Elasticsearch Audit Integration
Overview
Elasticsearch provides distributed search and analytics with audit logging. KYRA MDR collects Elasticsearch audit logs for monitoring cluster access and authentication. Supports Elasticsearch 7.x and 8.x with Platinum or Enterprise license.
Prerequisites
- A KYRA MDR Collector installed and running
- Elasticsearch cluster with Platinum or Enterprise license
- Administrative access to the cluster
- Network connectivity from Elasticsearch nodes to the collector
Configuration
Configure Elasticsearch audit logging:
- Edit
elasticsearch.yml:
xpack.security.audit.enabled: truexpack.security.audit.logfile.events.include: - access_denied - access_granted - authentication_failed - connection_denied - security_config_change-
Restart Elasticsearch nodes
-
Forward via Filebeat:
filebeat.inputs: - type: log paths: - /var/log/elasticsearch/*_audit.jsonoutput.logstash: hosts: ["<collector-ip>:5044"]Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Authentication | Login success and failure | Access monitoring |
| Access Granted | Successful authorization events | Permission auditing |
| Access Denied | Authorization failure events | Unauthorized access detection |
| Index Operations | Index creation and deletion | Data management monitoring |
| Security Config | Security setting changes | Security policy auditing |
| Connection | Connection grant and deny events | Network access control |
Troubleshooting
Audit not available: Requires Platinum or Enterprise license.
High volume: Use events.include to log only security-relevant events.
Performance: Audit logging has minimal impact, but emit_request_body increases volume.
Contact kyra@seekerslab.com for support.