Skip to content

MongoDB Audit Integration

Overview

MongoDB is a document-oriented NoSQL database. KYRA MDR collects MongoDB audit logs for monitoring database access and authentication events. Supports MongoDB Enterprise 5.x and 6.x.

Prerequisites

  • A KYRA MDR Collector installed and running
  • MongoDB Enterprise (for native auditing) or Community Edition
  • Administrative access to the MongoDB instance
  • Network connectivity from the MongoDB host to the collector

Configuration

Configure MongoDB Enterprise audit logging:

# mongod.conf
auditLog:
destination: syslog
format: JSON
filter: '{atype: {$in: ["authenticate", "createUser", "dropUser", "authCheck"]}}'
setParameter:
auditAuthorizationSuccess: true

Restart MongoDB:

Terminal window
sudo systemctl restart mongod

Configure syslog forwarding:

/etc/rsyslog.d/mongodb.conf
if $programname == 'mongod' then @@<collector-ip>:514

Collected Log Types

Log TypeDescriptionSecurity Use
AuthenticationLogin success and failure eventsAccess monitoring
AuthorizationPermission check eventsPrivilege escalation detection
CRUD OperationsData access and modificationData security auditing
Schema ChangesCollection and index changesSchema integrity monitoring
User ManagementUser creation and role changesIdentity management
ReplicationReplica set eventsDatabase availability

Troubleshooting

Audit not available: Native audit logging requires MongoDB Enterprise.

High volume: Use the filter parameter to limit audited operations.

Syslog format: Set the audit log format to JSON for proper parsing.

Contact kyra@seekerslab.com for support.