Use Oracle Log Analytics for Large Activity Stream Payloads
You can publish your activity stream logs to Oracle Log Analytics. This is useful if your activity stream payload is large, because Oracle Cloud Infrastructure (OCI) public logging limits the size of log files.
You must be subscribed to Oracle Log Analytics to publish your activity stream logs there.
- Publish Oracle Integration Logs to Oracle Log Analytics
- Publish Human in the Loop Logs to Oracle Log Analytics
To learn about the benefits of storing human in the loop logs in Oracle Log Analytics, see Why Publish Human in the Loop Logs to Log Analytics?.
Publish Oracle Integration Logs to Oracle Log Analytics
To publish the Oracle Integration activity stream logs to Oracle Log Analytics, perform the following tasks:
If you later decide to stop storing activity stream logs in Oracle Log Analytics, you can disable it for your Oracle Integration instance. See Disable Storing Logs in Oracle Log Analytics.
Create a Log Group to Store Your Logs in Oracle Log Analytics
To create a log group in Oracle Log Analytics to store your Oracle Integration activity stream logs, perform the following steps:
- In the Oracle Cloud Console, open the navigation menu and click Observability & Management, then, under Log Analytics, click Administration.
- On the Log Groups page, in the menu on the left, click Log Groups.
- Next to Applied filters, make sure you're viewing the compartment in which you want to create the log group.
- Click Create Log Group.
- Enter a name (for example,
OracleIntegration_ActivityStream_LogGroup) and description. - Click Create.
Create a Policy to Allow Log Uploads from Oracle Integration
To create a policy to allow log uploads from Oracle Integration, perform the following steps:
- If you haven't already done so, sign in to the Oracle Cloud Console.
- Get the client ID for your Oracle Integration instance:
- In the Oracle Cloud Console navigation menu, click Identity & Security, then, under Identity, click Domains.
- Open the domain in which you created your Oracle Integration instance.
If you don't see the domain, make sure you're in the correct region (in the banner) and you're viewing the correct compartment (in the filters).
- In the tabs across the top, click Oracle cloud services.
- Open your Oracle Integration instance.
If you have trouble finding your instance, searching for "Integration" might narrow down your choices.
- In the tabs across the top, click OAuth configuration.
- Scroll down to the General information section, and copy the Client ID.
- Create a dynamic group to be used in the policy:
- Go back to your domain by clicking Oracle cloud services at the top of the page.
- In the tabs across the top, click Dynamic groups.
- Click Create dynamic group.
- Enter a Name (for example,
OracleIntegration_LogAnalytics_DynamicGroup) and Description for the group. - In the Rule 1 box, enter the following rule.
Syntax:
resource.id='OracleIntegration_ClientID'
Where:OracleIntegration_ClientIDis the client ID you copied in step 2
Example:resource.id='A01BC23DE4567FGH89I0123456J78901_APPID'
- Create the policy:
- In the left navigation pane, click Policies.
- Click Create Policy.
- Enter a name (for example,
OracleIntegration_LogUploadPolicy) and description for the policy. - Click Show manual editor.
- Enter the following permissions.
Syntax:
allow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment LogGroup_Compartmentallow dynamic-group DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancyallow dynamic-group DynamicGroup to use loganalytics-ondemand-upload in tenancyallow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy
Where:DynamicGroupis the dynamic group you created in step 3LogGroup_Compartmentis the compartment in which you created the log group
Example:allow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment OracleIntegration_LogGroup_Compartmentallow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancyallow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to use loganalytics-ondemand-upload in tenancyallow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy
Create a Policy to Allow Users to View Logs in Oracle Log Analytics
To create a policy to allow users to view logs in Oracle Log Analytics, perform the following steps:
- Create a group for the users you want to be able to view the activity stream logs in Oracle Log Analytics:
- In the left navigation pane, click Domains.
- Open the domain in which you created your Oracle Integration instance.
If you don't see the domain, make sure you're in the correct region (in the banner) and you're viewing the correct compartment (in the filters).
- In the tabs across the top, click User management.
- Scroll down to the Groups section, and click Create group.
- Enter a Name (for example,
OracleIntegration_LogAnalytics_Group) and Description for the group. - Add users to the group.
- Click Create.
- Create the policy:
- In the left navigation pane, click Policies.
- Click Create Policy.
- Enter a Name (for example,
OracleIntegration_LogAnalyticsAccessPolicy) and Description for the policy. - Click Show manual editor.
- In the editor, enter the following permissions.
Syntax:
allow group UserGroup to use loganalytics-features-family in tenancyallow group UserGroup to use loganalytics-resources-family in tenancy
Where:UserGroupis the group you created in step 1
Example:allow group OracleIntegration_LogAnalytics_Group to use loganalytics-features-family in tenancyallow group OracleIntegration_LogAnalytics_Group to use loganalytics-resources-family in tenancy
Enable the Option to Publish Logs to Oracle Log Analytics
To enable storing Oracle Integration activity stream logs in Oracle Log Analytics, perform the following steps:
- Get the OCID for the log group you created:
- In the Oracle Cloud Console navigation menu, click Observability & management, then, under Log analytics, click Administration.
