Use Oracle Log Analytics for Large Activity Stream Payloads

You can publish your activity stream logs to Oracle Log Analytics. This is useful if your activity stream payload is large, because Oracle Cloud Infrastructure (OCI) public logging limits the size of log files.

Note

You must be subscribed to Oracle Log Analytics to publish your activity stream logs there.

Publish Oracle Integration Logs to Oracle Log Analytics

To publish the Oracle Integration activity stream logs to Oracle Log Analytics, perform the following tasks:

Create a Log Group to Store Your Logs in Oracle Log Analytics

To create a log group in Oracle Log Analytics to store your Oracle Integration activity stream logs, perform the following steps:

  1. In the Oracle Cloud Console, open the navigation menu and click Observability & Management, then, under Log Analytics, click Administration.
  2. On the Log Groups page, in the menu on the left, click Log Groups.
  3. Next to Applied filters, make sure you're viewing the compartment in which you want to create the log group.
  4. Click Create Log Group.
  5. Enter a name (for example, OracleIntegration_ActivityStream_LogGroup) and description.
  6. Click Create.

Create a Policy to Allow Log Uploads from Oracle Integration

To create a policy to allow log uploads from Oracle Integration, perform the following steps:

  1. If you haven't already done so, sign in to the Oracle Cloud Console.
  2. Get the client ID for your Oracle Integration instance:
    1. In the Oracle Cloud Console navigation menu, click Identity & Security, then, under Identity, click Domains.
    2. Open the domain in which you created your Oracle Integration instance.

      If you don't see the domain, make sure you're in the correct region (in the banner) and you're viewing the correct compartment (in the filters).

    3. In the tabs across the top, click Oracle cloud services.
    4. Open your Oracle Integration instance.

      If you have trouble finding your instance, searching for "Integration" might narrow down your choices.

    5. In the tabs across the top, click OAuth configuration.
    6. Scroll down to the General information section, and copy the Client ID.
  3. Create a dynamic group to be used in the policy:
    1. Go back to your domain by clicking Oracle cloud services at the top of the page.
    2. In the tabs across the top, click Dynamic groups.
    3. Click Create dynamic group.
    4. Enter a Name (for example, OracleIntegration_LogAnalytics_DynamicGroup) and Description for the group.
    5. In the Rule 1 box, enter the following rule.
      Syntax:
      • resource.id='OracleIntegration_ClientID'
      Where:
      • OracleIntegration_ClientID is the client ID you copied in step 2
      Example:
      • resource.id='A01BC23DE4567FGH89I0123456J78901_APPID'
  4. Create the policy:
    1. In the left navigation pane, click Policies.
    2. Click Create Policy.
    3. Enter a name (for example, OracleIntegration_LogUploadPolicy) and description for the policy.
    4. Click Show manual editor.
    5. Enter the following permissions.
      Syntax:
      • allow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment LogGroup_Compartment
      • allow dynamic-group DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancy
      • allow dynamic-group DynamicGroup to use loganalytics-ondemand-upload in tenancy
      • allow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy
      Where:
      Example:
      • allow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment OracleIntegration_LogGroup_Compartment
      • allow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancy
      • allow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to use loganalytics-ondemand-upload in tenancy
      • allow dynamic-group OracleIntegration_LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy

Create a Policy to Allow Users to View Logs in Oracle Log Analytics

To create a policy to allow users to view logs in Oracle Log Analytics, perform the following steps:

  1. Create a group for the users you want to be able to view the activity stream logs in Oracle Log Analytics:
    1. In the left navigation pane, click Domains.
    2. Open the domain in which you created your Oracle Integration instance.

      If you don't see the domain, make sure you're in the correct region (in the banner) and you're viewing the correct compartment (in the filters).

