Oracle Cloud Infrastructure

Introduction#

Middleware's Oracle Cloud Infrastructure (OCI) integration collects metrics from OCI Monitoring for every tenancy you connect. Use it to monitor compute instances, block volumes, networking, load balancers, object storage, Autonomous Database, MySQL HeatWave, Kubernetes Engine (OKE), Functions and API Gateway, with built-in dashboards for each service.

How it works:

  • Middleware reads metrics with read-only access to your tenancy. Nothing is installed in your tenancy.
  • Every region your tenancy subscribes to and every compartment in it are discovered automatically, including regions and compartments added later.
  • Metrics are collected every 5 minutes at 1-minute resolution. Data appears a few minutes behind real time while OCI finishes ingesting it.
  • Each metric carries the resource's name, type, lifecycle state, compartment and OCI tags, so you can filter and group by them.

Integration Setup#

Prerequisites#

  • An OCI tenancy and a user who can manage IAM groups, users and policies (for example, a member of the Administrators group).
  • Your tenancy's home region. It is shown in the OCI Console under Profile > Tenancy, and is where IAM changes are made.
  • To collect compute instance metrics (oci_computeagent), the Compute Instance Monitoring plugin of the Oracle Cloud Agent must be enabled on your instances, and the instances must be able to reach OCI services (through a public IP, a NAT gateway or a service gateway).

Oracle Cloud Configuration#

Middleware needs a user in your tenancy with an API key and three read-only permissions:

PermissionUsed forRequired
inspect tenanciesDiscovering the regions your tenancy subscribes toYes
read metricsReading OCI Monitoring metricsYes
inspect all-resourcesResource names, compartment names and tags, and tag filtersOptional, recommended

1 Create a group#

  1. In the OCI Console, open Identity & Security > Domains and select the Default domain.
  2. Open Groups and click Create group.
  3. Name the group MiddlewareMonitoring and click Create.

2 Create a user and add it to the group#

  1. In the same domain, open Users and click Create user.
  2. Enter a name such as mw-monitoring and an email address. Identity Domains require an email; an alias such as you+mwmonitoring@example.com works.
  3. Open the user, go to Groups, and add it to MiddlewareMonitoring.

The user only signs in with an API key, so it does not need a console password.

3 Add an API key#

  1. Open the user and go to API keys > Add API key.
  2. Select Generate API key pair and click Download private key.
  3. Click Add. Keep the fingerprint and the user OCID shown in the configuration file preview.

4 Create the policy#

  1. Open Identity & Security > Policies and select your root compartment (the tenancy).
  2. Click Create Policy and name it MiddlewareMonitoring.
  3. Turn on Show manual editor and paste these statements:
1Allow group MiddlewareMonitoring to inspect tenancies in tenancy
2Allow group MiddlewareMonitoring to read metrics in tenancy
3Allow group MiddlewareMonitoring to inspect all-resources in tenancy
  1. Click Create.

The script below creates the group, user, API key and policy, then prints the values for the Middleware form. It needs the OCI CLI and openssl, and is safe to re-run.

First sign in as a tenancy administrator. This opens your browser:

1oci session authenticate --region <home-region> --profile-name mwsetup

Then save the script as oci-mw-monitoring-setup.sh and run it:

