Getting Data In

Pulling Confluence Audit logs into Splunk

adnankhan5133
Communicator

We are currently running the "Server" version of Confluence in our environment. This version doesn't actually store audit logs locally to a directory. Instead, the logs are only visible through the UI and can be exported from there with a max of 100k results. In that case, how would one be able to get these audit logs sent to Splunk in a programmatic manner rather than manually downloading the logs and uploading to Splunk on a periodic basis.

Here is a page which talks about Confluence audit logging and how it is lacking in capability for the "Server" version. The "Data Center" version, which we don't have, logs locally and can easily be sent over to Splunk via UF.

https://confluence.atlassian.com/doc/auditing-in-confluence-829076528.html

0 Karma

anilchaithu
Builder

@adnankhan5133 

Have you tried using confluence REST API? You can try splunk modular input to call confluence rest api to import the audit data.

Below are some  documentation references for both confluence & splunk that will give some direction

https://confluence.atlassian.com/cloud/audit-logging-970612562.html

https://developer.atlassian.com/cloud/admin/organization/rest/api-group-orgs/#api-orgs-orgid-events-...

https://docs.splunk.com/Documentation/SplunkCloud/8.0.2004/AdvancedDev/ModInputsIntro

Hope this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust
That page says integration with 3rd-party monitoring tools is not supported by the server version of the tool. IMO, the only solution to your problem is to buy the DC version.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...