Project team walking through a plan in a boardroom session
Oracle · VMware Audit Evidence · Sub

The Evidence Pack That Defends a Contained Oracle VMware Estate at Audit

Oracle GLAS opens VMware audits by pricing every reachable host, inflating the claim 4 to 10 times over a contained architecture. This is the documentation that proves your boundary and drives the settlement down to 10 to 25 percent of the opening position.

Contact Us Oracle Hub
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Independent

Oracle GLAS opens VMware audits by pricing every reachable host, inflating the claim 4 to 10 times over a contained architecture. This is the documentation that proves your boundary and drives the settlement down to 10 to 25 percent of the opening position.

Containment without evidence is a story you cannot prove. In 25 years of negotiating VMware findings against Oracle, the estates that settled cheaply were not the ones with the cleverest legal arguments about whether the partitioning policy is binding. They were the ones that walked into the first call with a topology file already built: cluster maps, host inventory, DRS and affinity exports, vMotion boundary configuration, and a dated change log proving the boundary held over time. Oracle's default position is that every physical core in every reachable cluster must be licensed. Your job is to make that position expensive for them to hold by putting provable facts on the table before their tools ever run.

This page assumes you have already read the containment architecture in our dedicated Oracle VMware cluster design guide. Here we focus on one thing: the specific documents that survive a GLAS challenge, how to assemble them before a notice arrives, and where each item moves the number. If you have not yet contained the estate, start with the contain it then prove it framework and the post-Broadcom exposure map.

Why the Evidence Pack Decides the Number

The financial stakes are large enough that documentation quality is worth six or seven figures. Oracle Database Enterprise Edition lists at $47,500 per processor in 2026, with a 0.5 core factor on most modern CPUs (two cores equal one licensed processor). A ten-host cluster with two 16-core processors per host produces 160 processor licenses, roughly $7.6M at list plus 22 percent annual support (about $1.67M per year, escalating at 8 percent). Those figures come from published 2026 pricing. The point is not the exact number, it is the multiplier: Oracle prices the whole reachable pool, not the hosts actually running the database.

Independent engagement data tells the story consistently. Soft-partitioned estates face opening license claims a median 3.5 times the cores actually running Oracle, and where vMotion or Storage vMotion reach is unbounded the opening position inflates 4 to 10 times over the contained architecture. The typical first VMware finding on a mid-sized enterprise lands between $5M and $40M depending on cluster size and vCenter topology. Estates with dedicated Oracle clusters and documented migration boundaries settle that VMware question at 10 to 25 percent of the opening claim. The difference between paying 25 percent and paying full list is almost entirely a function of what you can prove.

Contained estates settle the VMware question at 10 to 25 percent of the opening claim. The gap between those numbers is not argument, it is documentation.

The Contract Anchor Your Evidence Supports

Understand what your documents are proving against. Oracle's partitioning policy classifies all VMware products as soft partitioning, so in Oracle's stated view licensing follows where a VM could run, not where it does. But that policy is not contractual. It carries its own disclaimer that it is "for educational purposes only," and most Oracle ordering documents never mention VMware or virtualization at all. The binding language is the definition of Processor: "all processors where the Oracle Programs are installed and/or running." Oracle counsel stretched this in the Mars dispute to mean "available for use," but that is an argument, not a signed term.

Your evidence pack does not win by arguing the policy is void. In practice, arguing the policy is not binding rarely lowers the claim on its own. The pack wins by proving a factual boundary: that the Oracle programs are installed and running on a defined set of physical cores, that no migration path exists to unlicensed hosts, and that this state held continuously. That factual record converts an abstract "could run" argument into a concrete "did not and could not run" position that GLAS has to disprove. The mechanics of Oracle's cluster-scope claim are covered in why Oracle says the whole cluster could run the database.

The Six Documents That Actually Hold Up

An evidence pack that survives a GLAS challenge contains six items, each answering a specific question the auditor will ask. Assemble all six as static, dated exports. Live screen-shares during an audit call are worthless as evidence; timestamped exports retained on your side are not.

Evidence item What it proves GLAS question it answers
Cluster topology mapThe physical and logical boundary of every cluster where Oracle is installedWhere can this software run?
Host inventory exportExact CPU model, socket, and core count per host in the Oracle clusterHow many cores are we licensing?
DRS and affinity configuration exportVM-to-Hosts "must" rules binding Oracle VMs to the licensed host groupWhat stops migration to other hosts?
vMotion / Storage vMotion boundary configMigration reach is disabled or bounded to the licensed clusterCan a VM move to an unlicensed host?
Change log / configuration historyThe boundary held continuously across the audit periodWas this true the whole time or just today?
Continuous monitoring outputNo Oracle VM ever crossed the boundary in operationDid any breach actually occur?

