MinIO Object Storage Integration
Overview
MinIO is a high-performance, S3-compatible object storage system. KYRA MDR collects MinIO audit and access logs for monitoring bucket operations and detecting unauthorized access.
Prerequisites
- A KYRA MDR Collector installed and running
- MinIO server with administrative access
- MinIO audit webhook or log output configured
- Network connectivity from MinIO to the collector
Configuration
Configure MinIO audit logging:
- Enable audit logging via environment variable:
export MINIO_AUDIT_WEBHOOK_ENABLE_KYRA=onexport MINIO_AUDIT_WEBHOOK_ENDPOINT_KYRA=http://<collector-ip>:8080/webhook/minio- Or configure via MinIO Client (mc):
mc admin config set myminio audit_webhook:kyra \ endpoint="http://<collector-ip>:8080/webhook/minio" \ enable="on"mc admin service restart myminio- Restart MinIO server
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| API Requests | S3 API call events | Access pattern monitoring |
| Authentication | Login and credential events | Access control |
| Bucket Operations | Bucket create, delete, policy changes | Data management |
| Object Operations | Object upload, download, delete | Data access monitoring |
| IAM | User and policy changes | Identity management |
| Replication | Bucket replication events | Data protection |
Troubleshooting
No webhook events: Verify the endpoint is reachable from MinIO.
Authentication: MinIO webhooks do not require authentication by default.
High volume: Filter by bucket or operation type if needed.
Contact kyra@seekerslab.com for support.