All Apps and Add-ons

How to integrate Oracle Secure Global Desktop (SGD) logs in Splunk and make them CIM compatible?

pinVie
Path Finder

Hi all,

Has any one of you integrated logs from Oracle SGD?

Actual integration is easily done via Syslog, but making sense of all these logs is really hard.
I'm currently trying to make these logs CIM compatible, but I don't really know how to do this without proper documentation - and afaik there is no documentation regarding the logs.

Have you already done this, is there a Splunk app, do you know of any documentation? - all information is helpful.

Thank you !

chris
Motivator

Hi pinVie did you manage to integrate those logs? Any chance of sharing what logs you integrated? Regards Chris

0 Karma

tmuth_splunk
Splunk Employee
Splunk Employee

I used to work at Oracle and spent a LOT of time as a user of SGD, though I know little about the admin side. However, here are some doc links to get you started if you haven't already found them:

Global Table of Contents for 5.2: http://docs.oracle.com/cd/E51728_01/index.html
Monitoring and Logging Section: http://docs.oracle.com/cd/E51728_01/E51731/html/monitoring-logging.html
Gateway Logging and Diagnostics: http://docs.oracle.com/cd/E51728_01/E51733/html/gateway-logging-diagnostics.html
Enterprise Manager Plugin (might give you an idea what to monitor): http://docs.oracle.com/cd/E51728_01/E52284/html/plugin-monitoring.html
EM Plugin > Metrics Definitions: http://docs.oracle.com/cd/E51728_01/E52284/html/plugin-metrics-ref.html
Web Service API > Datastore > Item Constants (might define some ambiguous items): http://docs.oracle.com/cd/E51728_01/E51735/html/constant-values.html#com.tarantella.tta.webservices....

Wish I had an "easy-button" for you, but hopefully this will move you one step closer.

woodcock
Esteemed Legend
0 Karma

pinVie
Path Finder

Yes I do know splunkbase - thank you.
But if I am not wrong there is no app for Oracle SGD on splunkbase, right?

0 Karma

woodcock
Esteemed Legend

Not under "SGD" and when I typed in the whole phrase, I got tired of clicking after 5 pages. You should be more motivated than I am, though, to click all the way through.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...