---
title: Oracle Fusion Applications
description: >-
  Oracle Fusion Cloud Applications is a suite of business applications built on
  Oracle Cloud Infrastructure (OCI)
breadcrumbs: Docs > Integrations > Oracle Fusion Applications
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Oracle Fusion Applications
Supported OS Integration version1.0.0
{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}
  Oracle Fusion ESS Overview DashboardOracle Fusion ESS Overview Dashboard
## Overview{% #overview %}

Oracle Fusion Cloud Applications is a suite of cloud-based enterprise applications built on Oracle Cloud Infrastructure (OCI). It spans enterprise resource planning (ERP), supply chain management and manufacturing (SCM), human capital management (HCM), customer experience (CX), and enterprise performance management (EPM).

The Datadog Oracle Fusion Cloud Applications integration provides valuable insights into your Oracle Fusion and EPM environments by:

- Monitoring Enterprise Service Scheduler (ESS) jobs across 4 business applications: ERP, SCM, HCM, and CX
- Monitoring EPM jobs across five module types: FCCS, Planning, FreeForm, Tax Reporting, and EPCM, covering most [job types](https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/prest/pbcs_export_job_console_job.html)
- Helping identify bottlenecks and performance impact
- Auditing user activity including sign-in events, target user changes, user role assignment changes, and metadata permission checks

**Note**: The [Oracle Cloud Infrastructure Integration](https://docs.datadoghq.com/integrations/oracle-cloud-infrastructure.md) collects OCI metrics from the `oci_fusion` namespace. OCI audit logs include Oracle Fusion and EPM sign-in events.

After parsing your Oracle Fusion Cloud Applications and Oracle Fusion EPM data, Datadog populates an out-of-the-box **Oracle Fusion Overview** dashboard. The integration also offers recommended monitors to help you get started with alerting on ESS and EPM job performance, enabling proactive management and improved operational efficiency.

To set up the integration, visit the [Oracle Fusion Applications](https://app.datadoghq.com/integrations/oracle-fusion/) integration tile and add a new account.

## Setup{% #setup %}

To set up the integration, visit the [Oracle Fusion Applications](https://app.datadoghq.com/integrations/oracle-fusion/) integration tile and add a new account.

### Onboarding overview{% #onboarding-overview %}

Integration accounts are scoped by *OCI Identity Domain*, meaning that if an Oracle Fusion and Oracle EPM instance share an OCI identity domain, they must share a single Datadog account. However, Datadog accounts can also be configured to monitor only Fusion or only EPM.

### Required permissions{% #required-permissions %}

To run the onboarding script, you must have the **Identity Domain Administrator** role for the OCI identity domain, the **Service Administrator** role for the Oracle EPM instance, and access to **IT Security Manager** credentials for the Oracle Fusion instance.

You must also configure OCI CLI credentials for the tenancy. For instructions, see [Setting up the Configuration File](https://docs.oracle.com/en-us/iaas/Content/API/SDKDocs/cliinstall.htm#configfile).

### Creating the confidential application{% #creating-the-confidential-application %}

Datadog's onboarding script creates a confidential application, which enables Datadog to configure OAuth for your Fusion and EPM instances. The confidential application is used to generate client credentials, scoped to only the specified Fusion and EPM instances.

### Creating the Oracle Fusion user{% #creating-the-oracle-fusion-user %}

After creating the confidential application, the script creates a user in your Oracle Fusion instance with client ID matching the confidential application, enabling OAuth access to the instance.