1USER_EMAIL=you+mwmonitoring@example.com PROFILE=mwsetup AUTH=security_token \
2  bash oci-mw-monitoring-setup.sh
1#!/usr/bin/env bash
2# Creates the Middleware monitoring identity in an OCI tenancy and prints
3# the values for the Middleware "Connect your tenancy" form.
4set -euo pipefail
5
6PROFILE=${PROFILE:-DEFAULT}            # OCI CLI profile of a tenancy administrator
7AUTH=${AUTH:-}                         # "security_token" for profiles from `oci session authenticate`
8USER_EMAIL=${USER_EMAIL:?Set USER_EMAIL (Identity Domains require an email for every user)}
9GROUP=MiddlewareMonitoring
10USER_NAME=mw-monitoring
11POLICY=MiddlewareMonitoring
12KEY_DIR=${KEY_DIR:-$HOME/.oci/mw-monitoring}
13
14export SUPPRESS_LABEL_WARNING=True
15oci_() { oci --profile "$PROFILE" ${AUTH:+--auth "$AUTH"} "$@"; }
16value() { local v; v=$("$@" 2>/dev/null || true); [ "$v" = "null" ] && v=""; printf '%s' "$v"; }
17
18TENANCY=$(awk -v p="[$PROFILE]" '$0==p{f=1;next} /^\[/{f=0} f&&/^tenancy[[:space:]]*=/{sub(/^tenancy[[:space:]]*=[[:space:]]*/,"");print}' ~/.oci/config)
19HOME_REGION=$(oci_ iam region-subscription list --tenancy-id "$TENANCY" \
20  --query 'data[?"is-home-region"] | [0]."region-name"' --raw-output)
21
22# 1. Group
23GROUP_ID=$(value oci_ iam group list --compartment-id "$TENANCY" --name "$GROUP" --query 'data[0].id' --raw-output)
24[ -n "$GROUP_ID" ] || GROUP_ID=$(oci_ iam group create --compartment-id "$TENANCY" --name "$GROUP" \
25  --description "Middleware observability read-only access" --query 'data.id' --raw-output)
26
27# 2. User, added to the group
28USER_ID=$(value oci_ iam user list --compartment-id "$TENANCY" --name "$USER_NAME" --query 'data[0].id' --raw-output)
29[ -n "$USER_ID" ] || USER_ID=$(oci_ iam user create --compartment-id "$TENANCY" --name "$USER_NAME" \
30  --email "$USER_EMAIL" --description "Middleware OCI monitoring (API key only)" --query 'data.id' --raw-output)
31oci_ iam group add-user --group-id "$GROUP_ID" --user-id "$USER_ID" >/dev/null 2>&1 || true
32
33# 3. Policy in the root compartment
34POLICY_ID=$(value oci_ iam policy list --compartment-id "$TENANCY" --name "$POLICY" --query 'data[0].id' --raw-output)
35[ -n "$POLICY_ID" ] || oci_ iam policy create --compartment-id "$TENANCY" --name "$POLICY" \
36  --description "Read-only access for Middleware OCI monitoring" \
37  --statements "[\"Allow group $GROUP to inspect tenancies in tenancy\",\"Allow group $GROUP to read metrics in tenancy\",\"Allow group $GROUP to inspect all-resources in tenancy\"]" >/dev/null
38
39# 4. API key: generated locally, only the public key is uploaded
40mkdir -p "$KEY_DIR" && chmod 700 "$KEY_DIR"
41KEY="$KEY_DIR/oci_api_key.pem"
42if [ ! -f "$KEY" ]; then
43  openssl genrsa -out "$KEY" 2048 2>/dev/null && chmod 600 "$KEY"
44  openssl rsa -pubout -in "$KEY" -out "$KEY_DIR/oci_api_key_public.pem" 2>/dev/null
45fi
46FINGERPRINT=$(openssl rsa -pubout -outform DER -in "$KEY" 2>/dev/null | openssl md5 -c | awk '{print $NF}')
47UPLOADED=$(value oci_ iam user api-key list --user-id "$USER_ID" \
48  --query "data[?fingerprint=='$FINGERPRINT'] | length(@)" --raw-output)
49[ "${UPLOADED:-0}" != "0" ] || oci_ iam user api-key upload --user-id "$USER_ID" \
50  --key-file "$KEY_DIR/oci_api_key_public.pem" >/dev/null
51
52cat <<EOF
53Tenancy OCID : $TENANCY
54Home region  : $HOME_REGION
55User OCID    : $USER_ID
56Fingerprint  : $FINGERPRINT
57Private key  : paste the contents of $KEY
58EOF

A newly added API key can take a few minutes to be accepted by every OCI service. Wait a few minutes after running the script before you click Verify in Middleware.

If your Middleware account offers the Cross-tenancy policy access method, you can skip the user and API key. Select it in Middleware, copy the Define and Admit statements it shows into a policy in your root compartment, and Middleware reads metrics with its own identity. No key from your tenancy is stored.

