LDAP/OpenLDAP Integration
Overview
LDAP provides directory services for authentication and authorization. KYRA MDR collects LDAP access logs for monitoring authentication events and access patterns. Supports OpenLDAP, 389 Directory Server, and FreeIPA.
Prerequisites
- A KYRA MDR Collector installed and running
- LDAP server with access logging enabled
- Administrative access to the LDAP server configuration
- Network connectivity from the LDAP server to the collector
Configuration
Configure OpenLDAP access logging:
- Enable the access log overlay:
dn: olcOverlay=accesslog,olcDatabase={1}mdb,cn=configobjectClass: olcOverlayConfigobjectClass: olcAccessLogConfigolcOverlay: accesslogolcAccessLogDB: cn=accesslogolcAccessLogOps: allolcAccessLogSuccess: TRUE- Configure syslog forwarding:
local4.* @@<collector-ip>:514- Set the log level:
olcLogLevel: stats - Restart OpenLDAP and rsyslog
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Bind | Authentication events | Login monitoring, brute force |
| Search | Directory query events | Enumeration detection |
| Modify | Attribute modification events | Unauthorized changes |
| Add | New entry creation events | Account creation monitoring |
| Delete | Entry deletion events | Account deletion tracking |
| Compare | Attribute comparison events | Password verification |
Troubleshooting
No access logs: Verify the access log overlay is enabled. OpenLDAP does not log access events by default.
Log level: The stats log level provides connection and operation statistics.
389 Directory Server: Enable access logging with nsslapd-accesslog-logging-enabled: on.
Contact kyra@seekerslab.com for support.