### Creating the Datadog integration role{% #creating-the-datadog-integration-role %}

You must manually create a custom role, which the onboarding script automatically assigns to your user. To create the custom role:

1. Log in to Oracle Fusion as an administrator.
1. Navigate to: **Navigator** > **Tools** > **Security Console** > **Roles** > **Create Role**.
1. Set the following:
   - Role Name: Enter any descriptive name
   - Role Code: `DD_INTEGRATION_ROLE` (must be exactly this value)
   - Role Category: Default
1. Under **Role Hierarchy**, add the following three roles by their role codes:
   - `ESSMonitor`
   - `ORA_FND_INTEGRATION_SPECIALIST_JOB`
   - `ORA_FND_INTERNAL_AUDITOR_JOB`**Note**: Oracle Fusion may automatically add sub-roles for these roles. This is expected. Keep all sub-roles that are added.
1. Click **Save**.
1. Make the role API-assignable through Role Provisioning Rules:
   1. Go to **Setup and Maintenance** and search for **Manage Role Provisioning Rules**.
   1. Click **Add** to create a new mapping, and set the following values:
      - Mapping Name: DD Integration Role Mapping (or any descriptive name)
      - From Date: Enter today's date
      - Conditions: Leave blank
   1. Under **Associated Roles**, click **Add Row** and search for the custom role you created.
   1. Select **Requestable**, leave all other checkboxes unchecked, and click **Save and Close**.

### Required roles{% #required-roles %}

| Role                   | Code                                 | Purpose                               |
| ---------------------- | ------------------------------------ | ------------------------------------- |
| ESS Monitor            | `ESSMonitor`                         | Read ESS job requests and job logs    |
| Integration Specialist | `ORA_FND_INTEGRATION_SPECIALIST_JOB` | Access ERP Integration REST endpoints |
| Internal Auditor       | `ORA_FND_INTERNAL_AUDITOR_JOB`       | Read-only access to audit data        |

### Creating the Oracle Fusion EPM user{% #creating-the-oracle-fusion-epm-user %}

After creating the Oracle Fusion user, an associated user is automatically generated in the OCI identity domain. Datadog's onboarding script then adds this user to the EPM instance by assigning the **Service Administrator** role, which is necessary for accessing any job or audit reports. After assigning the EPM role, you *must* navigate to **Tools** > **Access Control** > **Role Assignment Report**, and verify the Datadog integration user is present. Otherwise, Oracle EPM does not automatically register the new user.

**Note**: If Oracle Fusion is not configured, the script generates a new OCI user associated with the confidential application. This role is then added to the EPM instance users.

### Account tags{% #account-tags %}

After your Oracle Fusion account is configured, you can add **Account Tags** from the [Oracle Fusion Applications](https://app.datadoghq.com/integrations/oracle-fusion/) integration tile. Select your account, then enter a comma-separated list of `<KEY:VALUE>` tags. These tags are applied to all metrics, logs, and resources collected from the account.

## Data Collected{% #data-collected %}

### Metrics{% #metrics %}

|  |
|  |
| **oracle.fusion.ess.jobs**(count)                                  | The number of Oracle Fusion ESS jobs that transitioned to the given state within the reporting window.*Shown as job*                                                                                   |
| **oracle.fusion.ess.job.execution_attempt**(gauge)                | The maximum number of execution attempts for Oracle Fusion ESS jobs that reached a terminal state.                                                                                                     |
| **oracle.fusion.ess.job.retried_count**(gauge)                    | The total number of retries for Oracle Fusion ESS jobs that reached a terminal state.                                                                                                                  |
| **oracle.fusion.ess.job.elapsed_time**(gauge)                     | The maximum elapsed time for Oracle Fusion ESS jobs that reached a terminal state.*Shown as millisecond*                                                                                               |
| **oracle.fusion.epm.jobs**(count)                                  | The number of Oracle Fusion EPM Hyperion Planning (HPL) jobs observed within the reporting window. Includes in-progress jobs.*Shown as job*                                                            |
| **oracle.fusion.epm.job.elapsed_time**(gauge)                     | The maximum elapsed time for Oracle Fusion EPM HPL jobs that reached a terminal state.*Shown as millisecond*                                                                                           |
| **oracle.fusion.avg_application_response_time_monthly**(gauge) | Average server response time for all HTTP requests in a production instance for a calendar month. Excludes reports, analytics, document parsing, data integration, and searches.*Shown as millisecond* |
| **oracle.fusion.environment_availability_status**(gauge)         | Availability status of the Fusion Applications environment.                                                                                                                                            |
| **oracle.fusion.service_availability**(gauge)                     | Monthly Service Availability Level expressed as an uptime percentage.*Shown as percent*                                                                                                                |