Middleware Configuration#

  1. In Middleware, go to Installations → All Integrations and open Oracle Cloud Infrastructure.

  2. Under Grant Middleware read-only access, select API key.

  3. Under Connect your tenancy, fill in:

    FieldWhere to find it
    Tenancy OCIDOCI Console Profile > Tenancy, starts with ocid1.tenancy.
    Home regionOCI Console Profile > Tenancy, for example us-ashburn-1
    User OCIDThe monitoring user's details page, starts with ocid1.user.
    FingerprintThe API key's fingerprint, for example 12:34:56:...
    Private key (PEM)The full contents of the downloaded private key file, including the BEGIN and END lines
  4. Click Verify. Middleware checks each permission separately:

    • Passed for all three: access is complete.
    • Failed for inspect tenancies or read metrics: a required policy statement is missing. Add it and verify again.
    • Missing for inspect all-resources: metrics are still collected, but without resource names, compartment names and tags, and tag filters cannot be used.

A tenancy can be connected once. To monitor several tenancies, click Add Tenancy and repeat these steps for each.

Configuring Metric Collection#

After the tenancy is verified, the Configure metric collection step appears:

  • Allow Metric Collection: turns collection on or off for this tenancy.
  • Regions: leave empty to collect from every region the tenancy subscribes to, or select specific regions.
  • OCI services: turn individual services on or off. The table shows the OCI Monitoring namespaces and the number of metrics collected for each service.
  • Compartments: leave empty to collect from the whole tenancy, including all sub-compartments. If you list compartment OCIDs, only those compartments are collected, without their sub-compartments.
  • Tag filters: collect only resources with matching OCI tags. Use key (any value) or key:value, and write defined tags as namespace.key, for example Operations.CostCenter:42. A resource is collected when it matches any Include entry (or Include is empty) and no Exclude entry. Tag filters need the inspect all-resources permission.
  • Custom attributes: key:value pairs added to every metric from this tenancy, for example team:payments.

Click Save Configuration. Data starts arriving within about 15 minutes.

You can also enable or disable a single service from its own card, such as OCI Compute, under Installations → All Integrations. The card's Data Collected tab lists the metrics collected for that service.

Supported OCI Services#

ServiceOCI Monitoring namespacesMetricsDashboard
OCI Computeoci_computeagent, oci_compute, oci_compute_instance_health, oci_compute_infrastructure_health, oci_vmi_resource_utilization20OCI Compute
OCI Block Volumeoci_blockstore10OCI Block Volume
OCI Networkingoci_vcn, oci_service_gateway16OCI Networking
OCI Load Balanceroci_lbaas27OCI Load Balancer
OCI Network Load Balanceroci_nlb9OCI Network Load Balancer
OCI Object Storageoci_objectstorage13OCI Object Storage
OCI Autonomous Databaseoci_autonomous_database45OCI Autonomous Database
OCI MySQL HeatWaveoci_mysql_database20OCI MySQL HeatWave
OCI Kubernetes Engineoci_oke5OCI Kubernetes Engine
OCI Functionsoci_faas6OCI Functions
OCI API Gatewayoci_apigateway8OCI API Gateway

Middleware collects 179 metrics across these services. To request another OCI service, contact Middleware support.

Accessing Data#

Each service has a default dashboard, listed on the Dashboards page under its service name, for example OCI Compute. To build your own widgets, search for metrics starting with oci_.

Metric names use the format <namespace>.<MetricName>, for example oci_computeagent.CpuUtilization. All metrics are gauges.

Every metric carries these resource attributes:

AttributeValue
cloud.provideroracle_cloud
cloud.account.idTenancy OCID
cloud.regionRegion, for example us-ashburn-1
cloud.resource_idOCID of the resource the metric belongs to
oci.compartment.idCompartment OCID
oci.compartment.nameCompartment name (the tenancy name for the root compartment)
oci.resource.nameResource display name
oci.resource.typeOCI resource type, for example Instance
oci.resource.lifecycle_stateLifecycle state, for example RUNNING
oci.tag.<key>Freeform tags
oci.tag.<namespace>.<key>Defined tags
channeloci

oci.compartment.name, oci.resource.type, oci.resource.lifecycle_state and the tags need the inspect all-resources permission. Other OCI dimensions, such as shape or availabilityDomain, are kept as metric attributes.

