Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

OCI Data Connector requires cursor group with static name but is not documented

Open PCNZ opened this issue 1 year ago • 20 comments

Describe the bug Deploy the Oracle Cloud Infrastructure (OCI) data connector and function app as per the instructions. Function app cannot connect to OCI as the instruction's mis a step - the cursor group name in the OCI stream configuration must be hard coded to be group1. https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Oracle%20Cloud%20Infrastructure/Data%20Connectors/AzureFunctionOCILogs/main.py Within the python script is where the name group1 is hard coded.

To Reproduce Deploy the OCI data connector as per instructions, get errors and function app does not collect logs.

Expected behavior Steps in data connector and guides which mention what the cursor type value should be set to when deploying the function app and prior to this when creating the stream in OCI. Ideally provide a way to specify the cursor group name as a variable for the function app - so it's not hard coded to group1.

Please update these pages with clear instructions. https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Oracle%20Cloud%20Infrastructure/Data%20Connectors/azuredeploy_OCI_logs_API_FunctionApp.json and https://docs.oracle.com/en/learn/oci-logs-ms-azure-sentinel/index.html#introduction

Screenshots Function app, New fields - cursor type and message limit - required but not documented. image image

Additional context Cursor type was added to the python code around January 2023 but the instructions were not updated.

PCNZ avatar Oct 12 '23 07:10 PCNZ

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Oct 12 '23 07:10 github-actions[bot]

Hi @PCNZ, thanks for flagging this, we will get back to you by 17 Oct 2023.

v-rbajaj avatar Oct 13 '23 06:10 v-rbajaj

Hi @PCNZ ,After initial analysis, noticed that the issue exists and will work on issue resolution and ETA is 02Nov23

v-muuppugund avatar Oct 30 '23 11:10 v-muuppugund

Hi @PCNZ , raised PR for it https://github.com/Azure/Azure-Sentinel/pull/9329 and waiting for approval, will update you once done by 06Nov23.

v-muuppugund avatar Nov 02 '23 11:11 v-muuppugund

Hi @PCNZ, Hope you are doing well. The PR review still in progress, we will share an update with you. Once the review is done. Thanks!

v-sudkharat avatar Nov 06 '23 12:11 v-sudkharat

Hi @PCNZ , This PR review still is in progress, we will share an update with you.once the review is done.Thanks!

v-muuppugund avatar Nov 08 '23 12:11 v-muuppugund

@PCNZ The above PR is still under internal review,will post updates by 14Nov23

v-muuppugund avatar Nov 10 '23 09:11 v-muuppugund

@PCNZ The above PR is still under internal review,will post updates by 17Nov23

v-muuppugund avatar Nov 14 '23 10:11 v-muuppugund

@PCNZ ,The above PR is under internal review ,will post updates by 21Nov23

v-muuppugund avatar Nov 17 '23 06:11 v-muuppugund

@PCNZ ,Working on internal review changes ,will get back to you 24Nov23

v-muuppugund avatar Nov 21 '23 07:11 v-muuppugund

@PCNZ Will update you once the PR is completed

v-muuppugund avatar Nov 24 '23 11:11 v-muuppugund

@PCNZ ,just want to update there are review comments for ARM template changes and code changes, so completed the changes, locally testing it, so once done. Will push to live, will keep you updated, Thanks.

v-muuppugund avatar Dec 15 '23 13:12 v-muuppugund

@PCNZ Apologies for the delayed response,will be sharing the package for today eod for testing ,so will proceed with the pushing it

v-muuppugund avatar Jan 04 '24 04:01 v-muuppugund

@PCNZ Apologies for the delayed response,will be sharing the package for today eod for testing ,so will proceed with the pushing it

@PCNZ yesterday didn't get chance to share the package,today will share it

v-muuppugund avatar Jan 05 '24 04:01 v-muuppugund

@PCNZ Apologies for the delayed response,will be sharing the package for today eod for testing ,so will proceed with the pushing it

@PCNZ yesterday didn't get chance to share the package,today will share it

HI @PCNZ , Apologies for delay in my end as blocked with high priority work,Please follow the below steps

  1. Please use ARM template (https://github.com/Azure/Azure-Sentinel/blob/users/v-muppugundu/OCIDocumentationupdates/Solutions/Oracle%20Cloud%20Infrastructure/Data%20Connectors/azuredeploy_OCI_logs_API_FunctionApp.json) and enter cursor type as group then Group Name and Group Instance Name mandatory
  2. Deploy the new function app with Group instance and Group name created in oracle if needed we can have a call to explain in detail

v-muuppugund avatar Jan 06 '24 08:01 v-muuppugund

Hi @PCNZ, I hope you are doing well. We are waiting for your response on above comment. Thanks!

v-sudkharat avatar Jan 10 '24 09:01 v-sudkharat

Hi @PCNZ , Gentle Reminder,Could you please check on the above steps and share updates,I have scheduled call on Monday for Oracle AMA issue updates,We can discuss on that call,thanks.

v-muuppugund avatar Jan 12 '24 15:01 v-muuppugund

Hi @PCNZ ,I have blocked calendar yesterday ,but unable to connect with you as you have declined ,Will block calendar again for testing this and close it from my end,Thanks.

v-muuppugund avatar Jan 16 '24 09:01 v-muuppugund

Hi @PCNZ ,As discussed over teams, blocked calendar in teams, Please let me know if this time isn't convenient.

v-muuppugund avatar Jan 21 '24 10:01 v-muuppugund

Hi @PCNZ ,as discussed yesterday over call, as you have don't have license and sdk based call,so need to test this package,will test with another customer and will update you once completed.

v-muuppugund avatar Jan 25 '24 04:01 v-muuppugund

@PCNZ , today have a call with another customer who having oracle license ,will update you post the call.

v-muuppugund avatar Mar 19 '24 23:03 v-muuppugund

@PCNZ , tested the issue with the cx i.e. (https://github.com/Azure/Azure-Sentinel/issues/10013) it worked, but unable to proceed to get results as cx having another issue,so will merge this pr with that issue i.e. ((https://github.com/Azure/Azure-Sentinel/issues/10013)),will update you once merged in the same issue,. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation!

v-muuppugund avatar Mar 20 '24 05:03 v-muuppugund