the managed PostgreSQL service in Oracle Cloud Infrastructure. These logs capture database events such as connections, queries, errors, and system activities in JSON format, enabling efficient parsing, monitoring, troubleshooting, and integration with log analytics and security monitoring tools. File PostgreSQL Database ociPostgreSQLServiceLogSource
OCI Private DNS Resolver Logs Oracle Cloud Infrastructure (OCI) DNS is a cloud native DNS service that serves both internet-facing and internal requests. It can globally load balance and steer requests based on multiple characteristics. File DNS Server ociDNSResolverLogSource
OCI Service Connector Hub Logs OCI Service Connector Hub Run Logs File OCI Service Connector ociServiceConnectorHubLogSource
OCI Site-to-Site VPN Logs OCI Site-to-Site VPN logs contain all status-related information of the IPSec tunnels associated with the site-to-site type of IPSec connections. This includes bringing of tunnels up or down, and accompanying negotiation information. Each IPSec connection has two IPSec tunnels created, thus the Site-to-Site VPN logs will contain status on both tunnels File IPSec Tunnel ociSite2SiteVPNLogSource
OCI Unified Schema Logs Logs coming in OCI Unified Schema format File Host (Linux) ociUnifiedSchemaLogSource
OCI VCN Flow Logs Oracle Cloud Infrastructure VCN Flow Logs (Legacy) File Host (Linux), OCI VCN Virtual Network Interface Card omc_ociVcnFlowLogSource
OCI VCN Flow Unified Schema Logs Oracle Cloud Infrastructure VCN Flow Logs in Unified Schema Format File OCI VCN Virtual Network Interface Card ociVcnFlowUniFmtLogSource
OCI WAF Logs Oracle Cloud Infrastructure Web Application Firewall Logs File OCI Web Application Firewall ociWAFLogSource
OCI Web Application Accelerator Logs OCI Web Application Accelerator(WAA) Logs File OCI Load Balancer ociWaaLogSource
OIC Audit Logs Oracle Integration Cloud Audit Logs File OCI Integration Instance ICSAuditLogSource
OIC Diagnostic Logs Oracle Integration Cloud Diagnostic Logs File OCI Integration Instance ICSDiagnosticLogSource
OIC Flow Logs Oracle Integration Cloud Flow Logs File OCI Integration Instance ICSFlowLogSource
OKE Control Plane Logs OKE Control Plane Logs File Kubernetes Cluster ociOkeControlPlaneLogSource
OKE Proxymux Client Logs Oracle Kubernetes Engine (OKE) Proxymux Client Logs File Kubernetes Cluster ociOkeProxymuxClientLogSource
OMC Compliance Assessment Result Logs Captures Oracle Management Cloud Compliance Assessment Result logs File Host (Linux) OMC_Compliance_Log_Source_Name
OMC Orchestration Service Output Logs Captures Oracle Management Cloud Orchestration Service orchestration job output logs. File Host (Linux), Host (Solaris), Host (AIX), Host (Windows) orcl_orchestration_output_source
OMC Security Monitoring Analytics Service Logs Captures Oracle Management Cloud Security Monitoring Analytics service derived events. File Host (Linux), Host (Solaris), Host (AIX), Host (Windows) orcl_sma_output_source
OpenTelemetry Logs Default source for collecting OTLP (JSON-encoded) based OpenTelemetry (OTEL) Logs conforming to CNCF (Cloud Native Computing Foundation) OpenTelemetry Host (Linux) openTelemetryLogs
Oracle Access Governance Cloud Service Diagnostic Logs Oracle Access Governance is a cloud service (AGCS) that delivers policy-driven access provisioning to help you manage access risks across applications, clouds, machines, and databases. File Access Governance Instance ociAgcsDiagnosticLogSource
Oracle Access Manager Audit Logs Oracle Access Manager Audit Logs File Oracle Access Management Server FmwOamAuditLogSource
Oracle Autonomous Database (ADB) Client Errors Provides real-time details of client-side communication errors encountered by Oracle Database sessions, including network, protocol, or internal client issues. It helps identify connection problems, handshake failures, and transient client faults useful for diagnostics, auditing, and SIEM correlation of session-level client communication anomalies. Database Autonomous Transaction Processing, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Data Warehouse db_client_errors
Oracle Cloud Security Access Broker Logs Standard Oracle Cloud Security Access Broker Logs. File Host (AIX), Host (Linux), Host (Solaris), Host (Windows) CasbSource
