Getting Data In

Pulling Confluence Audit logs into Splunk

adnankhan5133
Communicator

We are currently running the "Server" version of Confluence in our environment. This version doesn't actually store audit logs locally to a directory. Instead, the logs are only visible through the UI and can be exported from there with a max of 100k results. In that case, how would one be able to get these audit logs sent to Splunk in a programmatic manner rather than manually downloading the logs and uploading to Splunk on a periodic basis.

Here is a page which talks about Confluence audit logging and how it is lacking in capability for the "Server" version. The "Data Center" version, which we don't have, logs locally and can easily be sent over to Splunk via UF.

https://confluence.atlassian.com/doc/auditing-in-confluence-829076528.html

0 Karma

anilchaithu
Builder

@adnankhan5133 

Have you tried using confluence REST API? You can try splunk modular input to call confluence rest api to import the audit data.

Below are some  documentation references for both confluence & splunk that will give some direction

https://confluence.atlassian.com/cloud/audit-logging-970612562.html

https://developer.atlassian.com/cloud/admin/organization/rest/api-group-orgs/#api-orgs-orgid-events-...

https://docs.splunk.com/Documentation/SplunkCloud/8.0.2004/AdvancedDev/ModInputsIntro

Hope this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust
That page says integration with 3rd-party monitoring tools is not supported by the server version of the tool. IMO, the only solution to your problem is to buy the DC version.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...