Could you please advise
Hi @Sankar
Hopefully I understand what you're asking here, you're looking to onboard Confluence Audit Logs into your Splunk Cloud environment?
Is your Confluence on-premise or their cloud SaaS offering?
If you are hosting Confluence on-premise then you can use a Splunk Universal Forwarder to send logs from the server using the details on the Confluence docs page to help: https://confluence.atlassian.com/doc/audit-log-integrations-in-confluence-1005333794.html
If you are using their cloud service (e.g. yourCompany.atlassian.net) then you will need to use an administrator account in order to pull the logs, this is a restriction from Atlassian and not something that Splunk is able to workaround (see https://support.atlassian.com/confluence-cloud/docs/view-the-audit-log/)
Have you seen the Confluence Cloud Audit Log Ingestor app for pulling the audit logs using the API? I believe this will need the admin level scoped auth token.
In terms of documentation justifying the elevated access and risk assessment, unfortunately this is an Atlassian control but it might be worth reaching out to any Atlassian support you have for help with this.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing