跳至正文

Redis Logs

Overview

Redis is an in-memory data store used for caching, session management, and message brokering. KYRA MDR collects Redis server logs, slow query logs, ACL violations, and keyspace notifications to detect unauthorized access, data exfiltration, and configuration changes.

Prerequisites

  • KYRA MDR account (MDR tier or above)
  • KYRA Collector installed and reachable from the Redis host
  • Redis 6.0+ (for ACL support) or Redis 5.x (basic logging)
  • Administrative access to the Redis server configuration

Configuration

Step 1: Configure Redis Server Logging

Edit /etc/redis/redis.conf:

# Set log level (debug, verbose, notice, warning)
loglevel notice
# Log to a file
logfile /var/log/redis/redis-server.log
# Enable syslog output
syslog-enabled yes
syslog-ident redis
syslog-facility local0
Terminal window
sudo systemctl restart redis

Step 2: Configure Slow Query Logging

# Log queries slower than 10ms (10000 microseconds)
slowlog-log-slower-than 10000
# Keep last 128 slow queries
slowlog-max-len 128
Terminal window
# View slow queries
redis-cli SLOWLOG GET 10
# Get count and reset
redis-cli SLOWLOG LEN
redis-cli SLOWLOG RESET

Step 3: Configure ACL Logging (Redis 6.0+)

# Maximum ACL log entries
acllog-max-len 128
Terminal window
# View ACL violations
redis-cli ACL LOG 10
# Reset ACL log
redis-cli ACL LOG RESET

Step 4: Enable Keyspace Notifications

Terminal window
# Enable notifications for all key events
redis-cli CONFIG SET notify-keyspace-events KEA
# In redis.conf for persistence:
# notify-keyspace-events KEA
#
# K = Keyspace events, E = Keyevent events
# g = Generic commands (DEL, EXPIRE, RENAME)
# $ = String commands, l = List, s = Set, h = Hash, z = Sorted set
# x = Expired events, e = Evicted events
# A = Alias for "g$lshzxe" (all events)

Step 5: Forward Logs via rsyslog

/etc/rsyslog.d/30-redis.conf
local0.* @@<COLLECTOR_IP>:514
Terminal window
sudo systemctl restart rsyslog

Step 6: Periodic Metric Collection

#!/bin/bash
# /opt/kyra/redis-audit.sh - cron every 5 minutes
REDIS_CLI="redis-cli -a <PASSWORD>"
COLLECTOR="<COLLECTOR_IP>"
# Collect slow queries
$REDIS_CLI SLOWLOG GET 50 | logger -t redis-slowlog -n $COLLECTOR -P 514 --tcp
# Collect ACL violations
$REDIS_CLI ACL LOG 50 | logger -t redis-acl -n $COLLECTOR -P 514 --tcp
# Collect client list
$REDIS_CLI CLIENT LIST | logger -t redis-clients -n $COLLECTOR -P 514 --tcp
# Collect INFO stats
$REDIS_CLI INFO stats | logger -t redis-stats -n $COLLECTOR -P 514 --tcp
# Reset after collection
$REDIS_CLI SLOWLOG RESET
$REDIS_CLI ACL LOG RESET
Terminal window
echo "*/5 * * * * /opt/kyra/redis-audit.sh" | sudo crontab -

Verify on KYRA Collector

Terminal window
kyra-collector status
kyra-collector logs --source redis --tail 5

Collected Log Types

Log TypeDescriptionSecurity Use
Server LogsStartup, shutdown, config changes, replication eventsAvailability monitoring
Slow QueriesCommands exceeding time thresholdPerformance abuse detection
ACL LogUnauthorized command attemptsAccess violation detection
Keyspace NotificationsKey create, modify, delete, expire eventsData change monitoring
Client ConnectionsConnected clients with IP, name, age, idle timeUnauthorized connection detection
INFO StatsCommand counts, memory, connections, keyspaceAnomaly baseline

Security Commands

CommandDescription
ACL LOGView authentication and authorization failures
SLOWLOG GETRetrieve slow query entries
CLIENT LISTList all connected clients (IP, name, age)
CONFIG GET *View configuration (detect misconfigurations)
INFO statsCommand stats, rejected connections
INFO clientsConnected client count, blocked clients

Security-Critical Events

EventIndicatorDescription
rejected_connections increasingBrute forcePassword guessing attempts
ACL violation for CONFIGPrivilege escalationAttempt to modify server config
ACL violation for DEBUG, MODULECode executionAttempt to load malicious modules
ACL violation for SLAVEOF, REPLICAOFData exfiltrationAttempt to replicate to attacker server
FLUSHALL / FLUSHDBData destructionDatabase wipe attempt
KEYS * patternReconnaissanceEnumeration of all keys

Troubleshooting

  • No syslog output: Verify syslog-enabled yes in redis.conf and restart Redis. Check redis-cli CONFIG GET syslog-enabled.
  • ACL LOG empty: Requires Redis 6.0+. Older versions only log auth failures in server log.
  • Keyspace notifications not firing: Check redis-cli CONFIG GET notify-keyspace-events. Empty string means disabled.
  • High volume from keyspace: Using KEA on high-throughput Redis generates massive volume. Filter to Kgx for generic and expired events only.
  • Protected mode: Redis 3.2+ has protected mode. Ensure Collector connects from allowed IP or uses password auth.

Contact kyra@seekerslab.com for integration support.