Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Atlassian Guard - SIEM webhooks - Empty payload

Jesus Martin Jurado
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
May 25, 2026

Hello,

I am integrating Atlassian Guard Detect alerts into a SIEM (NGSIEM / Falcon LogScale) using the official guidance here:
https://support.atlassian.com/security-and-access-policies/docs/send-alerts-to-a-siem-slack-or-other-tools/

However, the events we receive appear to be missing the actual payload (JSON body) and only contain metadata.

The times of the events received in our SIEM match the timestamps of the alerts in atlassian guard dashboard, but the events received are empty, have no payload/rawstring.

1 answer

0 votes
Arkadiusz Wroblewski
Community Champion
May 30, 2026

Hello and welcome to the Community @Jesus Martin Jurado 

Which Atlassian Guard tier (Standard or Premium) are you using, and which specific Falcon LogScale ingestion endpoint are you targeting?

Have you tried testing the Guard Detect webhook with a neutral receiver like webhook.site to see if the JSON payload actually shows up? If the payload is visible there, issue could be on the LogScale parsing side or if it's empty there too. should we have Atlassian Support look into the backend webhook delivery? (Did you have Opened ticket?)

Best,

Arkadiusz 🤠☀️

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events