Skip to content

GitHub Audit Log Integration

Overview

GitHub provides code hosting and collaboration with organization-level audit logging. KYRA MDR collects GitHub audit logs via the Audit Log API for monitoring repository security and compliance. Supports GitHub Enterprise Cloud and Enterprise Server.

Prerequisites

  • A KYRA MDR Collector installed and running
  • GitHub Enterprise Cloud or Enterprise Server organization
  • Personal access token with admin:org and audit_log scopes
  • Organization Owner role

Configuration

Configure GitHub audit log collection:

  1. Generate a personal access token at Settings > Developer settings > Personal access tokens
  2. Select scopes: admin:org, audit_log
  3. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: github
organization: <org-name>
token: <personal-access-token>
api_url: https://api.github.com
poll_interval: 120s
  1. Restart the collector service

Collected Log Types

Log TypeDescriptionSecurity Use
RepositoryRepo creation, deletion, visibility changesCode security, access control
TeamTeam membership changesAccess management
OrganizationOrg settings and policy changesSecurity policy monitoring
OAuth ApplicationApp authorization eventsThird-party app oversight
GitPush, clone, and fetch eventsCode access monitoring
Secret ScanningSecret detection alertsCredential leak prevention

Troubleshooting

API authentication failed: Verify the personal access token has the required scopes and has not expired.

No audit log entries: Audit logs are only available for GitHub Enterprise organizations.

Rate limiting: GitHub API enforces rate limits (5000 requests/hour). The collector handles rate limiting with automatic backoff.

Contact kyra@seekerslab.com for support.