Stratégies créées lors de l'intégration de Log Analytics

En tant que nouvel utilisateur, si vous voulez commencer à utiliser Oracle Log Analytics, accédez à Observabilité et gestion à partir du menu de la console OCI, cliquez sur Log Analytics, puis sur Démarrer à l'aide de Log Analytics sur la page d'intégration. L'assistant crée automatiquement des stratégies pour activer Oracle Log Analytics et configurer la collecte des journaux d'audit OCI.

Les stratégies suivantes sont créées :

  • logging_analytics_automatic_service_policies

    Cette stratégie permet d'activer Oracle Log Analytics et inclut les instructions suivantes :

    define tenancy sampledata as <sampledata_tenancy_OCID>
    endorse group Administrators to read loganalytics-features-family in tenancy sampledata
    endorse group Administrators to read loganalytics-resources-family in tenancy sampledata
    endorse group Administrators to read compartments in tenancy sampledata
    allow service loganalytics to READ loganalytics-features-family in tenancy
    allow service loganalytics to READ compartments in tenancy
  • logging_analytics_automatic_ingestion_policies

    La stratégie permet de configurer la collecte des journaux d'audit OCI et inclut les instructions suivantes :

    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {EVENTRULE_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {LOAD_BALANCER_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {BUCKET_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to read functions-family in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to read api-gateway-family in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {VNIC_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {APPROVED_SENDER_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {IPSEC_CONNECTION_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {WEB_APP_FIREWALL_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to read operator-control-family in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {NETWORK_FIREWALL_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {DEVOPS_DEPLOYMENT_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {DEVOPS_DEPLOY_PIPELINE_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {DEVOPS_DEPLOY_STAGE_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {APM_DOMAIN_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {SERVICE_CONNECTOR_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {DATAFLOW_APPLICATION_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {MEDIA_WORKFLOW_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {MEDIA_WORKFLOW_JOB_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {CLUSTER_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {GOLDENGATE_DEPLOYMENT_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {CG_DATA_SOURCE_READ} in tenancy
    allow resource loganalyticsvrp LogAnalyticsVirtualResource to {POSTGRES_DB_SYSTEM_READ} in tenancy
    allow any-user to {LOG_ANALYTICS_LOG_GROUP_UPLOAD_LOGS} in compartment id <compartment_OCID> where all {request.principal.type='serviceconnector', target.loganalytics-log-group.id='<target_log_group_OCID>',request.principal.compartment.id='<compartment_OCID>'}