-
Type:
Suggestion
-
Resolution: Unresolved
-
None
-
Component/s: Apps - Atlassian Supported - App Insights Plugin
-
None
With the introduction of the Monitor security threats feature starting in version 10.X
Monitor security threats
By design, system administrators receive these security alerts.
Some Jira administrators would like the ability to control what information is displayed in notifications, for example, to mask or hide the user's IP address who triggered the alert.
Currently, by design, only administrators receive these alerts, so displaying the source IP does not pose an immediate risk. However, some administrators are not comfortable with this information being sent via email.
At this time, the feature can be completely disabled by following the steps mentioned in the article: Disabling all alerts. However, in the near future, it will not be possible to disable the plugin that generates these alerts (Atlassian Security Monitoring and Alerts).
For these reasons, it would be valuable to have the ability to control what information is sent in the alerts, especially information that could be considered sensitive, such as the IP address.
Steps to Reproduce.
This functionality is included by default in Jira versions 10.x and later, so it doesn’t require any setup—just the following prerequisites.
To get security alerts, you’ll need:
- Access to a working SMTP mail server.
- System administrator permissions, or be part of a custom group called security-monitoring-alerts.
To see security alerts in the product tracking hub, you’ll need:
- System administrator permissions, or membership in the security-monitoring-alerts custom group.
Expected Results.
- Having the ability to customize the template used for notification emails, This would allow the administrators to control what information is included.
Actual Results.
- Currently, there’s no way to customize the template. While it’s possible to disable some or all notifications, it would be more convenient for administrators to keep the functionality and have control over the information included in the notifications.
Workaround.
- N/A