Prevent multiple calls from one internal user causing CPU overload

digit-s2_ec_europa_eu
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 5, 2024

Dear reader,

We are facing a problem with Jira Data Center.

We would like to prevent the software to be have multiple request coming from internal customer, that could send multiple calls to our server.

We know that there is a native max-requests settings that we can use, but the problem is that we also use Jira as a incident ticket tool.

That is to say that our Jira is called by monitoring and alerting tools which are the most important things to handle.

Having this in mind, it is then not possible for us to know in advance how many calls we get per minutes as it depends on the attacks detected by the our internal associated tools to Jira.

Then we need a solution to prevent any internal 'bruteforce' like a user making multiple calls by using a widget or the API directly,

Here an example of call to limit: 

 

rest/api/1.0/users/picker?showAvatar=true&query=sssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssssss&_=1717592574471

 

Do you have a solution to prevent for example normal users to exceed a certain amount of call whereas we could keep the requests coming from alerting tools (bot accounts) unlimited.

Thank you in advance for your answer,

Best regards

1 answer

0 votes
Laurie Sciutti
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 5, 2024

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
9.12.10
TAGS
AUG Leaders

Atlassian Community Events