1. Cluster topology map

Map every cluster where Oracle is installed or could migrate, and draw the boundary explicitly. Show the vCenter, the clusters, the hosts, the datastores, and any cross-cluster migration links. This is the document that reframes the conversation from "your whole environment" to "this defined set of hosts." It must reflect the Broadcom-era consolidation you have done; larger consolidated clusters widen the Oracle count, so if you have shrunk the Oracle footprint deliberately, show the before and after. The cluster-sizing dynamic is detailed in how vSphere 8 consolidation widens your Oracle license count.

2. Host inventory export

Produce a per-host inventory listing CPU model, socket count, and physical core count for every host inside the Oracle boundary, plus the applicable core factor. This is the arithmetic base of your position. It also lets you challenge Oracle's own count line by line rather than accepting a lump figure. Oracle auditors routinely price hosts that are physically incapable of running the Oracle VMs; a clean inventory strips those out.

3. DRS and affinity configuration export

Export the VM-to-Hosts affinity rules, specifically the hard "must run on hosts in group" and "must not run on hosts in group" rule types. A hard must-rule cannot be violated by a user-initiated migration; an attempt to move a VM outside the host group is blocked, and must-rules remain tracked by the host even after DRS is disabled. Be honest about the limit here: Oracle explicitly disallows software-based controls, DRS rules, CPU affinity, and CPU pinning as licensing limits, and has told customers directly that it does not accept VMware as a hard partitioning technology at all. So this export does not win alone. It matters as corroborating evidence that migration was blocked in practice and as leverage in settlement, and it directly rebuts a "could run anywhere" claim by showing the technical constraint that was in force.

4. vMotion and Storage vMotion boundary configuration

This is the most load-bearing document after the topology map. vMotion, DRS, and HA all extend Oracle's scope claim across the cluster because the software "could run" on any host. Worse, vSphere 6.0 and later extend the cluster boundary across data centers when Storage vMotion and shared datastores are enabled, and long-distance vMotion widens the pool further. Export the configuration proving migration is disabled or bounded to the licensed hosts, and confirm no shared datastore silently bridges the Oracle cluster to unlicensed hosts. The hidden-scope risk from shared storage is covered in our Storage vMotion scope expander analysis.

5. Change log and configuration history

A single point-in-time export proves the boundary today. It does not prove the boundary held across the audit lookback period, which is where GLAS will push. Retain dated change records showing that the cluster composition, affinity rules, and migration configuration remained stable, and that any changes preserved the boundary. Without this, Oracle argues that even if you are contained now, you were exposed for the period they are auditing. This is the single most commonly missing item, and its absence routinely costs clients the difference between a 15 percent and a 40 percent settlement in my experience.

6. Continuous monitoring output

If an Oracle VM ever moves to an unlicensed host, it is out of compliance for that period regardless of your intent. Containment must be paired with monitoring that proves no breach occurred. Affinity rule violations produce log events; capture and retain them (or their absence). This monitoring output is both operational insurance and audit evidence: it demonstrates the boundary was not merely configured but observed to hold.

Assemble It Before the Notice, Not After

The standard OMA audit clause gives Oracle the right to audit on 45 days written notice, requires that the audit not unreasonably interfere with normal business operations, and obliges you to cooperate including, but not limited to, running Oracle data measurement tools. That 45-day window is not enough time to build a credible evidence pack from scratch, especially the change log and monitoring history, which by definition must have been accumulating already. Build the pack now, refresh it quarterly, and store it where you control it.

Note two rights that shape how you use the pack. First, you can run your own tools and provide Oracle a curated output that satisfies the contractual obligation without volunteering more than the clause requires. Oracle's measurement scripts (the USMM and its equivalents) collect broadly; a client-side equivalent lets you meet the obligation while controlling scope. Second, the same discipline that traps VMware findings also traps the options and packs that ship enabled by default, so treat your evidence pack as part of a wider audit posture, not a VMware-only exercise. See the options and packs audit trap and the broader Oracle pitfalls that print invoices.

The 45-day notice window is not enough time to invent a change log. The evidence must already exist when the letter arrives.

What the Evidence Does in the Negotiation

GLAS opens by pricing the full reachable pool. A complete evidence pack changes the sequence of the conversation. Instead of debating whether the partitioning policy binds you, you present a bounded set of hosts with proof that Oracle could not run outside it. Oracle's opening claim, inflated 4 to 10 times, becomes indefensible line by line: the hosts they priced are either outside the boundary, physically incapable, or contradicted by your dated configuration exports. That is what drives settlements to 10 to 25 percent of the opening position.

Be realistic about what the pack does and does not do. It does not make Oracle concede that its partitioning policy is invalid; Oracle will not sign that. What it does is shift the commercial reality. Oracle would rather settle a contained, well-documented estate at a fraction of the opening claim than litigate the "available for use" theory against a client with clean evidence. The pack raises Oracle's cost of pursuing the full figure, and that cost is your leverage. Weigh the settled cost against the alternative of moving the workload; the VMware versus OCI cost comparison is the calculation to run if the number stays high.

