Extending Security and Observability Across Oracle Cloud Infrastructure
As organizations modernize applications on Oracle Cloud Infrastructure (OCI), they must extend the security and operational practices that support those workloads. Today’s applications often span virtual machines, containers, Oracle Kubernetes Engine (OKE), and on-premises infrastructure. Security and operations teams must maintain visibility across increasingly distributed environments.
OCI provides native telemetry and observability services for collecting metrics, events, logs, and traces (MELT) through capabilities such as OCI Monitoring and OCI Logging. In many situations, however, teams also need to understand how applications communicate, validate runtime behavior, and investigate activity between workloads. Network-derived telemetry complements OCI-native telemetry by adding application, flow, and packet-level context. This context strengthens security investigations, performance analysis, and compliance validation.
GigaVUE Cloud Suite™ for OCI, part of the Gigamon Deep Observability Pipeline, extends this network visibility by acquiring, optimizing, and enriching network traffic before delivering network-derived telemetry to existing security, cloud, and observability platforms. Rather than introducing a separate operational model, it integrates with existing OCI deployment and automation practices while extending consistent visibility across hybrid cloud infrastructure.
Maintaining Visibility as Applications Move to OCI
Cloud adoption is rarely a single migration event. Organizations often modernize applications incrementally, moving selected workloads into OCI while continuing to operate services across multiple environments. Security and operations teams must maintain consistent visibility throughout this transition without adding operational complexity.
Separate monitoring practices for cloud and on-premises infrastructure can create visibility gaps and inconsistent security policies. Teams may also deploy multiple traffic collection methods to support different downstream tools.
GigaVUE Cloud Suite helps address these challenges by extending network visibility into OCI while continuing to deliver telemetry to the security, monitoring, and observability tools already in use. Organizations can maintain consistent traffic policies and investigation workflows as workloads expand across hybrid cloud infrastructure.
How Network-Derived Telemetry Complements OCI Observability
Metrics, events, logs, and traces provide valuable operational insight, but they do not always capture the full context of application communications. Network-derived telemetry provides runtime evidence by showing how workloads communicate across virtual cloud networks, application tiers, and service boundaries. When optimized and enriched with application context, that telemetry becomes network-derived intelligence for downstream security and observability platforms.
GigaVUE Cloud Suite for OCI acquires traffic from OCI infrastructure and processes it into optimized network-derived telemetry, including packet data, flow records, and context-rich application metadata, before forwarding it to downstream platforms. Gigamon Application Metadata Intelligence (AMI), generated through deep packet inspection, extracts thousands of application attributes. It enriches security and observability tools without requiring every downstream platform to process full packet streams. This context can improve threat investigations, speed root-cause analysis, and strengthen application observability.
Acquiring Network Traffic Across OCI Workloads
Applications deployed on OCI commonly span virtual machines, containers, multiple virtual cloud networks, and OKE clusters. GigaVUE Cloud Suite provides flexible traffic acquisition across these environments through OCI native vTAPs or GigaVUE® Universal Cloud Tap (UCT).
GigaVUE Universal Cloud Tap provides lightweight traffic mirroring for virtual machine and container workloads, including OKE environments. It reduces the need to deploy separate agents for every downstream security or observability platform. Traffic is acquired once and forwarded through Generic Routing Encapsulation (GRE) or Virtual Extensible LAN (VXLAN) tunnels to GigaVUE® V Series visibility nodes. There, it can be processed and distributed according to centrally defined visibility policies.
This shared acquisition model allows organizations to scale visibility as OCI deployments grow while minimizing operational overhead and maintaining application performance.

Optimizing Telemetry Before It Reaches Security and Observability Tools
Not every tool requires every packet. Sending complete traffic streams to every platform can increase data movement, infrastructure costs, and processing overhead.
GigaVUE V Series visibility nodes aggregate traffic from OCI workloads before applying policy-based filtering, packet de-duplication, packet slicing, masking, flow generation, and traffic distribution. Layer 2 through Layer 4 policies allow organizations to select traffic based on IP addresses, protocols, ports, subnets, or workload attributes before forwarding packets, flows, or application metadata to the appropriate destination.
Traffic can also be distributed across multiple tool instances through integrated load balancing. This allows security and observability platforms to scale without separate load-balancing infrastructure.
Processing traffic before it reaches downstream tools reduces unnecessary data movement while providing each platform with the telemetry appropriate for its function.
Gaining Visibility into Encrypted and Lateral Traffic
Many security events occur within East-West application communications rather than at the network perimeter. Modern application architectures also rely extensively on transport layer security (TLS) and mutual TLS to protect communication between workloads. This can limit the visibility available to security and monitoring tools.
Gigamon provides complementary approaches for inspecting encrypted traffic. Gigamon Precryption® technology provides access to plaintext traffic before encryption or after workload decryption. It preserves visibility into encrypted East-West communications, including mTLS-protected traffic, without requiring changes to application architecture. Across other parts of hybrid cloud infrastructure, GigaSMART® TLS/SSL Decryption can selectively decrypt traffic once and distribute it to multiple inline and out-of-band tools.
Combined with application metadata, these capabilities help teams identify unexpected application behavior, investigate lateral movement, validate security and compliance policies, and troubleshoot application dependencies across OCI environments.
Aligning With OCI Automation and Operational Practices
OCI environments are commonly deployed through infrastructure as code and automated provisioning workflows. GigaVUE Cloud Suite follows a third-party orchestration model that allows GigaVUE V Series, GigaVUE Universal Cloud Tap, and supporting components to be provisioned manually or through established automation frameworks such as Terraform and Ansible.
After deployment, GigaVUE-FM fabric manager provides centralized registration, health monitoring, topology visibility, and traffic policy management across OCI and hybrid cloud environments. This separation between infrastructure provisioning and visibility management allows cloud teams to maintain existing OCI automation practices while providing security and operations teams with centralized control over how network-derived telemetry is acquired, processed, and distributed.
Building a Stronger Operational Foundation for OCI
As OCI deployments expand, combining OCI-native telemetry with network-derived telemetry gives teams a fuller view of application communications, workload behavior, and infrastructure activity.
Together, these capabilities help organizations strengthen security operations, improve application observability, and maintain consistent visibility as OCI deployments evolve.
FAQ
What Does Network Visibility Add to OCI Observability?
- Visibility into East-West communications between OCI workloads
- Packet, flow, and application metadata for security investigations
- Visibility into encrypted and mTLS-protected workload traffic
- Optimized telemetry delivery to existing security and observability tools
- Consistent visibility across OCI and on-premises infrastructure
CONTINUE THE DISCUSSION
People are talking about this in the Gigamon Community’s Security group.
Share your thoughts today