I am currently facing an issue in which a particular user (still active in JIRA) who used to be a JIRA admin but terminated employment in May 2019, is somehow still being logged in between once to twice a week automatically, even though his AD password expired in July.
I have checked if this jira admin has scripts running under his name or post functions through the script registry, however nothing was found. As well as the logs in JIRA for any user activity and the logs show as follows:
Security log: 2019-08-07 13:31:55,404 http-nio-8080-exec-4527 <username> 811x5140428x2 12di4n0 <Jira node IP>, <Jira node IP> /sr/jira.issueviews:searchrequest-xml/temp/SearchRequest.xml HttpSession [12di4n0] destroyed for '<username>'
Access log: <Jira node IP> o716x753862x3 <username> [14/Aug/2019:11:56:00 +0200] "GET https://<hostname>/sr/jira.issueviews:searchrequest-xml/temp/SearchRequest.xml HTTP/1.0" 200 1677 0.0620 - "Apache-HttpClient/4.5.5 (Java/1.8.0_202)" "szlg9k"
I do not wish to delete the user, as this is not the first encounter of such issue, and deleting the user will solve the issue, however will not explain the root cause of this. Also, if something underlying is running under his name, it will create another problem.
Any ideas of what can I check further to find out the cause please? Thank you.