With Dynatrace Jira integration, issue tickets are generated automatically for all new vulnerabilities in your Dynatrace environments. Direct integration of Dynatrace and Atlassian Jira saves you a lot of manual work and completely automates the reporting of Dynatrace-detected vulnerabilities in your monitored environments into your organization's Jira project.
To integrate security notifications with Jira, follow the instructions below.
To set up notifications for vulnerabilities
Create an alerting profile, which allows you to set up alert-filtering rules that are based on the risk level of detected vulnerabilities.
Go to Settings and select Alerting > Vulnerability alerting profiles.
Select Add alerting profile.
Enter a Name for the profile on which you want to receive security notifications.
Under Alert for the following events, select at least one event type for which you want to receive notifications.
optional To restrict alerts to one management zone, under Alert only if the following management zone is affected (optional), select the desired management zone from the dropdown list. This way, you are alerted only when the selected management zone is affected by the selected event types. For example, for the New management zone affected event type, you are notified when an open vulnerability that hasn't previously affected your selected management zone starts affecting it.
Only one management zone can be selected per alerting profile.
Turn on each risk level for which you want to receive notifications. You can select more than one.
Select Save changes to save your configuration.
Link the alerting profile to a security notifications integration with Jira. You can define the Jira integration and configure the payload (in the form of a message template) that you want to receive with your security notifications.
Go to Settings and select Integration > Security notifications.
Select Add integration and enter the following information.
https://{instancename}.atlassian.net/rest/api/2
. Be sure to replace {instancename}
with your Atlassian instance.task
or story
, that should be used for issues detected by Dynatrace. Be sure to specify an issue type that's already been set up in Jira. To find all available issue types or create a new one, in your Jira account, go to Project settings > Issue types.Besides plain text, your summary and issue description can both include placeholders. Select the Info icon for a list of Available placeholders that you can use for this integration. Placeholders are automatically replaced with information related to the vulnerability when the notification is generated.
Example issue description:
Severity: {Severity}Davis Security Score: {DavisSecurityScore}{Description}{Tags}{Tags[Host Name]}{ManagementZones}
optional To verify your configuration, select Send test notification. If your configuration is correct:
Test notification sent successfully
.Save changes.
Example reporting to a Jira ticket
Dynatrace doesn't automatically close resolved issues. You need to close Jira issues manually.
To verify that your integration is set up correctly