    3. In the tabs across the top, click User management.
    4. Scroll down to the Groups section, and click Create group.
    5. Enter a Name (for example, OracleIntegration_LogAnalytics_Group) and Description for the group.
    6. Add users to the group.
    7. Click Create.
  2. Create the policy:
    1. In the left navigation pane, click Policies.
    2. Click Create Policy.
    3. Enter a Name (for example, OracleIntegration_LogAnalyticsAccessPolicy) and Description for the policy.
    4. Click Show manual editor.
    5. In the editor, enter the following permissions.
      Syntax:
      • allow group UserGroup to use loganalytics-features-family in tenancy
      • allow group UserGroup to use loganalytics-resources-family in tenancy
      Where:
      • UserGroup is the group you created in step 1
      Example:
      • allow group OracleIntegration_LogAnalytics_Group to use loganalytics-features-family in tenancy
      • allow group OracleIntegration_LogAnalytics_Group to use loganalytics-resources-family in tenancy

Enable the Option to Publish Logs to Oracle Log Analytics

To enable storing Oracle Integration activity stream logs in Oracle Log Analytics, perform the following steps:

  1. Get the OCID for the log group you created:
    1. In the Oracle Cloud Console navigation menu, click Observability & management, then, under Log analytics, click Administration.
    2. In the left navigation pane, click Log Groups.
    3. Next to the log group you created for Oracle Integration, click Actions icon, then click Copy OCID.

      If you don't see the log, make sure you're viewing the correct compartment (in the left menu).

  2. Enable the option:
    1. In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
    2. Open your Oracle Integration instance.

      If you don't see the instance you're looking for, make sure you're viewing the correct region (in the banner) and compartment (at the top of the instance list, next to Applied filters).

    3. Under Settings, next to OCI Log Analytics, click Enable.
    4. Paste the OCID you copied into the Log group OCID box, and then click Update.

      The service instance status changes to Updating. When it's finished, the status changes to Active, and, under OCI Log Analytics, you see that log analytics is enabled. You also see a new entry for Integration log group, which shows the log group OCID.

Disable Storing Logs in Oracle Log Analytics

If you want to stop storing activity stream logs in Oracle Log Analytics, you can disable it for your Oracle Integration instance.

  1. In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
  2. Open your Oracle Integration instance.

    If you don't see your instance, make sure you're viewing the correct compartment (in the left menu).

  3. Under OCI Log Analytics, next to OCI Log Analytics, click Disable.

    You'll be asked to confirm your action.

    The service instance status changes to Updating. When it's finished, the status changes to Active, and OCI Log Analytics shows Not enabled.

Publish Human in the Loop Logs to Oracle Log Analytics

To learn about the benefits of publishing human in the loop logs to Oracle Log Analytics, see Why Publish Human in the Loop Logs to Log Analytics?. To publish human in the loop activity stream logs to Oracle Log Analytics, perform the following tasks:

Why Publish Human in the Loop Logs to Log Analytics?

Human in the Loop Runtime Data Retention

Human in the loop runtime data is stored within Oracle Integration and is governed by the data retention setting configured for the Oracle Integration instance. This retention setting determines how long workflow runtime data and associated task history remain available after a workflow instance reaches a terminal state.

The retention period is:
  • Standard edition: 32 days
  • Enterprise edition: 32 days, 93 days, or 184 days, depending on the configured retention setting
  • Healthcare edition: 184 days
Only Enterprise edition instances support increasing the default retention period, up to a maximum of six months.
The retention period begins when a workflow instance reaches a terminal state. Workflow instances that are still active are not subject to automatic purging. Once an instance transitions to one of the following terminal states, however, the retention countdown begins:
  • Completed
  • Faulted
  • Expired
  • Terminated

After the configured retention period has elapsed, the workflow instance and its associated task history are automatically deleted from Oracle Integration.

Standard Data Retention vs. Long-Term Audit Requirements

The standard data retention period is generally sufficient for routine workflow management and analysis, such as monitoring recent workflow executions, investigating failures, reviewing task activity, and troubleshooting issues.

However, the standard data retention period may not be sufficient for long-term audit, compliance, or governance requirements.

Business processes such as financial approvals, HR decisions, and regulated workflows may need to remain reconstructible for several years. Organizations may need to demonstrate what occurred during a process, when specific activities took place, and how the workflow progressed even long after the original human in the loop workflow instance and its task history have been purged from Oracle Integration.

