---
title: Install & configure NRDOT for Oracle monitoring with Ansible
source: https://docs.newrelic.com/docs/opentelemetry/db360/oracle/ansible
---

You can install and configure the NRDOT Collector for Oracle Database monitoring using the `newrelic.newrelic_install` Ansible role. The role installs the collector, creates the monitoring database user, and configures the collector in a single play.

## Prerequisites [#prerequisites]

-   A New Relic account with a valid [license key](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#overview-keys).
-   A New Relic [account ID](https://docs.newrelic.com/docs/accounts/accounts-billing/account-structure/account-id).
-   Oracle Database 19c or later.
-   Ansible Core 2.13 or 2.14, Python 3.10, and the `ansible.windows` and `ansible.utils` collections.
-   For self-hosted Oracle: Oracle Linux 7, 8, or 9, with SSH access (with agent forwarding) to the Oracle Database host where the SSH user can run `sudo su - oracle` without a password prompt.
-   For Oracle on AWS RDS: a collector host running Debian/Ubuntu or CentOS/RHEL/OEL.
-   For Oracle Autonomous Database (ADB): a collector host running Debian/Ubuntu or CentOS/RHEL/OEL, with Oracle Instant Client (`sqlplus`) installed and on `PATH`; each instance's egress IP allowed in its ADB access control list; and each instance's Oracle Wallet downloaded and unzipped to its own directory on the target host.

## Install the role [#install-role]

```bash
ansible-galaxy install newrelic.newrelic_install
```

## Configure the playbook [#configure]

**Self-hosted Oracle Database**

This role monitors one or more Oracle Database instances (each reachable via SSH) from a single collector. Instead of a single host/container/credential set, it reads an instances file (YAML) that must already exist on the target host, listing every instance to monitor, and optionally a secrets file to pin monitoring-user passwords instead of auto-generating them. See the [CLI install](https://docs.newrelic.com/docs/opentelemetry/db360/oracle/cli/#install) for the exact file formats.

Create a file named `playbook.yml` and copy the following content into it. Set `targets` to `oracle-otel` and replace the placeholder values with your own:

```yaml
- name: Install New Relic NRDOT for Oracle Database
  hosts: all
  roles:
    - role: newrelic.newrelic_install
  vars:
    targets:
      - oracle-otel
  environment:
    NEW_RELIC_API_KEY: <API key>
    NEW_RELIC_ACCOUNT_ID: <Account ID>
    NEW_RELIC_REGION: <Region>
    NR_CLI_ORACLE_INSTANCES_FILE: <path to the instances YAML file on the target host>
    NR_CLI_ORACLE_SECRETS_FILE: <optional path to a secrets file pinning monitoring passwords, on the target host>
    NR_CLI_ORACLE_CONFIG_PRESET: <1 Basic, 2 Advanced, default 1>
```

> #### 💡 TIP
>
> To enable debug logging, add `verbosity: "debug"` under `vars` in the playbook.

| Variable                       | Description                                                                                                                                                                                                    | Default |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `NR_CLI_ORACLE_INSTANCES_FILE` | Required. Path to the instances YAML file, already present on the target host.                                                                                                                                 | None    |
| `NR_CLI_ORACLE_SECRETS_FILE`   | Optional. Path to a secrets file (`KEY=VALUE`) pinning `NR_CLI_ORACLE_LOGIN_PASSWORD_<i>` per instance, already present on the target host. Leave unset to auto-generate a random password for every instance. | None    |
| `NR_CLI_ORACLE_CONFIG_PRESET`  | NRDOT configuration: 1 for Basic 2 for Advanced                                                                                                                                                                | `1`     |

> #### 💡 TIP
>
> To monitor more than one Oracle Database instance from this collector, add more entries to the instances file. An instance that fails its checks is skipped with a logged reason rather than aborting the whole install.

