-
Suggestion
-
Resolution: Unresolved
-
62
-
60
-
Log what have been done through an API (which allow the same actions as a User can do through the UI) in the Audit Log.
The originating and forwarding IP address, username, and project names could be logged.
- is duplicated by
-
JRACLOUD-36856 Logging for JIRA REST API
- Closed
- relates to
-
ID-8198 User re-activation by API not showing any record in the Audit Log
- Gathering Interest
Form Name |
---|
With recent data breaches in the news and API being potentially the issue to one of them a few customers now would like visibility of when an API call is made. We can of course track this through automation rule logs, or a scheduled task on a server that may be calling a script that calls the API but the concern is if there is an outside process that manages to fire the API and make calls to the dataset not controlled by known processes. This is really forefront now in the eyes of cyber teams for some customers.