This creates an important distinction between standard data retention and long-term audit retention. Standard data retention retains workflow data primarily to support routine workflow management and analysis, whereas audit and compliance requirements may require data to be retained for a significantly longer period.

Extend Auditability by Publishing Logs to Oracle Log Analytics

Enabling log publishing to Oracle Log Analytics provides a mechanism for addressing this long-term retention requirement.

Once log publishing is enabled, human in the loop events are sent to a log group owned by your organization within your OCI tenancy. The retention period for this log data can be configured independently according to your organization’s operational, audit, and compliance requirements.

As a result, the published event data is no longer dependent on the lifecycle of the original workflow instance. Even after a human in the loop instance and its task history have been removed from Oracle Integration under the configured data retention setting, the corresponding published log data can remain available according to the retention period you configure when enabling log publishing to Oracle Log Analytics.
  • Long-term retention: Human in the loop event data can outlive the workflow instance itself, supporting historical analysis, audit reconstruction, and compliance requirements.
  • Centralized observability: The workflow event data resides alongside your other OCI observability data, allowing it to be managed and analyzed as part of the organization’s broader logging and monitoring strategy rather than remaining isolated in a silo.
For organizations with extended audit or regulatory requirements, publishing human in the loop logs to Oracle Log Analytics provides a long-term storage for human in the loop event data beyond the lifecycle of the underlying workflow instance.

Operational Visibility with Dashboards

From an operational perspective, every state change is logged with a rich set of contextual fields, including workflow, task, assignee, approver, outcome, duration, due date, and priority. This level of detail provides greater visibility into workflow execution and makes it easier to answer operational questions that can be difficult to analyze directly from within the workspace.

The dashboard feature brings this information together in a consolidated visual format, enabling you to gain insights into workflow and task activity without having to write individual queries. For example, dashboards can help answer questions such as:

  • How many tasks are currently open, and who are they assigned to?
  • Which workflows generate the highest volume of approval requests?
  • What is the average processing time for each workflow, from task creation through completion?
  • How frequently do approvers approve or reject tasks, and what comments do they provide with their decisions?
  • Which workflow instances have faulted or expired, and where in the workflow did these conditions occur?
These insights provide a consolidated view of workflow operations, making it easier to monitor workloads, understand approval patterns, evaluate processing times, and identify workflow execution issues.

To learn how you can view dashboards, see View Dashboards in Using Human in the Loop in Oracle Integration 3.

Investigate Logs with Log Explorer

Use Log Explorer in Oracle Log Analytics to search and inspect published human in the loop activity stream logs. Log Explorer is useful to investigate a specific workflow instance or answer specific questions from audit or compliance teams.

For example, if you need information about a workflow instance from a specific period, you can select the applicable time range, search for the instance, and use the available fields and query capabilities to examine the relevant activity stream records.

To learn how you can view logs, see View Logs in Using Human in the Loop in Oracle Integration 3.

Create a Log Group to Store Human in the Loop Logs in Oracle Log Analytics

Note

This log group should be different from the log group created for Oracle Integration. The log group should be specific to human in the loop.

To create a log group in Oracle Log Analytics to store your human in the loop activity stream logs, perform the following steps:

  1. In the Oracle Cloud Console, open the navigation menu and click Observability & Management, then, under Log Analytics, click Administration.
  2. On the Log Groups page, in the menu on the left, click Log Groups.
  3. Next to Applied filters, make sure you're viewing the compartment in which you want to create the log group.
  4. Click Create Log Group.
  5. Enter a name (for example, ActivityStream_LogGroup) and description.
  6. Click Create.

Create a Policy to Allow Log Uploads from Human in the Loop

To create a policy to allow log uploads from human in the loop, perform the following steps:

  1. If you haven't already done so, sign in to the Oracle Cloud Console.
  2. Get the OCID for your human in the loop instance:
    1. In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
    2. Open the Oracle Integration instance in which human in the loop is enabled.

      If you don't see the instance you're looking for, make sure you're viewing the correct region (in the banner) and compartment (at the top of the instance list, next to Applied filters).

