---
title: Troubleshoot the OCI integration
source: https://docs.newrelic.com/docs/infrastructure/oci/troubleshoot
---

If you're having trouble with the OCI integration, start here.

## Troubleshoot logs [#logs]

If your OCI logs don't appear, stop unexpectedly, show up as duplicates, or display resource names incorrectly, start with the health check below, then find your specific issue in the sections that follow.

### Health check [#logs-health-check]

These two checks tell you whether the problem is upstream in OCI (nothing to check in New Relic yet) or logs have actually reached New Relic:

1.  **Check your connector in OCI.** In the OCI Console, go to **Connector Hub** and open the compartment where you deployed your New Relic integration. Look for a connector named `newrelic-logs-<region>-audit` (for example, `newrelic-logs-us-ashburn-1-audit`) and confirm its status is **Active**. If you see an error status, open the connector for error details.
2.  **Check that logs are arriving in New Relic.** Run this query in [Query your data](https://docs.newrelic.com/docs/query-your-data/explore-query-data/query-builder/introduction-query-builder):

    ```sql
    SELECT count(*) FROM Log WHERE oracle.loggroupid = '_Audit' SINCE 30 minutes ago
    ```

    A count greater than zero means audit logs are flowing. If you're troubleshooting a different log type, confirm you see recent results for the relevant time window instead.

If both checks look healthy, your issue is likely one of the specific scenarios below rather than a total outage.

**No logs appear at all**

Match what you're seeing to the likely cause:

| If you see this                                                                           | Try this                                                                                                                                                                                                                                   |
| ----------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| You just finished setup and nothing has appeared yet                                      | Give it some time. When you create a connector for the first time, OCI can take a while to backfill recent activity — for audit logs, this can be up to 24 hours for historical events, though new events typically appear within minutes. |
| No connector shows up in **Connector Hub** at all                                         | Re-open your setup: if you used the guided setup wizard, confirm you turned on the relevant toggle and re-run it. If you used Terraform, confirm your configuration includes the log connector and re-apply it.                            |
| You have resources in more than one OCI region                                            | Confirm each region has its own connector, that you're checking the region you expect, and repeat setup for any additional regions.                                                                                                        |
| The New Relic UI shows an access/permission error when loading compartments or log groups | See [Missing permissions](#logs-permissions) below.                                                                                                                                                                                        |

**Logs stopped after working**

Match what you're seeing to the likely cause:

| If you see this                                                                                          | Try this                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| -------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| The connector in OCI is no longer **Active**                                                             | Open the connector in **Connector Hub** and check its error details. A permissions change usually causes this (see [Missing permissions](#logs-permissions)), or someone redeployed or replaced the underlying integration.                                                                                                                                                                                                                                           |
| The connector is **Active**, but no new logs are showing up                                              | In the OCI Console, go to **Functions** and confirm the New Relic integration function is deployed and not showing an error state. If you've set up [log forwarder observability](https://docs.newrelic.com/docs/logs/forward-logs/oci-log-forwarder-observability), check that dashboard first for the specific failure, for example a secret-fetch error or a delivery error. If it still looks unhealthy and you can't resolve it from OCI alone, contact support. |
| Someone recently changed your setup (re-ran the wizard, changed a Terraform config, turned a toggle off) | Re-run setup with the correct option enabled to restore the connector — that change likely removed or altered it.                                                                                                                                                                                                                                                                                                                                                     |

**Duplicate log entries**

More than one connector is sending the same log event to New Relic. This usually means more than one connector in OCI is covering the same logs — most often, someone added a broader "all compartments" connector without removing an older connector that only covered a single compartment.

In **Connector Hub**, list all connectors related to your New Relic integration and check what each one covers. Remove any that overlap, keeping only the one connector that covers the scope you actually want.

**Missing compartments or resources**

Your connector's scope doesn't cover everything you expected.

| Setup covers                                                 | What's included                                                                        |
| ------------------------------------------------------------ | -------------------------------------------------------------------------------------- |
| The entire tenancy (all compartments, including future ones) | Everything, automatically — no action needed as you add new compartments.              |
| A specific compartment and everything under it               | That compartment and its sub-compartments, including new sub-compartments added later. |
| A single specific compartment only                           | Just that compartment — it doesn't automatically include new sub-compartments.         |

If you set up through the guided wizard, your connector already covers the entire tenancy — if compartments are still missing, this points to a connector problem (see [No logs appear at all](#no-logs)) rather than a scope problem. If you set up manually or via Terraform, check which scope you configured your connector with, and recreate it with a broader scope if needed.

**Missing permissions**

New Relic doesn't have the OCI permissions it needs — this can block connector creation entirely, or cause it to run without full functionality.

