Ansible Automation Integration
Overview
Ansible provides IT automation for configuration management and orchestration. KYRA MDR collects Ansible execution logs for monitoring automated changes and maintaining compliance. Supports Ansible Core 2.x and AWX/Tower.
Prerequisites
- A KYRA MDR Collector installed and running
- Ansible control node or AWX/Ansible Tower
- Callback plugin configuration access
- Network connectivity from the Ansible host to the collector
Configuration
Configure Ansible logging:
- Enable syslog callback plugin in
ansible.cfg:
[defaults]callback_whitelist = syslog_jsonlog_path = /var/log/ansible/ansible.log- Forward logs via rsyslog:
module(load="imfile")input(type="imfile" File="/var/log/ansible/ansible.log" Tag="ansible")if $syslogtag == 'ansible' then @@<collector-ip>:514For AWX/Tower, configure under Settings > System > Logging with syslog aggregator.
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Playbook | Playbook execution events | Automation monitoring |
| Task | Individual task results | Change tracking |
| Module | Module execution details | Configuration auditing |
| Authentication | Login and API access events (AWX) | Access monitoring |
| Inventory | Inventory changes and syncs | Asset management |
| Credential | Credential usage events (AWX) | Secret access monitoring |
Troubleshooting
No syslog output: Verify syslog_json is in callback_whitelist.
AWX/Tower: Configure syslog aggregator under Settings > System > Logging.
Sensitive data: Use no_log: true on tasks with sensitive data.
Contact kyra@seekerslab.com for support.