    3. On the Integration instance details page, under Human in the Loop section, copy the OCID (value that uniquely identifies the Process Automation instance).
  3. Create a dynamic group to be used in the policy:
    1. Go back to your domain by clicking Oracle cloud services at the top of the page.
    2. In the tabs across the top, click Dynamic groups.
    3. Click Create dynamic group.
    4. Enter a Name (for example, LogAnalytics_DynamicGroup) and Description for the group.
    5. In the Rule 1 box, enter the following rule.
      Syntax:
      • resource.id='Humanintheloop_OCID'
      Where:
      • Humanintheloop_OCID is the OCID you copied in step 2
  4. Create the policy:
    1. In the left navigation pane, click Policies.
    2. Click Create Policy.
    3. Enter a name (for example, LogUploadPolicy) and description for the policy.
    4. Click Show manual editor.
    5. Enter the following permissions.
      Syntax:
      • allow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment LogGroup_Compartment
      • allow dynamic-group DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancy
      • allow dynamic-group DynamicGroup to use loganalytics-ondemand-upload in tenancy
      • allow dynamic-group DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy
      Where:
      Example:
      • allow dynamic-group LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment LogGroup_Compartment
      • allow dynamic-group LogAnalytics_DynamicGroup to {LOG_ANALYTICS_SOURCE_READ} in tenancy
      • allow dynamic-group LogAnalytics_DynamicGroup to use loganalytics-ondemand-upload in tenancy
      • allow dynamic-group LogAnalytics_DynamicGroup to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in tenancy

Enable the Option to Publish Human in the Loop Logs to Oracle Log Analytics

Note

If you've not enabled storing Oracle Integration activity stream logs in Oracle Log Analytics already, then you need to enable it by performing the steps described in Enable the Option to Publish Logs to Oracle Log Analytics before you enable storing human in the loop logs in Oracle Log Analytics.

To enable storing human in the loop activity stream logs in Oracle Log Analytics, perform the following steps:

  1. Get the OCID for the log group you created:
    1. In the Oracle Cloud Console navigation menu, click Observability & management, then, under Log analytics, click Administration.
    2. In the left navigation pane, click Log Groups.
    3. Next to the log group you created for human in the loop, click Actions icon, then click Copy OCID.

      If you don't see the log, make sure you're viewing the correct compartment (in the left menu).

  2. Enable the option:
    1. In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
    2. Open your Oracle Integration instance.

      If you don't see the instance you're looking for, make sure you're viewing the correct region (in the banner) and compartment (at the top of the instance list, next to Applied filters).

    3. Under OCI Log Analytics, next to Human in the Loop, click Enable.
    4. Paste the OCID you copied into the Log group OCID box, and then click Update.

      The service instance status changes to Updating. When it's finished, the status changes to Active, and, under OCI Log Analytics, you see that log analytics is enabled for Human in the Loop. You also see a new entry for Human in the Loop log group, which shows the log group OCID.

    A parser (defining how to parse the log file into log entries and how to parse the log entries into fields) is automatically created. To see the parser, perform the following steps:
    1. In the Oracle Cloud Console navigation menu, click Observability & management, then, under Log analytics, click Administration.
    2. In the left navigation pane, click Parsers.

      On the Parsers page, the list of available parsers are listed.

    3. You can click the parser created for human in the loop to see which element in the log is mapped to which element in log analytics.

Disable Storing Human in the Loop Logs in Oracle Log Analytics

If you want to stop storing activity stream logs for human in the loop in Oracle Log Analytics, you can disable it for your Oracle Integration instance.

  1. In the Oracle Cloud Console navigation menu, click Developer Services, then, under Application Integration, click Integration.
  2. Open your Oracle Integration instance.

    If you don't see your instance, make sure you're viewing the correct compartment (in the left menu).

  3. Under OCI Log Analytics, next to Human in the Loop, click Disable.

    You'll be asked to confirm your action.

    The service instance status changes to Updating. When it's finished, the status changes to Active, and Human in the Loop shows Not enabled.