Ask your OCI tenancy administrator to confirm the following policy statements exist for the dynamic group created during setup:

| Policy                                                                                                                                                                                 | What it's for                                               |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------- |
| `Allow dynamic-group your_dynamic_group_name to read log-content in tenancy`                                                                                                           | Reading your log data                                       |
| `Allow dynamic-group your_dynamic_group_name to use fn-function in tenancy`                                                                                                            | Running the New Relic integration                           |
| `Allow dynamic-group your_dynamic_group_name to use fn-invocation in tenancy`                                                                                                          | Running the New Relic integration                           |
| `Allow dynamic-group your_dynamic_group_name to read secret-bundles in tenancy where any { target.secret.id = 'your_ingest_secret_ocid', target.secret.id = 'your_user_secret_ocid' }` | Securely accessing your New Relic license key               |
| `Allow dynamic-group your_dynamic_group_name to inspect dns-family in tenancy`                                                                                                         | Resolving friendly names for DNS resources                  |
| `Allow dynamic-group your_dynamic_group_name to inspect goldengate-family in tenancy`                                                                                                  | Resolving friendly names for GoldenGate resources           |
| `Allow dynamic-group your_dynamic_group_name to inspect network-firewall-family in tenancy`                                                                                            | Resolving friendly names for network firewall resources     |
| `Allow dynamic-group your_dynamic_group_name to inspect cloudevents-rules in tenancy`                                                                                                  | Resolving friendly names for event rule resources           |
| `Allow dynamic-group your_dynamic_group_name to inspect integration-instance in tenancy`                                                                                               | Resolving friendly names for integration instance resources |

If you re-run the guided wizard or the Terraform policy module, it reapplies these automatically. After restoring permissions, if the connector still isn't **Active**, delete it and create it again.

**Resource names show as ID strings**

For some OCI resource types, New Relic automatically looks up a human-readable name (like a VCN or firewall name) shortly after the log first arrives, rather than showing the raw resource identifier. This lookup can take a few minutes the first time New Relic sees a given resource.

| If you see this                                                       | What it means                                                                                                              |
| --------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| A resource shows its ID at first, then a friendly name shortly after  | Normal — this is expected the first time a new resource shows up.                                                          |
| A resource never gets a friendly name, even after a while             | This is usually a permissions issue — see below.                                                                           |
| A specific resource type never shows a friendly name for any resource | Some resource types don't have name lookup enabled and will always show their ID. This is expected behavior, not an error. |

If names never resolve, ask your OCI tenancy administrator to confirm the dynamic group has the `inspect` policies listed under [Missing permissions](#logs-permissions) — one each for DNS, GoldenGate, network firewall, event rule, and integration instance resources. If permissions look correct and names still don't resolve after a reasonable wait, contact support with an example of the affected resource and log timestamp.

**Dashboard shows errors, gaps, or unexpected values**

If you've enabled the OCI Log Forwarder monitoring dashboard, use it as your first stop for anything beyond "are logs arriving":

| If you see this                                                         | What to do                                                                                                                                                                                                                                  |
| ----------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Every widget on the dashboard is empty                                  | Confirm you turned on the integration's metrics option (it's a setting you choose during setup) and that the underlying function is running in OCI.                                                                                         |
| The error rate is climbing on the dashboard                             | Check whether this started right after a recent change to your setup. If nothing changed and it's ongoing, check your OCI network/firewall rules allow outbound access to New Relic, and confirm your New Relic license key is still valid. |
| A "records dropped" or similar metric shows non-zero and stays that way | Contact support with the time range — some log data isn't reaching New Relic.                                                                                                                                                               |
| A tile shows a dash or no value instead of a number or percentage       | Check a wider time range before assuming something's broken — this is often just a "not enough data yet in this time window" state, not an error.                                                                                           |

## Get more help [#get-help]

If you've worked through the checks above and the issue isn't resolved, contact New Relic Support with:

-   Which setup method you used (guided wizard, manual setup, or Terraform)
-   The OCI region and, if relevant, the affected compartment(s)
-   The approximate time range the issue started
-   Which of the checks above you've already tried

## Related articles [#related-articles]

-   [Introduction to the OCI integration](https://docs.newrelic.com/docs/infrastructure/oci/introduction): What the OCI integration does, its capabilities, and how to connect your account.
-   [OCI metrics reference](https://docs.newrelic.com/docs/infrastructure/oci/metrics-reference): The OCI namespaces New Relic collects from, the service each belongs to, and the entity type it reports on.
-   [Monitor your OCI log forwarder](https://docs.newrelic.com/docs/logs/forward-logs/oci-log-forwarder-observability): Enable self-observability metrics on the log forwarder function and import a dashboard to monitor its health.
-   [Uninstall the OCI integration](https://docs.newrelic.com/docs/infrastructure/oci/uninstall): Remove the resources created by the integration and unlink your account.