## Uninstallation{% #uninstallation %}

In addition to uninstalling the tile, deleting credentials, or both, consider deleting the confidential application created in your OCI identity domain and the associated integration user.

## Support{% #support %}

**Need help?** Contact [Datadog support](https://docs.datadoghq.com/help/).

**To set up the integration**, visit the [Oracle Fusion Applications](https://app.datadoghq.com/integrations/oracle-fusion/) integration tile and add a new environment.

**Missing Oracle Fusion EPM data?** In your Oracle Fusion EPM instance, navigate to **Tools** > **Access Control** > **Role Assignment Report**, and verify that the Datadog integration user is present. Opening the report triggers a user sync, which EPM does not perform automatically.

**Missing audit events?**

- For Oracle Fusion: Navigate to **Setup and Maintenance**, search for **Manage Audit Policies**, and set all audit levels to high
- For Oracle Fusion EPM: Navigate to **Tools** > **Audit** > **Enable Auditing** > **Enable for all services**
- Oracle Fusion and EPM user sign-in events can be monitored through the [Oracle Cloud Infrastructure integration](https://docs.datadoghq.com/integrations/oracle-cloud-infrastructure.md)

**Missing ESS data?**

- Datadog automatically removes the `requestParameters` field on ESS events exceeding the maximum size allowed by Datadog logs intake.

**Note**: Oracle Fusion ERP, SCM, HCM, and CX data is collected every 5 minutes or less. Oracle Fusion EPM data is collected hourly.

### Troubleshooting{% #troubleshooting %}

The following are health reporting errors you may encounter on your Oracle Fusion / Fusion EPM integration tile and their solutions.

##### If you have EPM configured, start here:{% #if-you-have-epm-configured-start-here %}

Add your EPM base URL as a secondary audience so EPM accepts the confidential app's tokens. In the OCI Console, go to **Domains** > **Oracle Cloud Services** > **`<Your EPM Instance>`** > **OAuth Configuration**, and paste [https://epmprod-dd-dev-eci-fusion.epm.us-ashburn-1.ocs.oraclecloud.com](https://epmprod-dd-dev-eci-fusion.epm.us-ashburn-1.ocs.oraclecloud.com) as a secondary audience. This can only be done while signed in as a user of the identity domain that the EPM instance resides in. Until this is done, Datadog will default to HTTP Basic Auth through the provisioned integration user for EPM monitoring.

##### `failed to obtain Oracle [Fusion / Fusion EPM] OAuth token: credentials are valid but lack the required OAuth scope or permission.`{% #failed-to-obtain-oracle-fusion--fusion-epm-oauth-token-credentials-are-valid-but-lack-the-required-oauth-scope-or-permission %}

- **Type**: 403 Forbidden from the Oracle Fusion OAuth token endpoint
- **Description**: The credentials authenticate successfully, but the associated OAuth scopes or permissions are insufficient to obtain a token.
- **Remediation**: Run the Oracle Fusion repair script to re-provision OAuth scopes and permissions.

##### `failed to obtain Oracle [Fusion / Fusion EPM] OAuth token: credentials are likely wrong or expired.`{% #failed-to-obtain-oracle-fusion--fusion-epm-oauth-token-credentials-are-likely-wrong-or-expired %}

- **Type**: 401 Unauthorized from the Oracle Fusion OAuth token endpoint
- **Description**: The credentials were rejected during token retrieval, likely because they are incorrect or expired.
- **Remediation**: Run the Oracle Fusion repair script to re-provision OAuth scopes and permissions.

