Apache Cassandra Integration
Overview
Apache Cassandra is a distributed NoSQL database designed for high availability. KYRA MDR collects Cassandra audit logs for monitoring database access and schema changes. Supports Cassandra 4.0+ (native audit logging).
Prerequisites
- A KYRA MDR Collector installed and running
- Apache Cassandra 4.0 or later
- Administrative access to the Cassandra cluster
- Network connectivity from Cassandra nodes to the collector
Configuration
Configure Cassandra audit logging (4.0+):
- Edit
cassandra.yaml:
audit_logging_options: enabled: true logger: - class_name: SyslogAuditLogger included_categories: AUTH, DML, DDL, DCL, OTHER audit_logs_dir: /var/log/cassandra/audit- Configure syslog forwarding:
if $programname == 'cassandra' then @@<collector-ip>:514- Restart Cassandra:
sudo systemctl restart cassandraCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Authentication | Login and authentication events | Access monitoring |
| DML | Data manipulation (SELECT, INSERT) | Data access auditing |
| DDL | Schema changes (CREATE, ALTER, DROP) | Schema integrity monitoring |
| DCL | Permission grants and revocations | Access control auditing |
| Query | CQL query execution events | Query analysis |
| Repair | Node repair and compaction events | Cluster health monitoring |
Troubleshooting
No audit logs: Native audit logging requires Cassandra 4.0+. Use Ecaudit plugin for 3.x.
Missing DML events: DML auditing can be high volume. Filter by keyspace.
SyslogAuditLogger: Verify the class name is correctly specified in cassandra.yaml.
Contact kyra@seekerslab.com for support.