- In the left navigation pane, click Log Groups.
- Next to the log group you created for Oracle Integration, click
, then click Copy OCID.
If you don't see the log, make sure you're viewing the correct compartment (in the left menu).
- Enable the option:
- In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
- Open your Oracle Integration instance.
If you don't see the instance you're looking for, make sure you're viewing the correct region (in the banner) and compartment (at the top of the instance list, next to Applied filters).
- Under Settings, next to OCI Log Analytics, click Enable.
- Paste the OCID you copied into the Log group OCID box, and then click Update.
The service instance status changes to Updating. When it's finished, the status changes to Active, and, under OCI Log Analytics, you see that log analytics is enabled. You also see a new entry for Integration log group, which shows the log group OCID.
Disable Storing Logs in Oracle Log Analytics
If you want to stop storing activity stream logs in Oracle Log Analytics, you can disable it for your Oracle Integration instance.
- In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
- Open your Oracle Integration instance.
If you don't see your instance, make sure you're viewing the correct compartment (in the left menu).
- Under OCI Log Analytics, next to OCI Log Analytics, click Disable.
You'll be asked to confirm your action.
The service instance status changes to Updating. When it's finished, the status changes to Active, and OCI Log Analytics shows Not enabled.
Publish Human in the Loop Logs to Oracle Log Analytics
If you later decide to stop storing activity stream logs for human in the loop in Oracle Log Analytics, you can disable it for your Oracle Integration instance. See Disable Storing Human in the Loop Logs in Oracle Log Analytics.
Why Publish Human in the Loop Logs to Log Analytics?
Human in the Loop Runtime Data Retention
Human in the loop runtime data is stored within Oracle Integration and is governed by the data retention setting configured for the Oracle Integration instance. This retention setting determines how long workflow runtime data and associated task history remain available after a workflow instance reaches a terminal state.
- Standard edition: 32 days
- Enterprise edition: 32 days, 93 days, or 184 days, depending on the configured retention setting
- Healthcare edition: 184 days
- Completed
- Faulted
- Expired
- Terminated
After the configured retention period has elapsed, the workflow instance and its associated task history are automatically deleted from Oracle Integration.
Standard Data Retention vs. Long-Term Audit Requirements
The standard data retention period is generally sufficient for routine workflow management and analysis, such as monitoring recent workflow executions, investigating failures, reviewing task activity, and troubleshooting issues.
However, the standard data retention period may not be sufficient for long-term audit, compliance, or governance requirements.
Business processes such as financial approvals, HR decisions, and regulated workflows may need to remain reconstructible for several years. Organizations may need to demonstrate what occurred during a process, when specific activities took place, and how the workflow progressed even long after the original human in the loop workflow instance and its task history have been purged from Oracle Integration.
This creates an important distinction between standard data retention and long-term audit retention. Standard data retention retains workflow data primarily to support routine workflow management and analysis, whereas audit and compliance requirements may require data to be retained for a significantly longer period.
Extend Auditability by Publishing Logs to Oracle Log Analytics
Enabling log publishing to Oracle Log Analytics provides a mechanism for addressing this long-term retention requirement.
Once log publishing is enabled, human in the loop events are sent to a log group owned by your organization within your OCI tenancy. The retention period for this log data can be configured independently according to your organization’s operational, audit, and compliance requirements.
- Long-term retention: Human in the loop event data can outlive the workflow instance itself, supporting historical analysis, audit reconstruction, and compliance requirements.
- Centralized observability: The workflow event data resides alongside your other OCI observability data, allowing it to be managed and analyzed as part of the organization’s broader logging and monitoring strategy rather than remaining isolated in a silo.
Operational Visibility with Dashboards
From an operational perspective, every state change is logged with a rich set of contextual fields, including workflow, task, assignee, approver, outcome, duration, due date, and priority. This level of detail provides greater visibility into workflow execution and makes it easier to answer operational questions that can be difficult to analyze directly from within the workspace.
The dashboard feature brings this information together in a consolidated visual format, enabling you to gain insights into workflow and task activity without having to write individual queries. For example, dashboards can help answer questions such as:
- How many tasks are currently open, and who are they assigned to?
- Which workflows generate the highest volume of approval requests?
- What is the average processing time for each workflow, from task creation through completion?
- How frequently do approvers approve or reject tasks, and what comments do they provide with their decisions?
- Which workflow instances have faulted or expired, and where in the workflow did these conditions occur?
To learn how you can view dashboards, see View Dashboards in Using Human in the Loop in Oracle Integration 3.
Investigate Logs with Log Explorer
Use Log Explorer in Oracle Log Analytics to search and inspect published human in the loop activity stream logs. Log Explorer is useful to investigate a specific workflow instance or answer specific questions from audit or compliance teams.
For example, if you need information about a workflow instance from a specific period, you can select the applicable time range, search for the instance, and use the available fields and query capabilities to examine the relevant activity stream records.