**Oracle Database on AWS RDS**

This role monitors one or more RDS Oracle endpoints from a single collector, using the same instances file / secrets file pattern as self-hosted (both files must already exist on the target host). Create a file named `playbook.yml` and copy the following content into it. Set `targets` to `oracle-otel-rds` and replace the placeholder values with your own:

```yaml
- name: Install New Relic NRDOT for Oracle Database on RDS
  hosts: all
  roles:
    - role: newrelic.newrelic_install
  vars:
    targets:
      - oracle-otel-rds
  environment:
    NEW_RELIC_API_KEY: <API key>
    NEW_RELIC_ACCOUNT_ID: <Account ID>
    NEW_RELIC_REGION: <Region>
    NR_CLI_ORACLE_INSTANCES_FILE: <path to the instances YAML file on the target host>
    NR_CLI_ORACLE_SECRETS_FILE: <path to the secrets file (KEY=VALUE per instance) on the target host>
    NR_CLI_ORACLE_CONFIG_PRESET: <1 Basic, 2 Advanced, default 1>
```

> #### 💡 TIP
>
> To enable debug logging, add `verbosity: "debug"` under `vars` in the playbook.

| Variable                       | Description                                                                                                                                                                                                           | Default |
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `NR_CLI_ORACLE_INSTANCES_FILE` | Required. Path to the instances YAML file, already present on the target host.                                                                                                                                        | None    |
| `NR_CLI_ORACLE_SECRETS_FILE`   | Required. Path to the secrets file (`KEY=VALUE`, one RDS master username/password pair per instance; optionally `NR_CLI_ORACLE_LOGIN_PASSWORD_<i>` to pin a monitoring password), already present on the target host. | None    |
| `NR_CLI_ORACLE_CONFIG_PRESET`  | NRDOT configuration: 1 for Basic 2 for Advanced                                                                                                                                                                       | `1`     |

> #### 💡 TIP
>
> To monitor more than one RDS Oracle endpoint from this collector, add more entries to the instances file and matching numbered credentials to the secrets file. An instance that fails its checks is skipped with a logged reason rather than aborting the whole install.

**Oracle Autonomous Database (ADB)**

This role monitors one or more Oracle Autonomous Database (ADB) instances from a single collector, using the same instances file / secrets file pattern as RDS (both files must already exist on the target host, and each instance also needs its own downloaded, unzipped Oracle Wallet on that host). See the [CLI install](https://docs.newrelic.com/docs/opentelemetry/db360/oracle/cli/#install) for the exact file formats. Create a file named `playbook.yml` and copy the following content into it. Set `targets` to `oracle-otel-adb` and replace the placeholder values with your own:

```yaml
- name: Install New Relic NRDOT for Oracle Autonomous Database
  hosts: all
  roles:
    - role: newrelic.newrelic_install
  vars:
    targets:
      - oracle-otel-adb
  environment:
    NEW_RELIC_API_KEY: <API key>
    NEW_RELIC_ACCOUNT_ID: <Account ID>
    NEW_RELIC_REGION: <Region>
    NR_CLI_ORACLE_INSTANCES_FILE: <path to the instances YAML file on the target host>
    NR_CLI_ORACLE_SECRETS_FILE: <path to the secrets file (KEY=VALUE per instance) on the target host>
```

> #### 💡 TIP
>
> To enable debug logging, add `verbosity: "debug"` under `vars` in the playbook.

| Variable                       | Description                                                                                                                                                                                                          | Default |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| `NR_CLI_ORACLE_INSTANCES_FILE` | Required. Path to the instances YAML file, already present on the target host. Each instance entry also needs `wallet_dir`: the path to that instance's unzipped Oracle Wallet.                                      | None    |
| `NR_CLI_ORACLE_SECRETS_FILE`   | Required. Path to the secrets file (`KEY=VALUE`, one ADB admin username/password pair per instance; optionally `NR_CLI_ORACLE_LOGIN_PASSWORD_<i>` to pin a monitoring password), already present on the target host. | None    |

> #### 💡 TIP
>
> There's no `NR_CLI_ORACLE_CONFIG_PRESET` for ADB: it's a fully managed service with no host to collect host-level metrics from.

> #### 💡 TIP
>
> To monitor more than one ADB instance from this collector, add more entries to the instances file and matching numbered credentials to the secrets file. An instance that fails its checks is skipped with a logged reason rather than aborting the whole install.

## Run the playbook [#run]

```bash
ansible-playbook -i <inventory_file> <playbook_file>.yml
```

To find your Oracle Database entity in New Relic, see [Find and use your data](https://docs.newrelic.com/docs/opentelemetry/db360/oracle/introduction/#find).
