@@ -47,56 +47,113 @@ An example event for `audit` looks as following:
4747
4848``` json
4949{
50- "@timestamp" : " 2021-11-16T09:25:56.666Z " ,
50+ "@timestamp" : " 2021-11-22T23:44:13.873Z " ,
5151 "agent" : {
52- "ephemeral_id" : " 5e7e2606-c5b7-4cca-bcf6-5a9959484395 " ,
53- "id" : " 1f67a92c-38d3-40a8-9093-c4495a7411a3 " ,
54- "name" : " docker-fleet- agent" ,
52+ "ephemeral_id" : " 5de25f34-0a0a-44ab-b6cf-ddf6d3e10467 " ,
53+ "id" : " 8c63ae6c-a626-40b8-9a24-b90a9bfde848 " ,
54+ "name" : " elastic- agent-92724 " ,
5555 "type" : " filebeat" ,
56- "version" : " 8.10.2 "
56+ "version" : " 8.19.4 "
5757 },
5858 "confluence" : {
5959 "audit" : {
60- "external_collaborator" : false ,
60+ "extra_attributes" : [
61+ {
62+ "name" : " Query" ,
63+ "nameI18nKey" : " atlassian.audit.event.attribute.query"
64+ },
65+ {
66+ "name" : " Results returned" ,
67+ "nameI18nKey" : " atlassian.audit.event.attribute.results" ,
68+ "value" : " 57"
69+ },
70+ {
71+ "name" : " ID Range" ,
72+ "nameI18nKey" : " atlassian.audit.event.attribute.id" ,
73+ "value" : " 1 - 57"
74+ },
75+ {
76+ "name" : " Timestamp Range" ,
77+ "nameI18nKey" : " atlassian.audit.event.attribute.timestamp" ,
78+ "value" : " 2021-11-22T23:42:45.791Z - 2021-11-22T23:43:22.615Z"
79+ }
80+ ],
81+ "method" : " Browser" ,
6182 "type" : {
62- "action" : " User deactivated" ,
63- "category" : " Users and groups"
83+ "action" : " Audit Log search performed" ,
84+ "actionI18nKey" : " atlassian.audit.event.action.audit.search" ,
85+ "area" : " AUDIT_LOG" ,
86+ "category" : " Auditing" ,
87+ "categoryI18nKey" : " atlassian.audit.event.category.audit" ,
88+ "level" : " BASE"
6489 }
6590 }
6691 },
6792 "data_stream" : {
6893 "dataset" : " atlassian_confluence.audit" ,
69- "namespace" : " ep " ,
94+ "namespace" : " 95121 " ,
7095 "type" : " logs"
7196 },
7297 "ecs" : {
7398 "version" : " 8.11.0"
7499 },
75100 "elastic_agent" : {
76- "id" : " 1f67a92c-38d3-40a8-9093-c4495a7411a3 " ,
101+ "id" : " 8c63ae6c-a626-40b8-9a24-b90a9bfde848 " ,
77102 "snapshot" : false ,
78- "version" : " 8.10.2 "
103+ "version" : " 8.19.4 "
79104 },
80105 "event" : {
81- "action" : " User deactivated " ,
106+ "action" : " atlassian.audit.event.action.audit.search " ,
82107 "agent_id_status" : " verified" ,
83- "created" : " 2023-11-06T13:17:04.339Z" ,
84108 "dataset" : " atlassian_confluence.audit" ,
85- "ingested" : " 2023-11-06T13:17:05Z " ,
109+ "ingested" : " 2025-12-17T10:43:52Z " ,
86110 "kind" : " event" ,
87- "original" : " {\" affectedObject\" :{\" name\" :\"\" ,\" objectType\" :\"\" },\" associatedObjects\" :[],\" author\" :{\" accountType\" :\"\" ,\" displayName\" :\" System\" ,\" externalCollaborator\" :false,\" isExternalCollaborator\" :false,\" operations\" :null,\" publicName\" :\" Unknown user\" ,\" type\" :\" user\" },\" category\" :\" Users and groups\" ,\" changedValues\" :[],\" creationDate\" :1637054756666,\" description\" :\"\" ,\" remoteAddress\" :\" 81.2.69.143\" ,\" summary\" :\" User deactivated\" ,\" superAdmin\" :false,\" sysAdmin\" :false}" ,
111+ "original": "{\"affectedObjects\":[],\"auditType\":{\"action\":\"Audit Log search performed\",\"actionI18nKey\":\"atlassian.audit.event.action.audit.search\",\"area\":\"AUDIT_LOG\",\"category\":\"Auditing\",\"categoryI18nKey\":\"atlassian.audit.event.category.audit\",\"level\":\"BASE\"},\"author\":{\"id\":\"2c9580827d4a06e8017d4a07c3e10000\",\"name\":\"test.user\",\"type\":\"user\"},\"changedValues\":[],\"extraAttributes\":[{\"name\":\"Query\",\"nameI18nKey\":\"atlassian.audit.event.attribute.query\",\"value\":\"\"},{\"name\":\"Results returned\",\"nameI18nKey\":\"atlassian.audit.event.attribute.results\",\"value\":\"57\"},{\"name\":\"ID Range\",\"nameI18nKey\":\"atlassian.audit.event.attribute.id\",\"value\":\"1 - 57\"},{\"name\":\"Timestamp Range\",\"nameI18nKey\":\"atlassian.audit.event.attribute.timestamp\",\"value\":\"2021-11-22T23:42:45.791Z - 2021-11-22T23:43:22.615Z\"}],\"method\":\"Browser\",\"source\":\"81.2.69.143\",\"system\":\"http://confluence.internal:8090\",\"timestamp\":{\"epochSecond\":1637624653,\"nano\":873000000},\"version\":\"1.0\"}",
88112 "type" : [
89113 " info"
90114 ]
91115 },
116+ "host" : {
117+ "architecture" : " aarch64" ,
118+ "containerized" : false ,
119+ "hostname" : " elastic-agent-92724" ,
120+ "ip" : [
121+ " 172.19.0.2" ,
122+ " 172.18.0.4"
123+ ],
124+ "mac" : [
125+ " 52-B9-17-2C-21-10" ,
126+ " 72-59-40-DC-CA-4F"
127+ ],
128+ "name" : " elastic-agent-92724" ,
129+ "os" : {
130+ "kernel" : " 6.12.54-linuxkit" ,
131+ "name" : " Wolfi" ,
132+ "platform" : " wolfi" ,
133+ "type" : " linux" ,
134+ "version" : " 20230201"
135+ }
136+ },
92137 "input" : {
93- "type" : " httpjson"
138+ "type" : " log"
139+ },
140+ "log" : {
141+ "file" : {
142+ "path" : " /tmp/service_logs/test-audit.log"
143+ },
144+ "offset" : 0
94145 },
95146 "related" : {
147+ "hosts" : [
148+ " confluence.internal"
149+ ],
96150 "ip" : [
97151 " 81.2.69.143"
98152 ]
99153 },
154+ "service" : {
155+ "address" : " http://confluence.internal:8090"
156+ },
100157 "source" : {
101158 "address" : " 81.2.69.143" ,
102159 "geo" : {
@@ -115,11 +172,11 @@ An example event for `audit` looks as following:
115172 },
116173 "tags" : [
117174 " preserve_original_event" ,
118- " forwarded" ,
119175 " confluence-audit"
120176 ],
121177 "user" : {
122- "full_name" : " System"
178+ "full_name" : " test.user" ,
179+ "id" : " 2c9580827d4a06e8017d4a07c3e10000"
123180 }
124181}
125182```
0 commit comments