Metrics Collected#

Metric NameUnitDescription
oci_computeagent.CpuUtilization%CPU utilization.
oci_computeagent.MemoryUtilization%Memory utilization, by pages in use.
oci_computeagent.DiskBytesReadByBytes read from disk per interval.
oci_computeagent.DiskBytesWrittenByBytes written to disk per interval.
oci_computeagent.DiskIopsRead{operations}Disk read operations per interval.
oci_computeagent.DiskIopsWritten{operations}Disk write operations per interval.
oci_computeagent.NetworksBytesInByBytes received over the network per interval.
oci_computeagent.NetworksBytesOutByBytes sent over the network per interval.
oci_computeagent.LoadAverage{processes}System load average over 1 minute.
oci_computeagent.MemoryAllocationStalls{stalls}Times page reclaim was called directly.
oci_compute.VolumeReadOps{operations}Boot and block volume read operations seen by the instance.
oci_compute.VolumeWriteOps{operations}Boot and block volume write operations seen by the instance.
oci_compute.VolumeReadThroughputByBytes read from attached volumes.
oci_compute.VolumeWriteThroughputByBytes written to attached volumes.
oci_compute.InstanceMetadataRequests{requests}Requests to the instance metadata service.
oci_compute_instance_health.InstanceAccessibilityStatus{status}0 when the instance responds to health checks.
oci_compute_instance_health.InstanceFileSystemStatus{status}0 when the instance file system is healthy.
oci_compute_infrastructure_health.instance_status{status}0 when the instance is running on healthy infrastructure.
oci_compute_infrastructure_health.maintenance_status{status}1 when maintenance is scheduled for the instance.
oci_vmi_resource_utilization.CpuUtilization%Hypervisor-reported CPU utilization.
Metric NameUnitDescription
oci_blockstore.VolumeReadThroughputByBytes read per interval.
oci_blockstore.VolumeWriteThroughputByBytes written per interval.
oci_blockstore.VolumeReadOps{operations}Read operations per interval.
oci_blockstore.VolumeWriteOps{operations}Write operations per interval.
oci_blockstore.VolumeThrottledIOs{operations}Throttled I/O operations per interval.
oci_blockstore.VolumeGuaranteedVPUsPerGB{VPUs}Active volume performance units per GB.
oci_blockstore.VolumeGuaranteedIOPS{operations}/sGuaranteed IOPS per the performance SLA.
oci_blockstore.VolumeGuaranteedThroughputMByGuaranteed throughput per the performance SLA.
oci_blockstore.VolumeReplicationSecondsSinceLastUploadsSeconds since the last cross-region replica upload.
oci_blockstore.VolumeReplicationSecondsSinceLastSyncsSeconds since the last synced cross-region replica.
Metric NameUnitDescription
oci_vcn.VnicFromNetworkBytesByBytes received by the VNIC from the network.
oci_vcn.VnicToNetworkBytesByBytes sent by the VNIC to the network.
oci_vcn.VnicFromNetworkPackets{packets}Packets received by the VNIC from the network.
oci_vcn.VnicToNetworkPackets{packets}Packets sent by the VNIC to the network.
oci_vcn.VnicIngressDropsSecurityList{packets}Inbound packets dropped by security rules.
oci_vcn.VnicEgressDropsSecurityList{packets}Outbound packets dropped by security rules.
oci_vcn.VnicIngressDropsThrottle{packets}Inbound packets dropped by throttling.
oci_vcn.VnicEgressDropsThrottle{packets}Outbound packets dropped by throttling.
oci_vcn.VnicIngressDropsConntrackFull{packets}Inbound packets dropped because the connection table is full.
oci_vcn.VnicEgressDropsConntrackFull{packets}Outbound packets dropped because the connection table is full.
oci_vcn.VnicConntrackUtilPercent%Connection tracking table utilization.
oci_vcn.VnicConntrackIsFull{status}1 when the connection tracking table is full.
oci_service_gateway.bytesFromServiceByBytes received from Oracle services.
oci_service_gateway.bytesToServiceByBytes sent to Oracle services.
oci_service_gateway.packetsFromService{packets}Packets received from Oracle services.
oci_service_gateway.packetsToService{packets}Packets sent to Oracle services.
Metric NameUnitDescription
oci_lbaas.acceptedConnections{connections}Connections accepted by the load balancer.
oci_lbaas.acceptedSSLHandshake{handshakes}Accepted SSL handshakes.
oci_lbaas.activeConnections{connections}Active connections.
oci_lbaas.activeSslConnections{connections}Active SSL connections.
oci_lbaas.backendServers{servers}Backend servers in the backend set.
oci_lbaas.backendTimeouts{timeouts}Timeouts across all backend servers.
oci_lbaas.bytesReceivedByBytes received.
oci_lbaas.bytesSentByBytes sent.