To learn how you can view logs, see View Logs in Using Human in the Loop in Oracle Integration 3.
Create a Log Group to Store Human in the Loop Logs in Oracle Log Analytics
This log group should be different from the log group created for Oracle Integration. The log group should be specific to human in the loop.
To create a log group in Oracle Log Analytics to store your human in the loop activity stream logs, perform the following steps:
- In the Oracle Cloud Console, open the navigation menu and click Observability & Management, then, under Log Analytics, click Administration.
- On the Log Groups page, in the menu on the left, click Log Groups.
- Next to Applied filters, make sure you're viewing the compartment in which you want to create the log group.
- Click Create Log Group.
- Enter a name (for example,
ActivityStream_LogGroup) and description. - Click Create.
Create a Policy to Allow Log Uploads from Human in the Loop
To create a policy to allow log uploads from human in the loop, perform the following steps:
- If you haven't already done so, sign in to the Oracle Cloud Console.
- Get the OCID for your human in the loop instance:
- In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
- Open the Oracle Integration instance in which human in the loop is enabled.
If you don't see the instance you're looking for, make sure you're viewing the correct region (in the banner) and compartment (at the top of the instance list, next to Applied filters).
- On the Integration instance details page, under Human in the Loop section, copy the OCID (value that uniquely identifies the Process Automation instance).
- Create a dynamic group to be used in the policy:
- Go back to your domain by clicking Oracle cloud services at the top of the page.
- In the tabs across the top, click Dynamic groups.
- Click Create dynamic group.
- Enter a Name (for example,
LogAnalytics_DynamicGroup) and Description for the group. - In the Rule 1 box, enter the following rule.
Syntax:
-
resource.id='Humanintheloop_OCID'
Where:-
Humanintheloop_OCIDis the OCID you copied in step 2
-
- Create the policy:
- In the left navigation pane, click Policies.
- Click Create Policy.
- Enter a name (for example,
LogUploadPolicy) and description for the policy. - Click Show manual editor.
- Enter the following permissions.
Syntax:
-
allow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment LogGroup_Compartment -
allow dynamic-group DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancy -
allow dynamic-group DynamicGroup to use loganalytics-ondemand-upload in tenancy -
allow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy
Where:-
DynamicGroupis the dynamic group you created in step 3 -
LogGroup_Compartmentis the compartment in which you create a log group to store human in the loop logs in Oracle Log Analytics
Example:-
allow dynamic-group LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment LogGroup_Compartment -
allow dynamic-group LogAnalytics_DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancy -
allow dynamic-group LogAnalytics_DynamicGroup to use loganalytics-ondemand-upload in tenancy -
allow dynamic-group LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy
-
Enable the Option to Publish Human in the Loop Logs to Oracle Log Analytics
If you've not enabled storing Oracle Integration activity stream logs in Oracle Log Analytics already, then you need to enable it by performing the steps described in Enable the Option to Publish Logs to Oracle Log Analytics before you enable storing human in the loop logs in Oracle Log Analytics.
To enable storing human in the loop activity stream logs in Oracle Log Analytics, perform the following steps:
- Get the OCID for the log group you created:
- In the Oracle Cloud Console navigation menu, click Observability & management, then, under Log analytics, click Administration.
- In the left navigation pane, click Log Groups.
- Next to the log group you created for human in the loop, click
, then click Copy OCID.
If you don't see the log, make sure you're viewing the correct compartment (in the left menu).
- Enable the option:
- In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
- Open your Oracle Integration instance.
If you don't see the instance you're looking for, make sure you're viewing the correct region (in the banner) and compartment (at the top of the instance list, next to Applied filters).
- Under OCI Log Analytics, next to Human in the Loop, click Enable.
- Paste the OCID you copied into the Log group OCID box, and then click Update.
The service instance status changes to Updating. When it's finished, the status changes to Active, and, under OCI Log Analytics, you see that log analytics is enabled for Human in the Loop. You also see a new entry for Human in the Loop log group, which shows the log group OCID.
A parser (defining how to parse the log file into log entries and how to parse the log entries into fields) is automatically created. To see the parser, perform the following steps:- In the Oracle Cloud Console navigation menu, click Observability & management, then, under Log analytics, click Administration.
- In the left navigation pane, click Parsers.
On the Parsers page, the list of available parsers are listed.
- You can click the parser created for human in the loop to see which element in the log is mapped to which element in log analytics.
Disable Storing Human in the Loop Logs in Oracle Log Analytics
If you want to stop storing activity stream logs for human in the loop in Oracle Log Analytics, you can disable it for your Oracle Integration instance.
- In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
- Open your Oracle Integration instance.
If you don't see your instance, make sure you're viewing the correct compartment (in the left menu).
- Under OCI Log Analytics, next to Human in the Loop, click Disable.
You'll be asked to confirm your action.
The service instance status changes to Updating. When it's finished, the status changes to Active, and Human in the Loop shows Not enabled.