跳至正文

Apache Cassandra Integration

Overview

Apache Cassandra is a distributed NoSQL database designed for high availability. KYRA MDR collects Cassandra audit logs for monitoring database access and schema changes. Supports Cassandra 4.0+ (native audit logging).

Prerequisites

  • A KYRA MDR Collector installed and running
  • Apache Cassandra 4.0 or later
  • Administrative access to the Cassandra cluster
  • Network connectivity from Cassandra nodes to the collector

Configuration

Configure Cassandra audit logging (4.0+):

  1. Edit cassandra.yaml:
audit_logging_options:
enabled: true
logger:
- class_name: SyslogAuditLogger
included_categories: AUTH, DML, DDL, DCL, OTHER
audit_logs_dir: /var/log/cassandra/audit
  1. Configure syslog forwarding:
/etc/rsyslog.d/cassandra.conf
if $programname == 'cassandra' then @@<collector-ip>:514
  1. Restart Cassandra:
Terminal window
sudo systemctl restart cassandra

Collected Log Types

Log TypeDescriptionSecurity Use
AuthenticationLogin and authentication eventsAccess monitoring
DMLData manipulation (SELECT, INSERT)Data access auditing
DDLSchema changes (CREATE, ALTER, DROP)Schema integrity monitoring
DCLPermission grants and revocationsAccess control auditing
QueryCQL query execution eventsQuery analysis
RepairNode repair and compaction eventsCluster health monitoring

Troubleshooting

No audit logs: Native audit logging requires Cassandra 4.0+. Use Ecaudit plugin for 3.x.

Missing DML events: DML auditing can be high volume. Filter by keyspace.

SyslogAuditLogger: Verify the class name is correctly specified in cassandra.yaml.

Contact kyra@seekerslab.com for support.