Task:
We are attempting to integrate Jira Cloud authentication event logs into our on-premise Splunk instance using heavy forwarders.
Blockers:
During my search for technical documentation, I found an article published in March 2020 that explicitly states Jira Cloud logs are not available for integration with Splunk, as they are maintained and monitored by Jira and hosted online. This poses a significant challenge for our security team, as integrating Jira authentication log events into our SIEM platform is crucial for compliance. The specific blockers we are facing are:
- Lack of official documentation on Jira.
- Absence of an official Splunk Add-on available on the Atlassian Marketplace.
Available Solution:
We need to identify a solution or an official workaround to integrate these logs into our SIEM portal, are there any options to do this?