New Relic's OCI integration connects your Oracle Cloud Infrastructure environment to New Relic, so you can monitor OCI resources and applications from the same observability platform you use for the rest of your stack. New Relic collects OCI metrics and logs using specialized infrastructure agents, on-host integrations, and cloud integrations built specifically for OCI. Once connected, your OCI resources appear as entities in New Relic, alongside the applications and hosts running on them.
Capabilities
New Relic collects two types of OCI data:
Metrics: Real-time metrics tracking health, capacity, and performance for your OCI resources
Logs: OCI service and audit logs
Compatibility and requirements
You need
Before you begin, make sure you have:
A New Relic account with infrastructure monitoring permissions in a supported region (US, EU, or JP)
An OCI tenancy with an Identity and Access Management (IAM) domain, and temporary administrative access to that domain and the root compartment, enough to complete Workload Identity Federation (WIF) setup, the mechanism New Relic uses to authenticate without storing long-lived credentials. You can revoke this access once setup is complete.
Your OCI tenancy OCID and home region (for example, us-ashburn-1)
An OCI API signing key (only if you're deploying with Terraform)
Guided installation
Guided installation is available at one.newrelic.com > Integrations & Agents > Oracle Cloud Infrastructure. The UI walks you through connecting your OCI account, then instrumenting the namespaces and log groups you want to monitor.
Choose data type(s)
Follow these steps:
Select the data type as Metrics (for performance and usage statistics), Logs (for detailed event and audit records), or both, depending on your monitoring needs. Choosing both sends metrics and logs together, so you can correlate them for the same OCI resources.
Click Continue.
Choose your integration method and configure the integration
Select your preferred integration method to ingest OCI data into New Relic based on your organizational needs:
Runs Oracle Resource Manager stacks to provision what the integration needs, instead of you creating each piece by hand in the OCI console.
Follow the on-screen instructions to establish the connection.
In the OCI console create the required policies and service connectors. You will need the following information to complete the process:
Name the dedicated compartment as newrelic_compartment_DO_NOT_REMOVE.
While creating the dynamic group in the root compartment under the default domain, add the rules resource.type = 'serviceconnector' and resource.type = 'fnfunc'.
Create a key vault to securely store your New Relic license key and user key for authentication.
Create a key vault. In the OCI console, locate and access the Key Management and Vault services and create a vault in the compartment you created earlier, naming it (for example, newrelic-vault) and choosing a standard or virtual private vault based on your security requirements.
Create a master encryption key. In the vault, create a master key named (for example) newrelic-encryption-key, using the AES algorithm and a 256-bit key length.
Create secrets for your API keys. Create a secret for your New Relic ingest license key, named (for example) newrelic-ingest-key, selecting the master key you just created and pasting your ingest license key as the secret content. Repeat to create a second secret for your New Relic user key, named (for example) newrelic-user-key, pasting your user key as the secret content.
Create a serverless application and deploy the New Relic function that processes and forwards your OCI metrics.
Create a serverless application
Access the Functions service under Developer Services in the OCI console.
Create a new application with this configuration:
Name: a descriptive name (for example, NewRelicMetricsApp)
Compartment: your designated New Relic compartment
VCN: the VCN created for the New Relic integration
Subnet: the private subnet, for secure connectivity
Shape: the compute shape matching your Docker image architecture (ARM or x86)
Configure environment variables
Within the application settings, add these configuration variables:
FORWARD_TO_NR: set to True to enable data forwarding to New Relic
LOGGING_ENABLED: set to False to disable verbose logging (optional)
NR_METRIC_ENDPOINT: the New Relic endpoint, using newrelic-metric-api for US accounts, newrelic-eu-metric-api for EU accounts, or newrelic-jp-metric-api for JP accounts
VAULT_REGION: the region where you created your key vault
SECRET_OCID: the OCID of your New Relic ingest secret from the key vault
TENANCY_OCID: your OCI tenancy OCID
Save the configuration variables.
Create and deploy the function
Within the application, create a new function with these specifications:
Function name: a descriptive name (for example, newrelic-metrics-function)
Image source: the New Relic Docker image from Container Registry
Memory allocation: appropriate memory (for example, 256 MB)
For the Docker image, use Container Registry authentication: authenticate with your regional Container Registry endpoint, pull the New Relic Docker image ({region}.ocir.io/axcvnhglb9ao/public-newrelic-repo:latest), tag and push it to your namespace if required, then reference it in your function configuration.
Complete the function creation and deployment process.
Create a serverless application and deploy the New Relic function that processes and forwards your OCI logs.
Create a serverless application for logging
Access the Functions service under Developer Services in the OCI console.
Create a new application with this configuration:
Name: a descriptive name (for example, newrelic-logging-function-app)
Compartment: your designated New Relic compartment
VCN: the VCN created for the New Relic integration
Shape: GENERIC_X86, for the application shape
Save the application configuration.
Configure environment variables for logging
Within the application settings, go to the configuration section and add these variables:
VAULT_REGION: the region where you created your key vault
DEBUG_ENABLED: false for production use (or true for debugging)
NEW_RELIC_REGION: your New Relic region (US, EU, or JP)
SECRET_OCID: the OCID of your New Relic license key secret from the key vault
CLIENT_TTL: 30 seconds, for the license key refresh interval
FORWARDER_METRICS_TIER: Controls which self-observability metrics the forwarder emits. Defaults to basic. Refer to the metric tiers for what each setting collects.
TENANCY_NAME: Identifies your OCI tenancy by its display name, tagging the forwarder's metrics so you can tell tenancies apart if you monitor more than one.
COMPARTMENT_NAME: Identifies, by display name, the compartment where you deployed the logs function, tagging metrics for per-compartment breakdowns. If you deployed into the tenancy's root compartment, use the same value as TENANCY_NAME.
Prepare the New Relic logging Docker image: authenticate with your regional Container Registry endpoint, pull the New Relic logging image from the public repository, then tag and push it to your namespace if required.
Create a new function within the application with these specifications:
Function name: a descriptive name (for example, newrelic-logging-function)
Image source: the New Relic logging Docker image from Container Registry
Memory allocation: at least 128 MB
Timeout: 300 seconds, for adequate processing time
Complete the function creation and deployment process.
(Optional) Enable function logging
Access the monitoring settings for your function application.
Enable function invocation logs by selecting or creating an appropriate log group, configuring log retention and access policies, and activating log collection for the function.
If you select Logs as a data type, Terraform is the recommended setup method.
For the detailed integration steps, refer to the OCI cloud integration guide.
Instrument your metric namespaces and log groups
Once you create the connection, the OCI page in New Relic shows separate views for metrics and logs, each with its own Add instrumentation control:
Click Add instrumentation, filtered to Not instrumented tab by default.
Expand a compartment to see its individual metric namespaces (or log groups), and select the ones you want to monitor. For logs, you can also turn on Enable audit logs to include OCI audit logs.
Confirm your selection. New Relic shows a summary of how many compartments and namespaces (or log groups) you're about to instrument. Then click Deploy to OCI.
After the deployment finishes in OCI, the compartment moves to the Instrumented tab, and its data appears at one.newrelic.com > Infrastructure > OCI.
If you selected both metrics and logs during setup, switch to the Logs view and repeat steps 1–4 there.
Data can take up to 30 minutes to appear. If you don't see it after that, check the deployment status in the OCI console.
To instrument additional namespaces or log groups later, return to the OCI page in New Relic and repeat these steps.
Find and use your data
Once your data starts appearing at one.newrelic.com > Infrastructure > OCI, confirm the integration is working and put it to use:
Verify that your OCI account appears in the integrations list.
Confirm that you're receiving data (metrics and/or logs).
Create alert conditions for key OCI metrics to get proactive notifications about performance issues.
Build custom dashboards to visualize your OCI infrastructure data and monitor performance trends.
If you don't see data after 30 minutes, see Troubleshooting.
Related articles
Continue exploring the OCI integration:
OCI metrics reference: The OCI namespaces New Relic collects from and the service each belongs to.
Monitor your OCI log forwarder: Enable self-observability metrics on the log forwarder function and import a dashboard to monitor its health.