Oracle Database Dataguard Logs Oracle Database Dataguard Logs. Verified on Oracle DB 19c Database Oracle Database Instance, Autonomous Transaction Processing, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development dbDataguardLogsSource
Oracle Database Health Monitor Service Logs Oracle Database Health Monitor Service Logs. Verified on Oracle DB 19c Database Oracle Database Instance, Autonomous Transaction Processing, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development dbHealthMonitorServiceLogsSource
Oracle Database Session Creation Logs The DB session log source combines data from Oracle’s V$SESSION and V$SESSION_CONNECT_INFO views to track real-time and active user connections. It captures essential session attributes—usernames, schemas, client identifiers, logon times, and authentication details—enabling the user to monitor database access patterns, connection origins, and session behavior for audit and security analytics. Database Oracle Database, Oracle Database Instance oracleDBSessionLogSource
Oracle DB Audit Log Source Stored in Database Source to fetch audit logs using specified sql stored in database Database Oracle Database Instance, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing dbauditlogfromdbsource
Oracle Delegate Access Control Logs Delegate Access Control (DaCtl) enables Oracle Exadata on Cloud@Customer and Dedicated Infrastructure to subscribe to maintenance/support services, delegate access to providers, and control when they can access VM and database resources. File Operator Access Control for Autonomous Database Dedicated on ExaCC, Oracle Delegation Control ociOracleDelegateAccessControlLogSource
Oracle EBS Transaction Logs Collect E-Business Suite Transaction Logs from the database table fnd_log_messages Database Oracle Database Instance, Oracle Pluggable Database, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing transactionlogsfororacleebs
Oracle GoldenGate Admin Server Logs Defines how to process Admin Server logs for Oracle GoldenGate File GoldenGate Admin Server omc_ogg_admin_server_log_source
Oracle GoldenGate Distribution Server Logs Defines how to process Distribution Server logs for Oracle GoldenGate File GoldenGate Distribution Server omc_ogg_distribution_server_log_source
Oracle GoldenGate Extract/Replicat Event Logs Defines how to process Extract/Replicat Event logs for Oracle GoldenGate File GoldenGate Deployment omc_ogg_er_event_log_source
Oracle GoldenGate GGS Error Logs Defines how to process GGS Error logs for Oracle GoldenGate File GoldenGate Deployment, GoldenGate omc_ogg_ggs_error_log_source
Oracle GoldenGate Manager Report Classic Logs Defines how to process Manager Report Files for Oracle GoldenGate File GoldenGate Manager omc_ogg_manager_report_log_source
Oracle GoldenGate Performance Metric Server Logs Defines how to process Performance Metric Server logs for Oracle GoldenGate File GoldenGate Performance Metric Server omc_ogg_pm_server_log_source
Oracle GoldenGate Receiver Server Logs Defines how to process Receiver Server logs for Oracle GoldenGate File GoldenGate Receiver Server omc_ogg_receiver_server_log_source
Oracle GoldenGate Service Manager Logs Defines how to process Service Manager logs for Oracle GoldenGate File GoldenGate Service Manager omc_ogg_service_manager_log_source
Oracle Management Agent Logs Logs generated by the Oracle Management Agent File Management Agent OrclMgmtAgentLogSource
Oracle Operator Access Control Logs Oracle Operator Access Control (OpCtl) is a compliance audit system that enables customers to grant, audit, and revoke access that Oracle has to their Exadata infrastructure, including Exadata Cloud@Customer, Exadata Cloud, and Autonomous Database on Exadata Cloud@Customer systems. File Operator Access Control for Autonomous Database Dedicated on ExaCC ociOracleOperatorAccessControlLogSource
Oracle Unified Audit Trail Stored in Cloud Database Retrieves unified audit logs using specified sql stored in a cloud database Database Autonomous Data Warehouse, Autonomous Transaction Processing unifiedauditlogfromclouddb
Oracle Unified DB Audit Log Source Stored in Database 12.1 Source to fetch audit logs using specified sql stored in database 12.1 Database Oracle Database Instance, Oracle Pluggable Database, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing unifieddbauditlogfromdbsource121
Oracle Unified DB Audit Log Source Stored in Database 12.2 Source to fetch audit logs using specified sql stored in databases version above 12.1 (Includes 12.2, 19c, ATP and ADW) Database Oracle Database Instance, Oracle Pluggable Database, Autonomous Transaction Processing, Autonomous Data Warehouse, Oracle Database, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development unifieddbauditlogfromdbsource122
Oracle Unified Directory Access Logs Oracle Unified Directory (OUD) Access Logs File Oracle Unified Directory oudAccessLogSource
Oracle Unified Directory Admin Logs Oracle Unified Directory (OUD) Admin Logs File Oracle Unified Directory oudAdminLogSource
Oracle Unified Directory Errors Logs Oracle Unified Directory (OUD) Errors Logs File Oracle Unified Directory oudErrorsLogSource
Oracle VM Manager Access Logs Oracle VM Manager Access Logs File Oracle VM Manager OVMManagerAccessLogSource
Oracle VM Manager Diagnostic Logs Oracle VM Manager Diagnostic Logs ODL Oracle VM Manager OVMManagerDiagLogSource
Oracle VM Manager Logs Oracle VM Manager Logs File Oracle VM Manager OVMManagerLogSource
Oracle VM Manager STDOUT Logs Oracle VM Manager STDOUT Logs File Oracle VM Manager OVMManagerOutSource
Palo Alto Syslog CEF Logs Palo Alto log source which supports the syslog CEF listener format Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) PaloAltoSyslogCEFListenerSource
Palo Alto Syslog Logs Palo Alto log source which supports the syslog listener format Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) PaloAltoSyslogListenerSource
PeopleSoft Analytics Engine Server Logs PeopleSoft Analytics Engine Server Logs File PSFT Process Scheduler Domain PeoplesoftAnalyticEngineServerLogSource
PeopleSoft Application Analytics Engine Server Logs PeopleSoft Application Analytics Engine Server Logs File PSFT Process Scheduler Domain PeoplesoftAppAnalyticEngineServerLogSource
PeopleSoft Application server domain Application Server (APPSRV) Process Logs PeopleSoft Application server domain Application Server (APPSRV) Process Logs File PSFT Application Server Domain PSFTAppServerDomainAPPSRVLogSource
PeopleSoft Application server domain Monitor Server (MONITORSRV) Process Logs PeopleSoft Application server domain Monitor Server (MONITORSRV) Process Logs File PSFT Application Server Domain PSFTAppServerDomainMonitorSRVLogSource
PeopleSoft Application server domain Watch Server (WATCHSRV) Process Logs PeopleSoft Application server domain Watch Server (WATCHSRV) Process Logs File PSFT Application Server Domain PSFTAppServerDomainWatchSRVLogSource
PeopleSoft Application Tuxedo Access Logs PeopleSoft Application Tuxedo Access Logs File PSFT Application Server Domain PSFTAppServerTuxAccessLogSource
PeopleSoft Application Tuxedo User Logs PeopleSoft Application Tuxedo User Logs File PSFT Application Server Domain PSFTAppServerTuxLogSource
PeopleSoft Integration Gateway Error Logs PeopleSoft Integration Gateway Error Logs File PSFT PIA PeoplesoftIntegrationGatewayErrorLogSource
PeopleSoft Integration Gateway Message Logs PeopleSoft Integration Gateway Message Logs File PSFT PIA PeoplesoftIntegrationGatewayMsgLogSource
PeopleSoft Master Scheduler Server Logs PeopleSoft Master Scheduler Server Logs File PSFT Process Scheduler Domain PeoplesoftMasterSchedulerServerLogSource
PeopleSoft Process Scheduler App Engine Server Logs PeopleSoft Process Scheduler App Engine Server Logs File PSFT Process Scheduler Domain PSFTProcessSchedulerAppEngineLogSource
PeopleSoft Process Scheduler Distribution Agent Logs PeopleSoft Process Scheduler Distribution Agent Logs File PSFT Process Scheduler Domain PSFTProcessSchedulerDistAgentLogSource
PeopleSoft Process Scheduler Master Scheduler Logs PeopleSoft Process Scheduler Master Scheduler Logs File PSFT Process Scheduler Domain PSFTProcessSchedulerMasterSchedulerLogSource
PeopleSoft WLS Server Access Logs PeopleSoft WLS Server Access Logs. File PSFT PIA PSFTWlsServerAccessLogSourc
PeopleSoft WLS Server Logs PeopleSoft WLS Server Logs. File PSFT PIA PiaWlsServerLogSource
PeopleSoft WLS Server STDOUT Logs PeopleSoft WLS Server STDOUT Logs. File PSFT PIA PiaWlsServerOutSource
