Atlassian Jira security logs
About 6,600 records/day from one Jira node and 512 accounts, with native security messages and ECS enrichment.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/web-atlassian-jira-security/generator.yml \
--id jira-security \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| session-created | session created | 42.55% | Session lifecycle |
| session-destroyed | session destroyed | 28.35% | Session lifecycle |
| authentication-passed | authentication passed | 14.19% | Authentication |
| logout | logout | 14.15% | Authentication |
| authentication-failed | authentication failed | 0.64% | Authentication |
| captcha-required | captcha required | 0.11% | Authentication |
Realism Features
- Office-hour activity, account-wide failure counts and overlapping authenticated sessions
- Login and logout preserve request IDs and session replacement records
- The retry sequence alone does not prove compromise
Sample Output
{
"@timestamp": "2026-09-01T00:01:23.300000+00:00",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "authentication-passed",
"category": [
"authentication"
],
"kind": "event",
"original": "2026-09-01 00:01:23,300+0000 http-nio-8080-exec-8 url: /jira/login.jsp user0029 0x103x1 4mk6er2 10.20.10.29 /login.jsp The user \u0027user0029\u0027 has PASSED authentication.",
"outcome": "success",
"type": [
"start"
]
},
"host": {
"name": "jira-dc-01.example.test"
},
"jira": {
"security": {
"context_url": "/jira/login.jsp",
"message": "The user \u0027user0029\u0027 has PASSED authentication.",
"request_id": "0x103x1",
"request_url": "/login.jsp",
"session_id": "4mk6er2",
"target_user": "user0029"
}
},
"log": {
"file": {
"path": "atlassian-jira-security.log"
}
},
"process": {
"thread": {
"name": "http-nio-8080-exec-8"
}
},
"related": {
"ip": [
"10.20.10.29"
],
"user": [
"user0029"
]
},
"source": {
"ip": "10.20.10.29"
},
"user": {
"name": "user0029"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include the recurring retry sequence |
| anomaly_interval_hours | 24 | Recurrence interval, from 1 to 8760 hours |
| host_name | jira-dc-01.example.test | Jira node name in the ECS wrapper |
| context_path | /jira | Application context in the thread's request URL |
Related Generators
1C:Enterprise Event Log
1C:Enterprise 8.3.27 event-log collector projection for a client/server, single-data-area infobase: ECS-style JSON with snake_case source fields under one_c.event_log, not a native XML or .lgf export and without event.original. Six staff accounts, four reusable temporary account names and five configured objects with explicit permissions. Recurring episodes, weekly by default, join an administrator's failed logins, a temporary FullAccess account, its payroll reads, its deletion and an event-log reduction.
1C:Enterprise Technological Log
1C:Enterprise 8.3.27 technological-log JSON records (SCALL, CALL, TLOCK, EXCP) of one rphost process serving fourteen client and service sessions of one infobase, in an ECS envelope. About 44,000 records a day: interactive users follow a working day in UTC, background jobs keep the same pace day and night. Managed locks on document keys are granted at once, queued, or time out after 20 seconds. Recurring episodes are lock convoys: one very long posting blocks a busy document key until six distinct sessions have timed out on it within 50 minutes.
Nextcloud Admin Audit
Nextcloud 35.0.0 admin_audit HTTP records from the dedicated audit.log file backend, with each native JSON line in event.original and parsed under nextcloud.audit, for testing detections on logins, file access and public links. 180 users work in sessions over 1,154 files, about 10,800 records a day. Recurring episodes show a guessed password followed by publishing a file for outside access through a public link.