本文にスキップ

AWS DynamoDB Integration

Overview

AWS DynamoDB is a fully managed NoSQL database with CloudTrail integration. KYRA MDR collects DynamoDB events via CloudTrail for access monitoring and security auditing.

Prerequisites

  • A KYRA MDR Collector installed and running
  • AWS account with DynamoDB tables
  • CloudTrail trail configured for DynamoDB events
  • IAM role with CloudTrail and S3 read permissions

Configuration

Configure DynamoDB audit logging via CloudTrail:

  1. Enable DynamoDB data events in CloudTrail:
Terminal window
aws cloudtrail put-event-selectors \
--trail-name kyra-trail \
--event-selectors '[{
"ReadWriteType": "All",
"DataResources": [{
"Type": "AWS::DynamoDB::Table",
"Values": ["arn:aws:dynamodb"]
}]
}]'
  1. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: aws-cloudtrail
region: ap-northeast-2
s3_bucket: <cloudtrail-bucket>
prefix: AWSLogs/
access_key_id: <access-key>
secret_access_key: <secret-key>
poll_interval: 300s

Collected Log Types

Log TypeDescriptionSecurity Use
Management EventsTable creation, deletion, updatesSchema management
Data EventsGetItem, PutItem, Query, ScanData access monitoring
StreamsDynamoDB Streams eventsChange data capture
TTL DeletionsTime-to-live item deletionsData lifecycle tracking
BackupBackup creation and restorationData protection monitoring
Global TablesReplication eventsMulti-region monitoring

Troubleshooting

No data events: DynamoDB data events must be explicitly enabled in CloudTrail event selectors.

High volume: Filter by specific table ARNs to control costs.

CloudTrail costs: Enabling data events increases CloudTrail costs.

Contact kyra@seekerslab.com for support.