PeopleSoft WLS Servlet Logs PeopleSoft WLS Servlet Logs File PSFT PIA PiaWlsServletLogSource
PostgreSQL Logs PostgreSQL Error Logs cover authentication failures, deadlocks, checkpoints, auto vacuum, resource exhaustion, and startup/shutdown diagnostics etc.,— ideal for alerting, forensics, and performance troubleshooting. File PostgreSQL Database PostgreSQLLogSource
QRadar LEEF Syslog Listener Source QRadar LEEF Direct Syslog Listener Source Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) QradarSyslogSource
SAP Application Startup Logs SAP Application Startup Logs File SAPNW Application Server Instance SAPStartupLogSource
SAP Application Transport Logs SAP Application Transport Logs File SAPNW Application Server Instance SAPTransportLogSource
SAP Dev Dispatcher Logs SAP Dev Dispatcher Logs File SAPNW Application Server Instance SAPDevDispLogSource
SAP Dev ICM Security Logs SAP Dev ICM Security Logs File SAPNW Application Server Instance SAPDevICMLogSource
SAP Dev Message Server Logs SAP Dev Message Server Logs File SAPNW Application Server Instance SAPDevMSLogSource
SAP Dev RD Logs SAP Dev RD Gateway Trace Logs File SAPNW Application Server Instance SAPDevRDLogSource
SAP Java Server Applications Logs Source to fetch SAP Java Server Applications Logs File SAPNW Application Server JAVA Server Process SapJavaServerAppVSource
SAP Java Server Default Trace Logs Source to fetch SAP Java Server Default Trace Logs File SAPNW Application Server JAVA Server Process SapJavaDefaultServerSource
SAP VMC Available Logs SAP VMC Available Logs File SAPNW Application Server Instance SAPVMCAvailableLogSource
Siebel Component Logs All Siebel Component Logs File Siebel Component OrclSiebelComponentSource
Siebel Gateway Name Server Audit Logs Siebel Gateway Name Server Audit Logs File Siebel Gateway Server OrclSiebelGatewayAuditSourceNew
Siebel Gateway Name Server Logs Siebel Gateway Name Server Logs File Siebel Gateway Server OrclSiebelGatewayServerSourceNew
Siebel Server Logs Siebel Server Logs File Siebel Server OrclSiebelSrvrSource
Slurm Job Status Logs Logs that provide a point-in-time view of a Slurm job’s allocation, resource usage, and execution state. OS Command Host (Linux) slurmScontrolJobLogSource
Slurm Node Status Logs Logs that provide a point-in-time view of each Slurm node’s configuration, resources, and current state. OS Command Host (Linux) slurmScontrolNodeLogSource
Solaris Audit Logs Standard OS Audit log files for Solaris File Host (Solaris) SolarisAuditSource
Solaris Cron Logs Standard OS Cron log files for Solaris File Host (Solaris) SolarisCronSource
Solaris ILOM Configuration Logs Log files that store configuration activity for Solaris ILOMS File Host (Solaris) SolarisILOMConfigLogSource
Solaris Install Logs Logs for Solaris installation operations File Host (Solaris) SolarisInstallLogSource
Solaris SMF Daemon Logs Logs for Solaris Service Management Facility (SMF) File Host (Solaris) SolarisSMFDaemonLogSource
Solaris SU Logs Logs that capture SU (switch user) activity File Host (Solaris) SolarisSUlogSource
Solaris Syslog Logs Standard OS Syslog log files for Solaris File Host (Solaris) SolarisSyslogSource
Squid Proxy Access Logs Files that store Squid Proxy Access Logs File Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX) SquidLogSource
Squid Proxy Syslog Listener Source Squid Proxy Syslog Listener Source Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) omc_squidProxySyslogSource
SUDO Logs Log files that capture SUDO activity, running a command as another user File Host (Linux) SudoLogSource
SUSE Secure Logs SUSE security logs. By default it also includes logs from sudo, sshd, pamd. File Host (Linux) omc_SuseSecureLogSource
SUSE Syslog Logs Standard OS Syslog logs for SUSE. By default, it also includes cron logs. File Host (Linux) omc_SuseSyslogSource
Symantec DLP Syslog Listener Logs Symantec DLP log source which supports the syslog listener format. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX), Host (Windows) SymantecDLPSyslogListenerLogs
Symantec DLP System Events Symantec DLP system event data stored in an Oracle database Database Oracle Database Instance, Oracle Database, Autonomous Data Warehouse, Autonomous JSON Database, Autonomous Database with the Oracle APEX Application Development, Autonomous Transaction Processing omc_SymantecDBDLPSystemEvents
