본문으로 건너뛰기

Slack Audit Logs Integration

Overview

Slack provides team messaging and collaboration with enterprise audit logging capabilities. KYRA MDR collects Slack audit logs via the Audit Logs API for security monitoring and compliance. Requires Slack Enterprise Grid plan.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Slack Enterprise Grid plan
  • Slack app with auditlogs:read scope installed at organization level
  • Organization Owner or Admin role

Configuration

Configure Slack Audit Logs app:

  1. Go to Slack API > Your Apps > Create New App
  2. Add OAuth scopes: auditlogs:read
  3. Install the app at the organization level
  4. Copy the OAuth Token
  5. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: slack
api_token: <oauth-token>
poll_interval: 120s
  1. Restart the collector service

Collected Log Types

Log TypeDescriptionSecurity Use
User LoginUser authentication eventsAccess monitoring, brute force detection
User LogoutUser session terminationSession management
File OperationsFile upload, download, share eventsData loss prevention
Channel OperationsChannel creation, archival, deletionCollaboration monitoring
App OperationsApp install, approval, removalShadow IT detection
Admin ActionsWorkspace and org admin changesSecurity policy auditing

Troubleshooting

Audit logs not available: Slack Audit Logs API is only available for Enterprise Grid plans.

Missing events: Ensure the Slack app is installed at the organization level, not individual workspace level.

Token issues: Slack OAuth tokens do not expire, but they can be revoked. Check the app installation status.

Contact kyra@seekerslab.com for support.