Splunk Search

Observing Oracle Forms on the net

simuvid
Splunk Employee
Splunk Employee

Hi all,

I want to do following task with Splunk:

I want to monitor and audit if a user or customer touches an Oracle Form in a WebServer.

What I need to know is:

Who opened and manipulated an Oracle Form?

What was done/manipulated in the Form?

Follow the transaction path?

For the transaction path, does anybody know if there is a unique ID in Oracle Forms, which can be used to track transactions?

Any feedback and shared experience is highly appreciated.

Cheers,

Christian

Tags (2)
0 Karma

cfrantsen
Explorer

While I haven't worked with Oracle Forms I know that alot of other oracle software (OC4J, WebCache, OHS, SOA, etc) utilize something called Execution Context ID (ECID) which is used to track transaction.

I have previously used this for stuff like finding out what request in the access_log generated a specific cluster of errors in the error_log.

simuvid
Splunk Employee
Splunk Employee

Hi Johnvey,

unfortunately I do not have logfile examples right now.

My question was if somebody has some kind of experience how to trace transactions within Oracle Forms Server or if somebody knows about unique ID's.

I will try to catch some examples and share with you.

Cheers,

Christian

0 Karma

Johnvey
Contributor

If you post an example block of logs from the Oracle Forms server, that'll provide a much better starting point for people to try and construct a search.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...