# Oracle

> Connect Oracle to sanda: what to prepare, the fields the connection form asks for, and how its data lands in your warehouse.

## Connect Oracle

:::steps
1. **Open the catalogue.** In the console, go to **Data · Connections** and press **New connection**.
2. **Choose Oracle.** It is listed under databases; you can also search for it by name.
3. **Fill in the form.** Enter the fields below. Credentials go straight to sanda’s sync engine and are never stored in sanda’s database.
4. **Choose what to sync.** Pick the streams you want, and a sync mode for each. See [choose what to sync](https://docs.sanda-os.com.au/connections/choose-streams).
5. **Run the first sync.** sanda tests the connection, then lands each stream as a table in your warehouse.
:::

## Configuration fields

What the connection form asks for. Required fields are marked; the rest are optional.

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **Host** | string | Yes | Hostname of the database. |
| **Port** | integer | Yes | Port of the database. Oracle recommends 1521, the default listening port for client connections to the listener, or 2484, the registered listening port for client connections using TCP/IP with SSL. Default `1521`. |
| **Connect by** | one of 2 options | No | Connect data that will be used for DB connection. |
| **User** | string | Yes | The username which is used to access the database. |
| **Password** | string, secret | No | The password associated with the username. |
| **Schemas** | array | No | The list of schemas to sync from. Defaults to user. Case sensitive. |
| **JDBC URL Params** | string | No | Additional properties to pass to the JDBC URL string when connecting to the database formatted as 'key=value' pairs separated by the symbol '&'. (example: key1=value1&key2=value2&key3=value3). |
| **Encryption** | one of 3 options | No | The encryption method with is used when communicating with the database. |
| **SSH Tunnel Method** | one of 3 options | No | Whether to initiate an SSH tunnel before connecting to the database, and if so, which kind of authentication to use. |

### Connect by

Connect data that will be used for DB connection.

Choose one of the following. Each asks for its own fields.

**Service name**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **Service name** | string | Yes |  |

**System ID (SID)**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **System ID (SID)** | string | Yes |  |


### Encryption

The encryption method with is used when communicating with the database.

Choose one of the following. Each asks for its own fields.

**Unencrypted**

No further fields.

**Native Network Encryption (NNE)**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **Encryption Algorithm** | string | No | This parameter defines what encryption algorithm is used. One of `AES256`, `RC4_56`, `3DES168`. Default `AES256`. |

**TLS Encrypted (verify certificate)**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **SSL PEM File** | string, secret | Yes | Privacy Enhanced Mail (PEM) files are concatenated certificate containers frequently used in certificate installations. |


### SSH Tunnel Method

Whether to initiate an SSH tunnel before connecting to the database, and if so, which kind of authentication to use.

Choose one of the following. Each asks for its own fields.

**No Tunnel**

No further fields.

**SSH Key Authentication**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **SSH Tunnel Jump Server Host** | string | Yes | Hostname of the jump server host that allows inbound ssh tunnel. |
| **SSH Connection Port** | integer | Yes | Port on the proxy/jump server that accepts inbound ssh connections. Default `22`. |
| **SSH Login Username** | string | Yes | OS-level username for logging into the jump server host. |
| **SSH Private Key** | string, secret | Yes | OS-level user account ssh key credentials in RSA PEM format ( created with ssh-keygen -t rsa -m PEM -f myuser_rsa ). |

**Password Authentication**

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| **SSH Tunnel Jump Server Host** | string | Yes | Hostname of the jump server host that allows inbound ssh tunnel. |
| **SSH Connection Port** | integer | Yes | Port on the proxy/jump server that accepts inbound ssh connections. Default `22`. |
| **SSH Login Username** | string | Yes | OS-level username for logging into the jump server host. |
| **Password** | string, secret | Yes | OS-level password for logging into the jump server host. |


## Related

:::links
- [Sync modes](https://docs.sanda-os.com.au/connections/sync-modes): How sanda reads each stream on every run.
- [Sync schedules](https://docs.sanda-os.com.au/connections/schedules): How often a connection runs.
- [Allowlist sanda’s address](https://docs.sanda-os.com.au/connections/allowlist): For a system behind a firewall.
- [Troubleshoot connections](https://docs.sanda-os.com.au/connections/troubleshooting): What an error means and how to fix it.
:::