Symantec Endpoint Protection Syslog Listener Logs Symantec Endpoint Protection log source which supports the syslog listener format. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (HP-UX), Host (Windows) SymantecEndpointProtectionSyslogListenerLogs
Symantec Endpoint Protection System Syslog Logs Standard system syslog files for Symantec Endpoint Protection. Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) omc_SymantecEPPSystemSyslogSource
Traefik Proxy Access Logs Traefik Access Logs capture per-request details for traffic handled by the proxy. These logs are critical for auditing, troubleshooting, traffic analysis, and detecting anomalies. File Traefik Proxy Server traefikProxyAccessLogSource
Traefik Proxy Logs Traefik Logs record internal proxy events such as startup, configuration changes, certificate updates, service health checks, and errors. They help administrators monitor Traefik’s state, diagnose issues, and ensure stability. File Traefik Proxy Server traefikProxyLogSource
TrendMicro Syslog Common Event Format Logs TrendMicro log source that supports the syslog Comment Event Format Syslog Listener Host (Linux), Host (AIX), Host (Solaris), Host (Windows) TrendMicroSyslogCefListenerSource
Tuxedo Application User Logs Tuxedo Application User Logs File Oracle Tuxedo Application Server tuxedoAppUserLogsLogSource
Ubuntu Secure Logs Ubuntu security logs. By default it also includes logs from sudo, sshd, pamd. File Host (Linux) UbuntuSecureLogSource
Ubuntu Syslog Logs Standard OS Syslog logs for Ubuntu. By default, it also includes cron logs. File Host (Linux) UbuntuSyslogSource
Unidentified Logs This source to be used when we receive invalid source during processing File Host (Linux) orcl_unidentified_logs_source
Unix HTTP Server Access Logs Access log files for Web Server that is installed as part of Unix installation. File Host (Linux) WebServerAccessLogSource
Unix HTTP Server Error Logs Error log files for Web Server that is installed as part of Unix installation. File Host (Linux) WebServerErrorLogSource
Unix HTTP Server SSL Access Logs SSL Access log files for Web Server that is installed as part of Unix installation. File Host (Linux) WebServerSSLAccessLogSource
Unix HTTP SSL Request Logs SSL Request log files for Web Server that is installed as part of Unix installation. File Host (Linux) WebServerSSLRequestLogSource
Unprocessed Logs Messages that track requests which were not processed by Log Analytics service File Host (Linux) ociUnprocessedLogsSource
VMWare vSphere Alarms Alarms collected from VMWare vSphere vCenter File VMware vSphere Cluster, VMware vSphere Data Center, VMware vSphere Data Store, VMware vSphere ESXi Host, VMware vSphere Resource Pool, VMware vSphere vApp, VMware vSphere vCenter, VMware vSphere VM VMWareVSphereAlarmsSource
VMWare vSphere Events VMWare vSphere Events File VMware vSphere Cluster, VMware vSphere Data Center, VMware vSphere Data Store, VMware vSphere ESXi Host, VMware vSphere Resource Pool, VMware vSphere vApp, VMware vSphere vCenter, VMware vSphere VM VMWareVSphereEventsSource
VMWare vSphere Metrics VMWare vSphere Metrics File VMware vSphere Cluster, VMware vSphere Data Center, VMware vSphere Data Store, VMware vSphere ESXi Host, VMware vSphere Resource Pool, VMware vSphere vApp, VMware vSphere vCenter, VMware vSphere VM VMWareVSPhereMetricsSource
VMWare vSphere Syslog Logs VMWare vSphere Syslog log files for VMWare Syslog Listener Host (Linux) VMWareVSphereSyslogSource
Windows Application Events Collects events from the Windows Event Subsystem for the Application channel as log entries Windows Event System Host (Windows) MsftWinEventApplicationLogSource
Windows Security Events Collects events from the Windows Event Subsystem for the Security Channel as log entries Windows Event System Host (Windows) MsftWinEventSecurityLogSource
Windows Setup Events Collects events from the Windows Event Subsystem for the Setup Channel as log entries Windows Event System Host (Windows) MsftWinEventSetupLogSource
Windows System Events Collects events from the Windows Event Subsystem for the System Channel as log entries Windows Event System Host (Windows) MsftWinEventSystemLogSource