oci_lbaas.closedConnections{connections}Connections closed between the load balancer and backends.
oci_lbaas.failedSSLClientCertVerify{count}Failed client certificate verifications.
oci_lbaas.FailedSslHandshake{handshakes}Failed SSL handshakes.
oci_lbaas.handledConnections{connections}Connections handled by the load balancer.
oci_lbaas.httpRequests{requests}Incoming HTTP requests.
oci_lbaas.httpResponses{responses}HTTP responses.
oci_lbaas.httpResponses200{responses}HTTP 200 responses.
oci_lbaas.httpResponses2xx{responses}HTTP 2xx responses.
oci_lbaas.httpResponses3xx{responses}HTTP 3xx responses.
oci_lbaas.httpResponses4xx{responses}HTTP 4xx responses.
oci_lbaas.httpResponses502{responses}HTTP 502 responses.
oci_lbaas.httpResponses504{responses}HTTP 504 responses.
oci_lbaas.httpResponses5xx{responses}HTTP 5xx responses.
oci_lbaas.invalidHeaderResponses{responses}Responses with invalid headers.
oci_lbaas.keepAliveConnections{connections}Keep-alive connections.
oci_lbaas.peakBandwidthbit/sPeak bandwidth used during the interval.
oci_lbaas.responseTimeFirstBytemsAverage time to first byte (TCP).
oci_lbaas.responseTimeHttpHeadermsAverage backend response time (HTTP).
oci_lbaas.unhealthyBackendServers{servers}Unhealthy backend servers.
Metric NameUnitDescription
oci_nlb.ProcessedBytesByBytes processed, including headers.
oci_nlb.ProcessedPackets{packets}Packets processed.
oci_nlb.NewConnections{connections}New client-to-backend connections.
oci_nlb.NewConnectionsTCP{connections}New TCP connections.
oci_nlb.NewConnectionsUDP{connections}New UDP connections.
oci_nlb.IngressPacketsDroppedBySL{packets}Inbound packets dropped by security rules.
oci_nlb.EgressPacketsDroppedBySL{packets}Outbound packets dropped by security rules.
oci_nlb.HealthyBackendsPerNlb{servers}Healthy backend servers.
oci_nlb.UnhealthyBackendsPerNlb{servers}Unhealthy backend servers.
Metric NameUnitDescription
oci_objectstorage.ObjectCount{objects}Objects in the bucket.
oci_objectstorage.StoredBytesBySize of the bucket.
oci_objectstorage.UncommittedPartsBySize of incomplete multipart upload parts.
oci_objectstorage.AllRequests{requests}All HTTP requests.
oci_objectstorage.ClientErrors{requests}Requests that returned 4xx errors.
oci_objectstorage.GetRequests{requests}GetObject requests.
oci_objectstorage.PutRequests{requests}PutObject requests.
oci_objectstorage.PostRequests{requests}POST requests.
oci_objectstorage.ListRequests{requests}ListObjects requests.
oci_objectstorage.HeadRequests{requests}HeadObject requests.
oci_objectstorage.DeleteRequests{requests}DeleteObject requests.
oci_objectstorage.FirstByteLatencymsTime from request received to first response byte.
oci_objectstorage.TotalRequestLatencymsTime from first request byte to last response byte.
Metric NameUnitDescription
oci_autonomous_database.CpuUtilization%CPU utilization across consumer groups.
oci_autonomous_database.CpuTimes/sRate of CPU time accumulation by foreground sessions.
oci_autonomous_database.DBTimes/sRate of time sessions spend executing database code.
oci_autonomous_database.WaitTimes/sRate of non-idle wait time accumulation.
oci_autonomous_database.AverageActiveSessions{sessions}Average active sessions.
oci_autonomous_database.Sessions{sessions}Sessions in the database.
oci_autonomous_database.SessionUtilization%Session utilization.
oci_autonomous_database.BlockingSessions{sessions}Sessions blocking others for over 60 seconds.
oci_autonomous_database.CurrentLogons{logons}Successful logons during the interval.
oci_autonomous_database.FailedLogons{logons}Logons failed due to invalid credentials.
oci_autonomous_database.FailedConnections{connections}Failed connections.
oci_autonomous_database.ConnectionsDroppedByClient{connections}Connections dropped by the client.
oci_autonomous_database.ConnectionsDroppedByServer{connections}Connections dropped by the server.
oci_autonomous_database.ConnectionlatencymsTime to connect to the database.
oci_autonomous_database.QueryLatencymsTime to return a simple query.
oci_autonomous_database.DatabaseAvailability{status}1 when the database is available, 0 otherwise.
oci_autonomous_database.ExecuteCount{executions}SQL statement executions.
oci_autonomous_database.RunningStatements{statements}Running SQL statements.
oci_autonomous_database.QueuedStatements{statements}Queued SQL statements.
oci_autonomous_database.ParseCount{parses}Hard and soft parses.
oci_autonomous_database.HardParseCount{parses}Hard parses.
