跳至正文

LDAP/OpenLDAP Integration

Overview

LDAP provides directory services for authentication and authorization. KYRA MDR collects LDAP access logs for monitoring authentication events and access patterns. Supports OpenLDAP, 389 Directory Server, and FreeIPA.

Prerequisites

  • A KYRA MDR Collector installed and running
  • LDAP server with access logging enabled
  • Administrative access to the LDAP server configuration
  • Network connectivity from the LDAP server to the collector

Configuration

Configure OpenLDAP access logging:

  1. Enable the access log overlay:
dn: olcOverlay=accesslog,olcDatabase={1}mdb,cn=config
objectClass: olcOverlayConfig
objectClass: olcAccessLogConfig
olcOverlay: accesslog
olcAccessLogDB: cn=accesslog
olcAccessLogOps: all
olcAccessLogSuccess: TRUE
  1. Configure syslog forwarding:
/etc/rsyslog.d/ldap.conf
local4.* @@<collector-ip>:514
  1. Set the log level: olcLogLevel: stats
  2. Restart OpenLDAP and rsyslog

Collected Log Types

Log TypeDescriptionSecurity Use
BindAuthentication eventsLogin monitoring, brute force
SearchDirectory query eventsEnumeration detection
ModifyAttribute modification eventsUnauthorized changes
AddNew entry creation eventsAccount creation monitoring
DeleteEntry deletion eventsAccount deletion tracking
CompareAttribute comparison eventsPassword verification

Troubleshooting

No access logs: Verify the access log overlay is enabled. OpenLDAP does not log access events by default.

Log level: The stats log level provides connection and operation statistics.

389 Directory Server: Enable access logging with nsslapd-accesslog-logging-enabled: on.

Contact kyra@seekerslab.com for support.