跳至正文

MinIO Object Storage Integration

Overview

MinIO is a high-performance, S3-compatible object storage system. KYRA MDR collects MinIO audit and access logs for monitoring bucket operations and detecting unauthorized access.

Prerequisites

  • A KYRA MDR Collector installed and running
  • MinIO server with administrative access
  • MinIO audit webhook or log output configured
  • Network connectivity from MinIO to the collector

Configuration

Configure MinIO audit logging:

  1. Enable audit logging via environment variable:
Terminal window
export MINIO_AUDIT_WEBHOOK_ENABLE_KYRA=on
export MINIO_AUDIT_WEBHOOK_ENDPOINT_KYRA=http://<collector-ip>:8080/webhook/minio
  1. Or configure via MinIO Client (mc):
Terminal window
mc admin config set myminio audit_webhook:kyra \
endpoint="http://<collector-ip>:8080/webhook/minio" \
enable="on"
mc admin service restart myminio
  1. Restart MinIO server

Collected Log Types

Log TypeDescriptionSecurity Use
API RequestsS3 API call eventsAccess pattern monitoring
AuthenticationLogin and credential eventsAccess control
Bucket OperationsBucket create, delete, policy changesData management
Object OperationsObject upload, download, deleteData access monitoring
IAMUser and policy changesIdentity management
ReplicationBucket replication eventsData protection

Troubleshooting

No webhook events: Verify the endpoint is reachable from MinIO.

Authentication: MinIO webhooks do not require authentication by default.

High volume: Filter by bucket or operation type if needed.

Contact kyra@seekerslab.com for support.