oci_autonomous_database.ParseFailureCount{parses}Parse failures.
oci_autonomous_database.TransactionCount{transactions}User commits and rollbacks.
oci_autonomous_database.UserCommits{transactions}User commits.
oci_autonomous_database.UserRollbacks{transactions}User rollbacks.
oci_autonomous_database.UserCalls{calls}Logons, parses and execute calls.
oci_autonomous_database.LogicalReads{blocks}Logical block reads.
oci_autonomous_database.PhysicalReads{blocks}Blocks read from disk.
oci_autonomous_database.PhysicalWrites{blocks}Blocks written to disk.
oci_autonomous_database.PhysicalReadTotalBytesByBytes read from disk.
oci_autonomous_database.PhysicalWriteTotalBytesByBytes written to disk.
oci_autonomous_database.DBBlockChanges{blocks}Block changes in the SGA.
oci_autonomous_database.RedoGeneratedByRedo generated.
oci_autonomous_database.IOPS{operations}/sAverage I/O operations per second.
oci_autonomous_database.IOThroughputMBy/sAverage I/O throughput.
oci_autonomous_database.PgaUtilization%PGA memory utilization.
oci_autonomous_database.SgaUtilization%SGA memory utilization.
oci_autonomous_database.StorageAllocatedGBySpace allocated for all tablespaces.
oci_autonomous_database.StorageUsedGByMaximum space used during the interval.
oci_autonomous_database.StorageMaxGByMaximum storage reserved.
oci_autonomous_database.StorageUtilization%Allocated storage as a share of the maximum.
oci_autonomous_database.ECPUsAllocated{ECPUs}ECPUs billed.
oci_autonomous_database.PeerLagsSeconds the disaster-recovery peer lags the primary.
oci_autonomous_database.SQLNetBytesFromClientByBytes received from clients over SQL*Net.
oci_autonomous_database.SQLNetBytesToClientByBytes sent to clients over SQL*Net.
Metric NameUnitDescription
oci_mysql_database.CPUUtilization%CPU utilization of the MySQL host or HeatWave nodes.
oci_mysql_database.MemoryUtilization%Memory utilization.
oci_mysql_database.MemoryUsedGiByMaximum memory used during the interval.
oci_mysql_database.ActiveConnections{connections}Connections executing statements.
oci_mysql_database.CurrentConnections{connections}Open connections.
oci_mysql_database.Statements{statements}Statements executed.
oci_mysql_database.StatementLatencymsStatement latency.
oci_mysql_database.DbVolumeReadOperations{operations}DB volume read operations.
oci_mysql_database.DbVolumeWriteOperations{operations}DB volume write operations.
oci_mysql_database.DbVolumeReadBytesByBytes read from DB volumes.
oci_mysql_database.DbVolumeWriteBytesByBytes written to DB volumes.
oci_mysql_database.DbVolumeUtilization%DB volume space utilization.
oci_mysql_database.NetworkReceiveBytesByNetwork bytes received.
oci_mysql_database.NetworkTransmitBytesByNetwork bytes sent.
oci_mysql_database.StorageUsedGiByStorage used.
oci_mysql_database.StorageAllocatedGiByStorage allocated.
oci_mysql_database.BackupFailure{status}1 when a backup failed.
oci_mysql_database.ChannelLagmsReplication channel lag.
oci_mysql_database.HeatWaveHealth{status}HeatWave cluster health: 0 healthy, 2 failed.
oci_mysql_database.HeatWaveStatements{statements}Statements executed on HeatWave.
Metric NameUnitDescription
oci_oke.APIServerRequestCount{requests}Requests to the Kubernetes API server.
oci_oke.APIServerResponseCount{responses}Non-200 responses from the Kubernetes API server.
oci_oke.UnschedulablePods{pods}Pods the scheduler cannot place.
oci_oke.NodeState{nodes}Worker nodes by state.
oci_oke.KubernetesNodeCondition{nodes}Worker nodes by condition.
Metric NameUnitDescription
oci_faas.FunctionInvocationCount{invocations}Function invocations.
oci_faas.FunctionResponseCount{responses}Function responses.
oci_faas.FunctionExecutionDurationmsFunction execution duration.
oci_faas.AllocatedTotalConcurrencyMByMemory allocated to concurrent executions.
oci_faas.AllocatedProvisionedConcurrencyMByMemory used by provisioned concurrency.
oci_faas.FunctionDetachedDeliveries{deliveries}Detached invocation deliveries.
Metric NameUnitDescription
oci_apigateway.HttpRequests{requests}Incoming API requests.
oci_apigateway.HttpResponses{responses}Responses sent to clients.
oci_apigateway.BackendHttpResponses{responses}Responses returned by backends.
oci_apigateway.BytesReceivedByBytes received from clients.
oci_apigateway.BytesSentByBytes sent to clients.
oci_apigateway.LatencysEnd-to-end request latency.
oci_apigateway.IntegrationLatencysTime spent calling backends.
oci_apigateway.InternalLatencysTime spent inside the gateway.

