MongoDB Audit Integration
Overview
MongoDB is a document-oriented NoSQL database. KYRA MDR collects MongoDB audit logs for monitoring database access and authentication events. Supports MongoDB Enterprise 5.x and 6.x.
Prerequisites
- A KYRA MDR Collector installed and running
- MongoDB Enterprise (for native auditing) or Community Edition
- Administrative access to the MongoDB instance
- Network connectivity from the MongoDB host to the collector
Configuration
Configure MongoDB Enterprise audit logging:
# mongod.confauditLog: destination: syslog format: JSON filter: '{atype: {$in: ["authenticate", "createUser", "dropUser", "authCheck"]}}'
setParameter: auditAuthorizationSuccess: trueRestart MongoDB:
sudo systemctl restart mongodConfigure syslog forwarding:
if $programname == 'mongod' then @@<collector-ip>:514Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Authentication | Login success and failure events | Access monitoring |
| Authorization | Permission check events | Privilege escalation detection |
| CRUD Operations | Data access and modification | Data security auditing |
| Schema Changes | Collection and index changes | Schema integrity monitoring |
| User Management | User creation and role changes | Identity management |
| Replication | Replica set events | Database availability |
Troubleshooting
Audit not available: Native audit logging requires MongoDB Enterprise.
High volume: Use the filter parameter to limit audited operations.
Syslog format: Set the audit log format to JSON for proper parsing.
Contact kyra@seekerslab.com for support.