AWS DynamoDB Integration
Overview
AWS DynamoDB is a fully managed NoSQL database with CloudTrail integration. KYRA MDR collects DynamoDB events via CloudTrail for access monitoring and security auditing.
Prerequisites
- A KYRA MDR Collector installed and running
- AWS account with DynamoDB tables
- CloudTrail trail configured for DynamoDB events
- IAM role with CloudTrail and S3 read permissions
Configuration
Configure DynamoDB audit logging via CloudTrail:
- Enable DynamoDB data events in CloudTrail:
aws cloudtrail put-event-selectors \ --trail-name kyra-trail \ --event-selectors '[{ "ReadWriteType": "All", "DataResources": [{ "Type": "AWS::DynamoDB::Table", "Values": ["arn:aws:dynamodb"] }] }]'- Configure the KYRA MDR collector:
sources: - type: aws-cloudtrail region: ap-northeast-2 s3_bucket: <cloudtrail-bucket> prefix: AWSLogs/ access_key_id: <access-key> secret_access_key: <secret-key> poll_interval: 300sCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Management Events | Table creation, deletion, updates | Schema management |
| Data Events | GetItem, PutItem, Query, Scan | Data access monitoring |
| Streams | DynamoDB Streams events | Change data capture |
| TTL Deletions | Time-to-live item deletions | Data lifecycle tracking |
| Backup | Backup creation and restoration | Data protection monitoring |
| Global Tables | Replication events | Multi-region monitoring |
Troubleshooting
No data events: DynamoDB data events must be explicitly enabled in CloudTrail event selectors.
High volume: Filter by specific table ARNs to control costs.
CloudTrail costs: Enabling data events increases CloudTrail costs.
Contact kyra@seekerslab.com for support.