Troubleshooting#

Verify fails with "Authentication failed" for every check

The user OCID, fingerprint or private key does not match. Check that the fingerprint belongs to the key you pasted, and that the private key includes the BEGIN and END lines.

Verify fails for some checks and passes for others, with "Authentication failed"

The API key was added in the last few minutes and has not reached every OCI service yet. Wait a few minutes and click Verify again.

A check fails with "Not authorized"

The policy statement for that permission is missing, or was added less than a minute ago. Check that the policy is in the root compartment and names the group the user belongs to.

No data after saving

  • Wait about 15 minutes after saving. Metrics are collected every 5 minutes and run a few minutes behind real time.
  • Check that Allow Metric Collection is on and the service is enabled for the tenancy.
  • Check that the resources exist in the selected regions and compartments, and match your tag filters.

Compute instances show no CPU or memory metrics

oci_computeagent metrics are published by the Oracle Cloud Agent on each instance. Enable the Compute Instance Monitoring plugin under the instance's Oracle Cloud Agent tab, and make sure the instance can reach OCI services through a public IP, a NAT gateway or a service gateway.

Resource names or tags are missing

Add the inspect all-resources policy statement. Names and tags are refreshed every 15 minutes.

Removing the Integration#

To stop collecting from a tenancy, open Oracle Cloud Infrastructure in Middleware, select the tenancy under Connected tenancies and delete it. Then remove the MiddlewareMonitoring policy, user and group from your tenancy.