• 62
    • 60
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Log what have been done through an API (which allow the same actions as a User can do through the UI) in the Audit Log.

      The originating and forwarding IP address, username, and project names could be logged.

          Form Name

            [JRACLOUD-79552] Record all the activities done via Rest API in Audit Log

            With recent data breaches in the news and API being potentially the issue to one of them a few customers now would like visibility of when an API call is made.  We can of course track this through automation rule logs, or a scheduled task on a server that may be calling a script that calls the API but the concern is if there is an outside process that manages to fire the API and make calls to the dataset not controlled by known processes.  This is really forefront now in the eyes of cyber teams for some customers.

            Steven Lees-Smith added a comment - With recent data breaches in the news and API being potentially the issue to one of them a few customers now would like visibility of when an API call is made.  We can of course track this through automation rule logs, or a scheduled task on a server that may be calling a script that calls the API but the concern is if there is an outside process that manages to fire the API and make calls to the dataset not controlled by known processes.  This is really forefront now in the eyes of cyber teams for some customers.

              Unassigned Unassigned
              779c84f46df5 Chaitra Doddegowda
              Votes:
              33 Vote for this issue
              Watchers:
              38 Start watching this issue

                Created:
                Updated: