本文にスキップ

Elasticsearch Audit Integration

Overview

Elasticsearch provides distributed search and analytics with audit logging. KYRA MDR collects Elasticsearch audit logs for monitoring cluster access and authentication. Supports Elasticsearch 7.x and 8.x with Platinum or Enterprise license.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Elasticsearch cluster with Platinum or Enterprise license
  • Administrative access to the cluster
  • Network connectivity from Elasticsearch nodes to the collector

Configuration

Configure Elasticsearch audit logging:

  1. Edit elasticsearch.yml:
xpack.security.audit.enabled: true
xpack.security.audit.logfile.events.include:
- access_denied
- access_granted
- authentication_failed
- connection_denied
- security_config_change
  1. Restart Elasticsearch nodes

  2. Forward via Filebeat:

filebeat.yml
filebeat.inputs:
- type: log
paths:
- /var/log/elasticsearch/*_audit.json
output.logstash:
hosts: ["<collector-ip>:5044"]

Collected Log Types

Log TypeDescriptionSecurity Use
AuthenticationLogin success and failureAccess monitoring
Access GrantedSuccessful authorization eventsPermission auditing
Access DeniedAuthorization failure eventsUnauthorized access detection
Index OperationsIndex creation and deletionData management monitoring
Security ConfigSecurity setting changesSecurity policy auditing
ConnectionConnection grant and deny eventsNetwork access control

Troubleshooting

Audit not available: Requires Platinum or Enterprise license.

High volume: Use events.include to log only security-relevant events.

Performance: Audit logging has minimal impact, but emit_request_body increases volume.

Contact kyra@seekerslab.com for support.