GitLab Audit Events Integration
Overview
GitLab provides DevOps lifecycle management with audit event logging for security and compliance. KYRA MDR collects GitLab audit events via the Audit Events API. Supports GitLab Premium and Ultimate.
Prerequisites
- A KYRA MDR Collector installed and running
- GitLab Premium or Ultimate subscription
- Personal access token with
apiscope - Instance Admin or Group Owner role
Configuration
Configure GitLab audit event collection:
- Generate a personal access token at User Settings > Access Tokens
- Select the
apiscope - Configure the KYRA MDR collector:
sources: - type: gitlab url: https://gitlab.com token: <personal-access-token> group_id: <group-id> poll_interval: 120s- Restart the collector service
For audit event streaming (GitLab Ultimate), configure an HTTP destination under Group > Settings > Audit Events > Streaming.
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Authentication | Login and token events | Access monitoring |
| Repository | Project and repo changes | Code security monitoring |
| Group | Group membership and settings | Access management |
| Permission | Role and permission changes | Privilege escalation detection |
| CI/CD | Pipeline and runner events | Build security monitoring |
| Compliance | Compliance framework events | Regulatory compliance |
Troubleshooting
No audit events: GitLab Audit Events API requires Premium or Ultimate subscription.
Missing instance events: Instance-level audit events require Instance Admin token.
Streaming latency: API polling may have a delay of 1-2 minutes.
Contact kyra@seekerslab.com for support.