To help administrators keep track of various events, Security for Jira Cloud has an audit log. Due to Atlassian policies, we cannot write to the Atlassian audit log.
Audit log entries are retained for 90 days.
Accessing the audit log
From the Soteri settings page, click on Audit Log in the top right of the page.
Viewing events
The audit log page shows events ordered from most to least recent.
The “Show more” column on the right can be clicked to show the details of individual events, including the Atlassian user ID of the author. (Events with no associated user, such as scans starting and completing, use “System” as the author)
The search boxes at the top of the page can be used to filter events by a substring of the Atlassian user ID, event type, or event details (which are stored as JSON). Click the search icon or press enter in one of the search boxes to filter. For example, the above event matches each of these filters:
Exporting events
The export button on the top right exports events matching the current filters as a CSV file.
Who can view the audit log?
The audit log is available to Jira administrators, plus any users and groups granted access under App Access on the Soteri settings page.
The audit log covers the entire instance. In order to ensure traceability, it is not filtered to particular spaces like the Dashboard. As such, an App Administrator will be able to see every event recorded for the instance, including events for spaces they cannot browse in Jira.
Audit events record identifiers and metadata only. This includes things like:
-
space and work item IDs and keys
-
finding counts
-
rule names
-
timestamps
-
author names
-
links to Soteri pages
They never include scanned content or the matched text of a finding. Viewing the text content of findings themselves still requires Read permission on the space.
Grant App Access only to people you trust with instance-wide visibility into scanning activity.
List of audited events
|
Event type |
Detail fields |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|