Getting Data In

Integrating and Ingesting Atlassian Audit Logs into Splunk?

anandhalagaras1
Contributor

Based on the article provided below we have updated our Atlassian settings to pull the Bitbucket logs into our Audit Logs hence we want to how can get them ingested into Splunk.

So do we any specific add-on to get this audit logs pulled and ingested into Splunk? Or how do we get them integrated and get them ingested into Splunk.

Article:

https://bitbucket.org/blog/bitbucket-audit-logs-are-now-available-in-atlassian-access

https://support.atlassian.com/security-and-access-policies/docs/track-organization-activities-from-t...

So can anyone help me on this requirement.

Labels (1)
0 Karma

Brett
SplunkTrust
SplunkTrust

I just built an app to do this: https://splunkbase.splunk.com/app/7371

BrianH
New Member

Brett - do you have any further guidance on making this app (7371) work?  We are trying to ingest Atlassian logs from a trusted partner to our Splunk.  They pointed us to APP 7371, we installed.  But don't see any options for configuration?  Not like we're used to with other apps, anyway.  No "input" tab, no "configuration" tab, no "proxy" tab.   We get one page with 'name', 'update checking', 'visible' and 'upload asset' .  nothing else.  no place to enter the API key they sent us, nowhere to enter file path.  Nothing.  At this point we have the app installed but no idea how to get the logs to come over.

0 Karma

anandhalagaras1
Contributor

Can anyone help on this requirement? Can we able to pull the logs using HTTP Event Collector method?

Kindly check and update.

0 Karma

anandhalagaras1
Contributor

Can anyone help on the requirement. On how to pull the Audit logs into Splunk.

Link from Atlassian for reference:

https://developer.atlassian.com/cloud/admin/organization/rest/api-group-events/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...