Redis Logs
Overview
Redis is an in-memory data store used for caching, session management, and message brokering. KYRA MDR collects Redis server logs, slow query logs, ACL violations, and keyspace notifications to detect unauthorized access, data exfiltration, and configuration changes.
Prerequisites
- KYRA MDR account (MDR tier or above)
- KYRA Collector installed and reachable from the Redis host
- Redis 6.0+ (for ACL support) or Redis 5.x (basic logging)
- Administrative access to the Redis server configuration
Configuration
Step 1: Configure Redis Server Logging
Edit /etc/redis/redis.conf:
# Set log level (debug, verbose, notice, warning)loglevel notice
# Log to a filelogfile /var/log/redis/redis-server.log
# Enable syslog outputsyslog-enabled yessyslog-ident redissyslog-facility local0sudo systemctl restart redisStep 2: Configure Slow Query Logging
# Log queries slower than 10ms (10000 microseconds)slowlog-log-slower-than 10000
# Keep last 128 slow queriesslowlog-max-len 128# View slow queriesredis-cli SLOWLOG GET 10
# Get count and resetredis-cli SLOWLOG LENredis-cli SLOWLOG RESETStep 3: Configure ACL Logging (Redis 6.0+)
# Maximum ACL log entriesacllog-max-len 128# View ACL violationsredis-cli ACL LOG 10
# Reset ACL logredis-cli ACL LOG RESETStep 4: Enable Keyspace Notifications
# Enable notifications for all key eventsredis-cli CONFIG SET notify-keyspace-events KEA
# In redis.conf for persistence:# notify-keyspace-events KEA## K = Keyspace events, E = Keyevent events# g = Generic commands (DEL, EXPIRE, RENAME)# $ = String commands, l = List, s = Set, h = Hash, z = Sorted set# x = Expired events, e = Evicted events# A = Alias for "g$lshzxe" (all events)Step 5: Forward Logs via rsyslog
local0.* @@<COLLECTOR_IP>:514sudo systemctl restart rsyslogStep 6: Periodic Metric Collection
#!/bin/bash# /opt/kyra/redis-audit.sh - cron every 5 minutesREDIS_CLI="redis-cli -a <PASSWORD>"COLLECTOR="<COLLECTOR_IP>"
# Collect slow queries$REDIS_CLI SLOWLOG GET 50 | logger -t redis-slowlog -n $COLLECTOR -P 514 --tcp
# Collect ACL violations$REDIS_CLI ACL LOG 50 | logger -t redis-acl -n $COLLECTOR -P 514 --tcp
# Collect client list$REDIS_CLI CLIENT LIST | logger -t redis-clients -n $COLLECTOR -P 514 --tcp
# Collect INFO stats$REDIS_CLI INFO stats | logger -t redis-stats -n $COLLECTOR -P 514 --tcp
# Reset after collection$REDIS_CLI SLOWLOG RESET$REDIS_CLI ACL LOG RESETecho "*/5 * * * * /opt/kyra/redis-audit.sh" | sudo crontab -Verify on KYRA Collector
kyra-collector statuskyra-collector logs --source redis --tail 5Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Server Logs | Startup, shutdown, config changes, replication events | Availability monitoring |
| Slow Queries | Commands exceeding time threshold | Performance abuse detection |
| ACL Log | Unauthorized command attempts | Access violation detection |
| Keyspace Notifications | Key create, modify, delete, expire events | Data change monitoring |
| Client Connections | Connected clients with IP, name, age, idle time | Unauthorized connection detection |
| INFO Stats | Command counts, memory, connections, keyspace | Anomaly baseline |
Security Commands
| Command | Description |
|---|---|
ACL LOG | View authentication and authorization failures |
SLOWLOG GET | Retrieve slow query entries |
CLIENT LIST | List all connected clients (IP, name, age) |
CONFIG GET * | View configuration (detect misconfigurations) |
INFO stats | Command stats, rejected connections |
INFO clients | Connected client count, blocked clients |
Security-Critical Events
| Event | Indicator | Description |
|---|---|---|
rejected_connections increasing | Brute force | Password guessing attempts |
ACL violation for CONFIG | Privilege escalation | Attempt to modify server config |
ACL violation for DEBUG, MODULE | Code execution | Attempt to load malicious modules |
ACL violation for SLAVEOF, REPLICAOF | Data exfiltration | Attempt to replicate to attacker server |
FLUSHALL / FLUSHDB | Data destruction | Database wipe attempt |
KEYS * pattern | Reconnaissance | Enumeration of all keys |
Troubleshooting
- No syslog output: Verify
syslog-enabled yesin redis.conf and restart Redis. Checkredis-cli CONFIG GET syslog-enabled. - ACL LOG empty: Requires Redis 6.0+. Older versions only log auth failures in server log.
- Keyspace notifications not firing: Check
redis-cli CONFIG GET notify-keyspace-events. Empty string means disabled. - High volume from keyspace: Using
KEAon high-throughput Redis generates massive volume. Filter toKgxfor generic and expired events only. - Protected mode: Redis 3.2+ has protected mode. Ensure Collector connects from allowed IP or uses password auth.
Contact kyra@seekerslab.com for integration support.