Splunk® Supported Add-ons

Splunk Add-on for Oracle Database

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Release notes for the Splunk Add-on for Oracle Database

Version 4.0.1 of the Splunk Add-on for Oracle Database was released on April 29, 2021.

About this release

Version 4.0.1 of the Splunk Add-on for Oracle Database is compatible with the following software, CIM versions, and platforms.

Splunk platform versions 8.0, 8.1
Splunk DB Connect 3.4.2
CIM 4.19
Platforms Platform independent
Vendor Products Oracle Database Server 11g/12.1/12.2/18c/19c

Splunk DB Connect version 2.x reached its End of Life on July 7, 2019

New features

Version 4.0.1 of the Splunk Add-on for Oracle Database includes the following new features:

  • Support for Oracle Database versions 12.2, 18c and 19c.
  • Two new sourcetypes:
    • oracle:sqlMonitor, mapped to the Databases CIM Data Model.
      • Sample event:
        SQL_ID="8fa50m2ggqmkh", SQL_EXEC_START="2021-02-04 3:50:53", SQL_EXEC_ID=16778066, KEY=25769804773, USERNAME="SYS", MACHINE="C3382290435", DATABASE_NAME="MORAL", ELAP_PER_EXEC="11389380.83", SQL_TEXT="SELECT * FROM ( SELECT CAST((event_timestamp at TIME zone 'UTC') AS TIMESTAMP) A_EVENT_TIMESTAMP_UTC,u.* FROM UNIFIED_AUDIT_TRAIL u) WHERE A_EVENT_TIMESTAMP_UTC > :1 ORDER BY A_EVENT_TIMESTAMP_UTC ASC", RECORDS_AFFECTED=2299, TABLES_HIT="ALL_UNIFIED_AUDIT_ACTIONS, AUD$UNIFIED, X$UNIFIED_AUDIT_TRAIL", INDEXES_HIT="I_STMT_AUDIT_OPTION_MAP, I_SYSTEM_PRIVILEGE_MAP, I_UNIFIED_AUDIT_ACTIONS", CPU_TIME="19790610", FETCHES="1", BUFFER_GETS="738282", DISK_READS="5963", DIRECT_WRITES="2276", APPLICATION_WAIT_TIME="82099", CONCURRENCY_WAIT_TIME="0", CLUSTER_WAIT_TIME="0", USER_IO_WAIT_TIME="17882604", PLSQL_EXEC_TIME="0", JAVA_EXEC_TIME="0", BANNER_FULL="Oracle Database 19c Enterprise Edition Release 19.0.0.0.0 - Production Version 19.3.0.0.0"
    • oracle:connections:poolStats, mapped to the Databases CIM Data Model.
      • Sample event:
        HOST_NAME="ca8e7f53acb8", INSTANCE_NAME="MORAL", CONNECTION_POOL="SYS_DEFAULT_CONNECTION_POOL", STATUS="ACTIVE", MAXSIZE="40", NUM_REQUESTS="0", NUM_HITS="0", NUM_MISSES="0", NUM_WAITS="0", CON_ID="0"
  • Removed search time extractions of the host field. This affects the following sourcetypes:
    • oracle:instance
    • oracle:session
    • oracle:sysPerf
    • oracle:connections
    • oracle:pool:connections
    • oracle:database:size
    • oracle:table
    • oracle:user
    • oracle:query

The value of the host field will be the same as the host field value provided at the time of your connection in Splunk DB Connect. For example, sourcetypes oracle:database or oracle:tablespace.

  • Common Information Model (CIM) enhancements:
    • Support for version 4.19.
    • Data Model mapping was updated for the following sourcetypes:
      • oracle:instance
      • oracle:session
      • oracle:tablespaceMetrics
      • oracle:sysPerf
      • oracle:connections
      • oracle:pool:connections
      • oracle:table
      • oracle:database:size
      • oracle:user
      • oracle:audit:text
      • oracle:audit:xml

Fixed issues

Version 4.0.1 of the Splunk Add-on for Oracle Database contains the following fixed issues.


Date resolved Issue number Description
2021-03-04 ADDON-33553 active_pooled_connections for sourcetype oracle:pool:connections is always 0
2021-02-24 ADDON-28810, ADDON-28812 Invalid extraction for host
2021-02-11 ADDON-28812, ADDON-28810 Eventtypes based on ORACODE is not being extracted

Known issues

Version 4.0.1 of the Splunk Add-on for Oracle Database contains the following known issues.


Third-party software attributions

Version 4.0.1 of the Splunk Add-on for Oracle Database does not incorporate any third-party software or libraries.

Last modified on 29 April, 2021
PREVIOUS
Source types for the Splunk Add-on for Oracle Database
  NEXT
Release history of the Splunk Add-on for Oracle Database

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters