Monitoring JIRA logs with Splunk

Ryan Gilliam March 24, 2020

Noob here, looking to monitor Jira logs with Splunk. I've read this article, but looking for direction as to where the Splunk UF needs to be installed to collect logs, or can we configure via REST API to pull into splunk? 

 

https://confluence.atlassian.com/adminjiraserver/audit-log-integrations-in-jira-998879037.html

3 answers

1 accepted

1 vote
Answer accepted
Dario B
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 26, 2020

Hi @Ryan Gilliam ,

Welcome to the Atlassian Community!

The documentation you are pointing to is for Jira Server (on premise) only.

In Cloud you do not maintain our products on your own servers since we host, set up, secure and maintain your products in the cloud for you. 

Therefore, you do not have access to the logs folder and therefore you cannot monitor Jira Cloud logs with Splunk.

 

For more details, please review below documentation page:

 

Specifically:

For detailed information on the infrastructure and functionality differences between our self-hosted and cloud products, check out:

 

I hope this explains.

 

Cheers,
Dario

2 votes
Martin Zeller October 20, 2020

Hi There,

We have the logs from Confluence and Jira through the Splunk Universal Forwarder available in Splunk.

BUT why are the atlassian-jira.logs so much different from the atlassian-confluence.logs in regards of the format?

The real power of Splunk reveals when one can use field extractions.

We have a good succes with Confluence but Jira is nearly impossible as the format of the log changes regarding the method which writes the logs.

Why is there a difference in format between Jira and Confluence atlassian-*.log?

Is there anyone who managed to write a propriate regex for field extractions ?

Thanks in advance,
Martin

Martin Zeller October 20, 2020

I will move that question to a separate thread as this is for cloud only.

Like Dario B likes this
1 vote
russ.robinson February 16, 2021

Im interested in this topic also. We use rapid 7 IDR and Im having some issues getting any logs. Is there a deployment guide for Rapid 7?

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
TAGS
AUG Leaders

Atlassian Community Events