Skip to content

Slack Audit Logs

Overview

Slack Enterprise Grid provides audit logging that captures user, channel, file, and application events across the organization. KYRA MDR collects these events via the Slack Audit Logs API to detect data exfiltration, unauthorized workspace access, and policy violations.

Prerequisites

  • KYRA MDR account (MDR tier or above)
  • KYRA Collector installed with outbound HTTPS access to api.slack.com
  • Slack Enterprise Grid plan (Audit Logs API is not available on Free, Pro, or Business+ plans)
  • A Slack app installed at the organization level (not workspace level) with appropriate OAuth scopes

Configuration

Step 1: Create a Slack App for Audit Log Access

  1. Go to api.slack.com/apps and click Create New App > From scratch
  2. Enter a name (e.g., “KYRA MDR Audit”) and select your Enterprise Grid organization
  3. Navigate to OAuth & Permissions and add the following User Token Scopes:
    • auditlogs:read — required for reading audit events
  4. Click Install to Organization (must be installed by an Org Owner or Org Admin)
  5. Record the User OAuth Token (starts with xoxp-)

Step 2: Configure KYRA Collector

/etc/kyra-collector/sources.d/slack-audit.yaml
source:
type: slack-audit
token: "xoxp-<USER_OAUTH_TOKEN>"
poll_interval: 300 # seconds
collect:
- user # login, logout, role changes
- channel # create, delete, archive, convert
- file # upload, download, share
- app # install, approve, restrict
- workspace # settings changes
- message # message_tombstoned (deleted), pinned
Terminal window
kyra-collector reload
kyra-collector status

Step 3: Verify API Access

Test the Audit Logs API:

Terminal window
# Fetch recent audit events
curl -s -H "Authorization: Bearer xoxp-<TOKEN>" \
"https://api.slack.com/audit/v1/logs?limit=5" \
| jq '.entries[] | {id, date_create, action, actor: .actor.user.email, entity: .entity.type}'
# Filter by action type
curl -s -H "Authorization: Bearer xoxp-<TOKEN>" \
"https://api.slack.com/audit/v1/logs?action=user_login&limit=10" \
| jq '.entries[] | {action, actor: .actor.user.email, date_create, context: .context.ip_address}'
# Filter by date range (Unix timestamps)
curl -s -H "Authorization: Bearer xoxp-<TOKEN>" \
"https://api.slack.com/audit/v1/logs?oldest=1700000000&latest=1700086400&limit=50" \
| jq '.entries | length'

Step 4: List Available Actions and Schemas

Terminal window
# Get the list of all audit log actions
curl -s -H "Authorization: Bearer xoxp-<TOKEN>" \
"https://api.slack.com/audit/v1/actions" \
| jq 'to_entries[] | {category: .key, actions: [.value[].action]}'
# Get the audit log schema
curl -s -H "Authorization: Bearer xoxp-<TOKEN>" \
"https://api.slack.com/audit/v1/schemas" \
| jq '.schemas[] | .type'

Step 5: Verify on KYRA Collector

Terminal window
kyra-collector logs --source slack-audit --tail 10

Collected Log Types

Log TypeDescriptionSecurity Use
User Eventsuser_login, user_logout, user_created, role_change_to_admin, user_deactivatedAccount security, access monitoring
Channel Eventschannel_created, channel_deleted, channel_converted_to_public, channel_archiveData governance
File Eventsfile_uploaded, file_downloaded, file_shared_externally, file_public_link_createdData loss prevention
App Eventsapp_installed, app_approved, app_restricted, app_scopes_expandedSupply chain security
Workspace Eventsemoji_added, workspace_settings_changed, retention_changedPolicy compliance
Message Eventsmessage_tombstoned, message_pinned, message_unpinnedContent monitoring

Key Audit Log Event Categories

CategoryActionsSecurity Relevance
Authenticationuser_login, user_login_failed, user_session_invalidatedBrute force detection, session hijacking
Access Controlrole_change_to_admin, role_change_to_owner, guest_createdPrivilege escalation
Data Movementfile_downloaded, file_shared_externally, public_link_createdData exfiltration
Integrationsapp_installed, app_scopes_expanded, incoming_webhook_createdMalicious app installation
Complianceretention_changed, ekm_key_changed, dlp_policy_updatedRegulatory compliance

Security-Critical Slack Events

EventIndicatorDescription
user_login_failed burstBrute forceMultiple failed login attempts for same user
role_change_to_ownerPrivilege escalationUser elevated to workspace/org owner
channel_converted_to_publicData exposurePrivate channel made public
file_shared_externallyData leakageFile shared outside the organization
app_installed with broad scopesSupply chain riskThird-party app with excessive permissions
user_session_invalidated not by userAccount compromiseAdmin force-logging out a user (indicator of incident response)
retention_changed to shorter periodEvidence destructionMessage retention period shortened

Troubleshooting

  • not_allowed_token_type error: The Audit Logs API requires a User OAuth Token (xoxp-), not a Bot Token (xoxb-). Reinstall the app with user token scopes.
  • missing_scope error: Verify the app has the auditlogs:read scope under User Token Scopes (not Bot Token Scopes).
  • paid_teams_only error: Audit Logs API is exclusive to Enterprise Grid. Business+ and lower plans cannot access this API.
  • Empty results: The app must be installed at the organization level, not a single workspace. Go to Organization Settings > Apps to verify.
  • Rate limiting (429): Slack allows approximately 25 requests per minute for the Audit Logs API. Increase poll_interval and use pagination cursors instead of overlapping time windows.
  • Missing IP addresses: IP addresses in context.ip_address may be null for API-initiated actions. Only interactive user actions include IP data.

Contact kyra@seekerslab.com for integration support.