##### `Oracle [Fusion / Fusion EPM] [stream name] stream returned 401 Unauthorized`{% #oracle-fusion--fusion-epm-stream-name-stream-returned-401-unauthorized %}

- **Type**: 401 Unauthorized from the Oracle Fusion REST API; stream is known
- **Description**: The REST API rejected the request for the named stream, likely because the OAuth token or the permissions backing it are no longer valid for the stream's resources.
- **Remediation**: Verify that the OAuth token and Oracle Fusion permissions required by the stream are still valid. If that doesn't work, run the Oracle Fusion repair script.

##### `Oracle [Fusion / Fusion EPM] API request was rejected (token invalid or expired)`{% #oracle-fusion--fusion-epm-api-request-was-rejected-token-invalid-or-expired %}

- **Type**: 401 Unauthorized from the Oracle Fusion REST API; stream is unknown
- **Description**: The REST API rejected a request, likely because the OAuth token is invalid or expired, and the originating stream could not be identified.
- **Remediation**: Run the Oracle Fusion repair script to re-provision OAuth scopes and permissions.

##### `Oracle [Fusion / Fusion EPM] [stream name] stream returned 403 Forbidden`{% #oracle-fusion--fusion-epm-stream-name-stream-returned-403-forbidden %}

- **Type**: 403 Forbidden from the Oracle Fusion REST API; stream is known
- **Description**: The credentials authenticate, but the user backing the named stream lacks the roles or permissions required to access that stream's resources.
- **Remediation**: Verify that you created a user in the Fusion App Security Console whose username matches your OAuth `client_id` and that you assigned the appropriate roles.

##### `Oracle [Fusion / Fusion EPM] API request was rejected (insufficient permissions)`{% #oracle-fusion--fusion-epm-api-request-was-rejected-insufficient-permissions %}

- **Type**: 403 Forbidden from the Oracle Fusion REST API; stream is unknown
- **Description**: The REST API rejected a request because the authenticated user lacks the roles or permissions required for the requested resource, and the originating stream could not be identified.
- **Remediation**: Run the Oracle Fusion repair script to re-provision OAuth scopes and permissions, then grant the Oracle Fusion user the REST API role or duty required for this resource and verify the integration in the Datadog Oracle Fusion Cloud integration tile.

#### Oracle Fusion Repair Script (Fusion and EPM){% #oracle-fusion-repair-script-fusion-and-epm %}

Execute this script in your terminal after filling in the placeholder fields.

```bash
export DD_API_KEY=<DD_API_KEY>
export DD_APP_KEY=<DD_APP_KEY>
export DD_SITE=<DD_SITE>
bash <(curl -fsSL https://raw.githubusercontent.com/DataDog/integrations-management/main/oracle_fusion/integration_quickstart/setup.sh) \
  --account-name '<your-datadog-account-name>' \
  --fusion-admin-username '<your-username>' \
  --fusion-admin-password '<your-password>' \
  --fix
```

#### Oracle Fusion Repair Script (EPM Only){% #oracle-fusion-repair-script-epm-only %}

Execute this script in your terminal after filling in the placeholder fields.

```bash
export DD_API_KEY=<DD_API_KEY>
export DD_APP_KEY=<DD_APP_KEY>
export DD_SITE=<DD_SITE>
bash <(curl -fsSL https://raw.githubusercontent.com/DataDog/integrations-management/main/oracle_fusion/integration_quickstart/setup.sh) \
  --account-name '<your-datadog-account-name>' \
  --fix
```

Note that `<DD_SITE>` is the hostname that your app is served for. Examples include datadoghq.com, datadoghq.eu, us3.datadoghq.com, etc.

## Further Reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Monitor Oracle Fusion Cloud Applications with Datadog](https://www.datadoghq.com/blog/oracle-fusion-applications-integration/)
