Description
Atlassian Beacon is a cloud product that is built for Intelligent threat detection across the Atlassian platforms (Jira, Confluence, and Atlassian Admin). This can help users detect, investigate and respond to risky user activity for the Atlassian suite of products. The solution is a custom data connector from DEFEND Ltd. that is used to visualize the alerts ingested from Atlassian Beacon to Microsoft Sentinel via a Logic App.
- Declared status
- 1
- Declared author / publisher
- DEFEND Ltd.
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
>1. Navigate to the newly installed Logic App 'Atlassian Beacon Integration'
>2. Navigate to 'Logic app designer'
>3. Expand the 'When a HTTP request is received'
>4. Copy the 'HTTP POST URL'
1. Microsoft Sentinel
>1. Login to Atlassian Beacon using an admin account
>2. Navigate to 'SIEM forwarding' under SETTINGS
> 3. Paste the copied URL from Logic App in the text box
> 4. Click the 'Save' button
2. Atlassian Beacon
>1. Login to Atlassian Beacon using an admin account
>2. Navigate to 'SIEM forwarding' under SETTINGS
> 3. Click the 'Test' button right next to the newly configured webhook
> 4. Navigate to Microsoft Sentinel
> 5. Navigate to the newly installed Logic App
> 6. Check for the Logic App Run under 'Runs history'
> 7. Check for logs under the table name 'atlassian_beacon_alerts_CL' in 'Logs'
> 8. If the analytic rule has been enabled, the above Test alert should have created an incident in Microsoft Sentinel
3. Testing and Validation
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
AtlassianBeaconAlerts
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC