GitHub Audit Log Integration
Overview
GitHub provides code hosting and collaboration with organization-level audit logging. KYRA MDR collects GitHub audit logs via the Audit Log API for monitoring repository security and compliance. Supports GitHub Enterprise Cloud and Enterprise Server.
Prerequisites
- A KYRA MDR Collector installed and running
- GitHub Enterprise Cloud or Enterprise Server organization
- Personal access token with
admin:organdaudit_logscopes - Organization Owner role
Configuration
Configure GitHub audit log collection:
- Generate a personal access token at Settings > Developer settings > Personal access tokens
- Select scopes:
admin:org,audit_log - Configure the KYRA MDR collector:
sources: - type: github organization: <org-name> token: <personal-access-token> api_url: https://api.github.com poll_interval: 120s- Restart the collector service
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Repository | Repo creation, deletion, visibility changes | Code security, access control |
| Team | Team membership changes | Access management |
| Organization | Org settings and policy changes | Security policy monitoring |
| OAuth Application | App authorization events | Third-party app oversight |
| Git | Push, clone, and fetch events | Code access monitoring |
| Secret Scanning | Secret detection alerts | Credential leak prevention |
Troubleshooting
API authentication failed: Verify the personal access token has the required scopes and has not expired.
No audit log entries: Audit logs are only available for GitHub Enterprise organizations.
Rate limiting: GitHub API enforces rate limits (5000 requests/hour). The collector handles rate limiting with automatic backoff.
Contact kyra@seekerslab.com for support.