What to Do This Quarter

  • Map every cluster where Oracle is installed or could migrate, and confirm the boundary against your actual vMotion and shared-datastore configuration.
  • Export the host inventory (CPU model, sockets, cores, core factor) for the Oracle boundary and reconcile it against your license entitlements today.
  • Configure hard must-run affinity rules and disable or bound migration to the licensed hosts, then export the configuration as dated evidence.
  • Stand up continuous monitoring that logs any Oracle VM crossing the boundary and retain the output.
  • Start the change log now: the audit lookback will demand proof the boundary held over time, and you cannot backfill history.
  • Rehearse the audit sequence before any notice arrives, deciding who runs the client-side tooling and what curated output you will provide.

Containment is the architecture; the evidence pack is the proof. Build both before the 45-day clock starts, and the VMware finding becomes a negotiation you control rather than an invoice you absorb.

Frequently asked questions

Does a DRS affinity rule prove containment to Oracle?

Not on its own. Oracle explicitly disallows software-based controls including DRS rules and CPU affinity as licensing limits, and has stated it does not accept VMware as a hard partitioning technology. The affinity export still matters as corroborating evidence that migration was technically blocked, and it strengthens your settlement position, but it must be paired with vMotion boundary configuration, a change log, and monitoring output.

What documents does Oracle GLAS challenge most aggressively?

The change log and configuration history. A point-in-time export proves the boundary exists today but not that it held across the audit lookback period, which is exactly where GLAS pushes. Because you cannot backfill history, the absence of a dated change log routinely costs clients the difference between a 15 percent and a 40 percent settlement.

Can I run my own tools instead of Oracle's audit scripts?

Yes. You have the right to run client-side equivalents of Oracle's measurement tools and provide a curated output that satisfies the contractual cooperation obligation without volunteering more than the clause requires. Oracle's own scripts collect broadly, so controlling the tooling lets you meet the obligation while managing scope.

How much can a complete evidence pack reduce an Oracle VMware claim?

Opening claims on soft-partitioned estates run a median 3.5 times the cores actually running Oracle, and up to 4 to 10 times where migration reach is unbounded. Estates with dedicated clusters and documented boundaries settle the VMware question at 10 to 25 percent of the opening claim. The reduction is almost entirely a function of what you can prove.

How long before a notice should I build the pack?

Immediately, and refresh it quarterly. The standard audit clause gives Oracle 45 days written notice, which is not enough time to build a credible pack from scratch, particularly the change log and monitoring history, which by definition must already be accumulating. Build it now and store it where you control it.

Does Storage vMotion affect what I need to document?

Significantly. vSphere 6.0 and later extend the cluster boundary across data centers when Storage vMotion and shared datastores are enabled, so a shared datastore can silently bridge your Oracle cluster to unlicensed hosts. Your evidence pack must confirm that no shared storage extends the boundary beyond the licensed hosts.

Free White Paper

Oracle Database Options & Management Packs: the accidental-use audit trap

The separately-licensed options and packs that ship enabled by default, get switched on with a single click, and become the single largest line item in most Oracle audit findings.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, your side. We never share your details with vendors.
Run a software spend health check against your Oracle estate in under five minutes.
Open the Tool →
Deep Library

More on this topic.

Oracle Hub →
Oracle Database on VMware After Broadcom: The 2026 Licensing Exposure Map
Oracle · Guide
Oracle Database on VMware After Broadcom: The 2026 Licensing Exposure Map
The full guide this article belongs to.
Guide
How vSphere 8 Cluster Consolidation Widens Your Oracle License Count
Oracle · Deep dive
How vSphere 8 Cluster Consolidation Widens Your Oracle License Count
Another angle on the same decision.
Guide
vMotion and DRS: Why Oracle Says the Whole Cluster Could Run the Database
Oracle · Deep dive
vMotion and DRS: Why Oracle Says the Whole Cluster Could Run the Database
Another angle on the same decision.
Guide
Defending IBM Sub Capacity Pricing With ILMT Evidence That Holds in an Audit
Oracle
Defending IBM Sub Capacity Pricing With ILMT Evidence That Holds in an Audit
ILMT is the condition for IBM sub capacity pricing. The 90 day install window, quarterly s
Guide
Oracle on VMware. After Broadcom.
Oracle
Oracle on VMware. After Broadcom.
Oracle on VMware in 2026. Soft partitioning policy, cluster licensing math, audit risk pos
Guide
Oracle on VMware. Contain it, then prove it.
Oracle
Oracle on VMware. Contain it, then prove it.
Oracle claims every reachable VMware host; the contract says otherwise. Containment archit
Guide
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Oracle licensing changes.

One your side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.