Getting Data In

Pulling Confluence Audit logs into Splunk

adnankhan5133
Communicator

We are currently running the "Server" version of Confluence in our environment. This version doesn't actually store audit logs locally to a directory. Instead, the logs are only visible through the UI and can be exported from there with a max of 100k results. In that case, how would one be able to get these audit logs sent to Splunk in a programmatic manner rather than manually downloading the logs and uploading to Splunk on a periodic basis.

Here is a page which talks about Confluence audit logging and how it is lacking in capability for the "Server" version. The "Data Center" version, which we don't have, logs locally and can easily be sent over to Splunk via UF.

https://confluence.atlassian.com/doc/auditing-in-confluence-829076528.html

0 Karma

anilchaithu
Builder

@adnankhan5133 

Have you tried using confluence REST API? You can try splunk modular input to call confluence rest api to import the audit data.

Below are some  documentation references for both confluence & splunk that will give some direction

https://confluence.atlassian.com/cloud/audit-logging-970612562.html

https://developer.atlassian.com/cloud/admin/organization/rest/api-group-orgs/#api-orgs-orgid-events-...

https://docs.splunk.com/Documentation/SplunkCloud/8.0.2004/AdvancedDev/ModInputsIntro

Hope this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust
That page says integration with 3rd-party monitoring tools is not supported by the server version of the tool. IMO, the only solution to your problem is to buy the DC version.
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...