Oracle WebLogic & Logsign Unified SecOps Platform Integration via Syslog(rsyslog)

Important, read before configuring: the steps below (Configuration Audit Type) only enable WebLogic's own configuration-change audit trail; they do not produce output that either of Logsign's WebLogic parsers can read. Source-code review of the current parsers shows they expect:

  • The JSON parser expects WebLogic's HTTP access log in Extended Log Format, with fields named c_ip, cs_method, cs_uri_stem, cs_uri_query, cs_Referer, cs_User_Agent, sc_status, and time_taken — this is a W3C-style HTTP access log, not a general server/domain/audit log.
  • The plain-text parser expects narrow session-open/session-close style messages, not general Domain/Application log entries.

To get logs Logsign can actually parse, enable WebLogic's HTTP access log instead of (or in addition to) the Configuration Audit Type setting below:

  1. In the WebLogic Console, go to Environment > Servers > <your server> > Logging > HTTP.
  2. Enable HTTP access logging, and set the format to Extended (not Common).
  3. Under the Extended Logging Format Fields, add at minimum: c-ip, cs-method, cs-uri-stem, cs-uri-query, cs(Referer), cs(User-Agent), sc-status, and time-taken, matching the fields listed above.
  4. Save and activate the changes.

This has not been independently tested against a live WebLogic instance for this guide; it is based on reading the parser source and WebLogic's own documented Extended Log Format support. If the resulting logs still don't parse as expected, contact Logsign Support with a sample log line so the parser mapping can be confirmed or corrected.


Log Forwarding on Oracle Weblogic;

Logging needs to be enabled before routing can be done. The following procedure is followed for this process;

1- It is entered into the user interface of Oracle Weblogic Console.

2- Go to Domain>Configuration>General

3- In the Advanced tab go to Configuration Audit Type and select Change Log and Audit.

4- Click on Save button.

For the Domain Logging;

1- It is entered into the user interface of Oracle Weblogic Console.

2- Go to Domain>Configuration>General

3- Path or file name are selected as Domain.

4- Paremeters can be selected.

5- Click on Save button.

For the Application Logging;

1- It is entered into the user interface of Oracle Weblogic Console.

2- Go to Domain>Configuration>General

3- Path or file name are selected as Application.

4- Paremeters can be selected.

5- Click on Save button.

Integration of Oracle Weblogic in Logsign Unified SecOps Platform

On the Logsign, go to Settings > Data Collection and add source with +Device. Select SYSLOG as the source type, then Oracle as Vendor and WebLogic as Product, and fill in the standard Syslog fields (Host, Port, Data Policy, Device Name, etc.) as with any other syslog source.

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.