Jira issue model
The integration creates one Jira issue or incident for each synchronized BloodHound Enterprise finding.If you connect a Jira Service Management project, the integration uses the configured request type and incident workflow instead of a standard Jira Software issue type.
Jira issue format
When the integration creates a Jira issue, it follows a specific format to ensure that all relevant information is included:- Summary
- Description
- Labels
- Dates
- Priority
The issue summary includes the zone, domain, affected principal, and finding ID.Example: [Tier-Zero] CORP.LOCAL - Administrator (12345)
Synchronization behavior
The integration keeps Jira aligned with BloodHound Enterprise automatically:- It runs synchronization every five minutes
- It creates issues for new findings and updates existing issues when finding details change
- It avoids duplicates by tracking synchronization metadata on the Jira issues
- It runs a cleanup scheduler hourly and closes orphaned issues when Auto-closure is enabled and the cleanup interval is met
No action is required for automatic synchronization. The integration will automatically create and update Jira issues based on the configured settings.If you need to manually trigger a synchronization, you can do so from the integration’s configuration settings in Jira.
Review synchronized findings
Reviewing the synchronized findings in Jira allows you to triage and manage security issues identified by BloodHound Enterprise. Use the synchronized issues the same way you manage other operational work in Jira:- Filter by labels, priority, or due date to focus on the findings you want to triage first.
- Assign findings to the team that owns remediation
- Update workflow state as triage and remediation progress
- Add comments or work notes that document investigation and closure decisions
- Use the Graph View link to move from Jira back to the BloodHound Enterprise finding when you need more context