跳至正文

GitLab Audit Events Integration

Overview

GitLab provides DevOps lifecycle management with audit event logging for security and compliance. KYRA MDR collects GitLab audit events via the Audit Events API. Supports GitLab Premium and Ultimate.

Prerequisites

  • A KYRA MDR Collector installed and running
  • GitLab Premium or Ultimate subscription
  • Personal access token with api scope
  • Instance Admin or Group Owner role

Configuration

Configure GitLab audit event collection:

  1. Generate a personal access token at User Settings > Access Tokens
  2. Select the api scope
  3. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: gitlab
url: https://gitlab.com
token: <personal-access-token>
group_id: <group-id>
poll_interval: 120s
  1. Restart the collector service

For audit event streaming (GitLab Ultimate), configure an HTTP destination under Group > Settings > Audit Events > Streaming.

Collected Log Types

Log TypeDescriptionSecurity Use
AuthenticationLogin and token eventsAccess monitoring
RepositoryProject and repo changesCode security monitoring
GroupGroup membership and settingsAccess management
PermissionRole and permission changesPrivilege escalation detection
CI/CDPipeline and runner eventsBuild security monitoring
ComplianceCompliance framework eventsRegulatory compliance

Troubleshooting

No audit events: GitLab Audit Events API requires Premium or Ultimate subscription.

Missing instance events: Instance-level audit events require Instance Admin token.

Streaming latency: API polling may have a delay of 1-2 minutes.

Contact kyra@seekerslab.com for support.