Splunk Cloud Platform

Confluence Audit Logs Integration with splunk- Requiring Admin Scope

Sankar
Explorer

Could you please advise

  1. Is there any Splunk Cloud security policy or best practice guidance on onboarding external data sources when the integration requires admin-level permissions at source?
  2. Does Splunk recommend or require any formal risk review or CCSA-like process for such cases?
  3. Do you have any documentation or recommendations to share with us to justify this elevated access for log collection?
  4. Any alternatives or Splunk add-ons/plugins that could achieve the same without needing admin-level permissions?
Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Sankar 

Hopefully I understand what you're asking here, you're looking to onboard Confluence Audit Logs into your Splunk Cloud environment?

Is your Confluence on-premise or their cloud SaaS offering?

If you are hosting Confluence on-premise then you can use a Splunk Universal Forwarder to send logs from the server using the details on the Confluence docs page to help: https://confluence.atlassian.com/doc/audit-log-integrations-in-confluence-1005333794.html

If you are using their cloud service (e.g. yourCompany.atlassian.net) then you will need to use an administrator account in order to pull the logs, this is a restriction from Atlassian and not something that Splunk is able to workaround (see https://support.atlassian.com/confluence-cloud/docs/view-the-audit-log/)

Have you seen the Confluence Cloud Audit Log Ingestor app for pulling the audit logs using the API? I believe this will need the admin level scoped auth token.

In terms of documentation justifying the elevated access and risk assessment, unfortunately this is an Atlassian control but it might be worth reaching out to any Atlassian support you have for help with this.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...