• /
  • EnglishEspañolFrançais日本語한국어Português
  • Inicia sesiónComenzar ahora

Monitor your OCI log forwarder

|View as Markdown (English)

When you integrate your OCI account to send logs to New Relic, OCI is your data source and New Relic is the destination. In between, a New Relic function (the log forwarder) pulls logs from OCI and delivers them to New Relic. If that function runs into trouble, for example a secret it can't read, a batch it can't decode, or a delivery it can't complete, your OCI logs stop flowing, but nothing in OCI or New Relic tells you why.

To catch this kind of failure before it costs you log data, the log forwarder can emit metrics about its own health. This document covers:

  1. Enable self-observability metrics on the log forwarder function, so it starts reporting signals like invocation counts, delivery errors, and pipeline lag, the kind of detail that tells you where in the pipeline a failure happened.
  2. Import a pre-built dashboard that turns those signals into charts, so you can spot an anomaly at a glance instead of digging through raw metric data.

Prerequisites

Before you begin, make sure you have:

  • The OCI log forwarder function you already deployed with Resource Manager, Terraform, or manual setup
  • Your New Relic account ID, to use when you import the dashboard

Enable self-observability metrics

In the logs function's configuration variables, the same place you set VAULT_REGION, SECRET_OCID, and the other logging variables, add:

  • FORWARDER_METRICS_TIER: Controls which self-observability metrics the forwarder emits. See metric tiers for what each setting collects.

If you set up the integration with Resource Manager or Terraform, FORWARDER_METRICS_TIER is the only variable you need to add — TENANCY_NAME and COMPARTMENT_NAME are resolved automatically.

If you set up the integration manually, also add:

  • TENANCY_NAME: Identifies your OCI tenancy by its display name, tagging the forwarder's metrics so you can tell tenancies apart if you monitor more than one.
  • COMPARTMENT_NAME: Identifies, by display name, the compartment where you deployed the logs function, tagging metrics for per-compartment breakdowns. If you deployed into the tenancy's root compartment, use the same value as TENANCY_NAME.

Importante

New Relic bills these self-observability metrics on ingest, the same as any other metric data.

Metric tiers

FORWARDER_METRICS_TIER lets you trade off visibility against cost. It accepts one of the following values:

  • none: Disables self-observability metrics entirely.
  • basic (default): Collects core health metrics: invocation counts, records received, delivered, and dropped, delivery duration, and pipeline lag.
  • advanced: Collects everything in basic, plus deeper tuning metrics: byte volumes, decode and serialize error counts, batching behavior, delivery error classes, function run duration, secret-fetch failures, and client cache hit rate.

Import the observability dashboard

Importante

Set FORWARDER_METRICS_TIER to basic or advanced before you import the dashboard. If you set it to none, the dashboard won't have any data to show.

To import the dashboard:

  1. Open the oci-log-forwarder-metrics-dashboard-template.json file in the oci-log-integration GitHub repository, and copy its contents.
  2. In the copied JSON, find and replace every occurrence of YOUR_ACCOUNT_ID with your New Relic account ID.
  3. Go to one.newrelic.com > All capabilities > Dashboards.
  4. In the top-right corner, click Import dashboard.
  5. Paste the edited JSON.
  6. Choose the account and permission settings for the dashboard, then click Save.

The dashboard populates after the logs function processes at least one invocation with metrics enabled.

Troubleshoot with the dashboard

If OCI logs stop arriving in New Relic, check this dashboard first. A spike in secret-fetch failures or delivery errors points to a problem in the forwarder pipeline, such as the service connector hub, log groups, or function, rather than in OCI or New Relic itself. After you fix the underlying issue, for example a policy or key vault permission, logs resume without redeploying anything.

If you're not seeing any log data at all and haven't yet confirmed the base integration is working, start with our standard log troubleshooting procedures instead.

Next steps

Continue exploring your OCI integration:

Copyright © 2026 New Relic Inc.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.