Slack Audit Logs
Overview
Slack Enterprise Grid provides audit logging that captures user, channel, file, and application events across the organization. KYRA MDR collects these events via the Slack Audit Logs API to detect data exfiltration, unauthorized workspace access, and policy violations.
Prerequisites
- KYRA MDR account (MDR tier or above)
- KYRA Collector installed with outbound HTTPS access to
api.slack.com - Slack Enterprise Grid plan (Audit Logs API is not available on Free, Pro, or Business+ plans)
- A Slack app installed at the organization level (not workspace level) with appropriate OAuth scopes
Configuration
Step 1: Create a Slack App for Audit Log Access
- Go to api.slack.com/apps and click Create New App > From scratch
- Enter a name (e.g., “KYRA MDR Audit”) and select your Enterprise Grid organization
- Navigate to OAuth & Permissions and add the following User Token Scopes:
auditlogs:read— required for reading audit events
- Click Install to Organization (must be installed by an Org Owner or Org Admin)
- Record the User OAuth Token (starts with
xoxp-)
Step 2: Configure KYRA Collector
source: type: slack-audit token: "xoxp-<USER_OAUTH_TOKEN>" poll_interval: 300 # seconds collect: - user # login, logout, role changes - channel # create, delete, archive, convert - file # upload, download, share - app # install, approve, restrict - workspace # settings changes - message # message_tombstoned (deleted), pinnedkyra-collector reloadkyra-collector statusStep 3: Verify API Access
Test the Audit Logs API:
# Fetch recent audit eventscurl -s -H "Authorization: Bearer xoxp-<TOKEN>" \ "https://api.slack.com/audit/v1/logs?limit=5" \ | jq '.entries[] | {id, date_create, action, actor: .actor.user.email, entity: .entity.type}'
# Filter by action typecurl -s -H "Authorization: Bearer xoxp-<TOKEN>" \ "https://api.slack.com/audit/v1/logs?action=user_login&limit=10" \ | jq '.entries[] | {action, actor: .actor.user.email, date_create, context: .context.ip_address}'
# Filter by date range (Unix timestamps)curl -s -H "Authorization: Bearer xoxp-<TOKEN>" \ "https://api.slack.com/audit/v1/logs?oldest=1700000000&latest=1700086400&limit=50" \ | jq '.entries | length'Step 4: List Available Actions and Schemas
# Get the list of all audit log actionscurl -s -H "Authorization: Bearer xoxp-<TOKEN>" \ "https://api.slack.com/audit/v1/actions" \ | jq 'to_entries[] | {category: .key, actions: [.value[].action]}'
# Get the audit log schemacurl -s -H "Authorization: Bearer xoxp-<TOKEN>" \ "https://api.slack.com/audit/v1/schemas" \ | jq '.schemas[] | .type'Step 5: Verify on KYRA Collector
kyra-collector logs --source slack-audit --tail 10Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| User Events | user_login, user_logout, user_created, role_change_to_admin, user_deactivated | Account security, access monitoring |
| Channel Events | channel_created, channel_deleted, channel_converted_to_public, channel_archive | Data governance |
| File Events | file_uploaded, file_downloaded, file_shared_externally, file_public_link_created | Data loss prevention |
| App Events | app_installed, app_approved, app_restricted, app_scopes_expanded | Supply chain security |
| Workspace Events | emoji_added, workspace_settings_changed, retention_changed | Policy compliance |
| Message Events | message_tombstoned, message_pinned, message_unpinned | Content monitoring |
Key Audit Log Event Categories
| Category | Actions | Security Relevance |
|---|---|---|
| Authentication | user_login, user_login_failed, user_session_invalidated | Brute force detection, session hijacking |
| Access Control | role_change_to_admin, role_change_to_owner, guest_created | Privilege escalation |
| Data Movement | file_downloaded, file_shared_externally, public_link_created | Data exfiltration |
| Integrations | app_installed, app_scopes_expanded, incoming_webhook_created | Malicious app installation |
| Compliance | retention_changed, ekm_key_changed, dlp_policy_updated | Regulatory compliance |
Security-Critical Slack Events
| Event | Indicator | Description |
|---|---|---|
user_login_failed burst | Brute force | Multiple failed login attempts for same user |
role_change_to_owner | Privilege escalation | User elevated to workspace/org owner |
channel_converted_to_public | Data exposure | Private channel made public |
file_shared_externally | Data leakage | File shared outside the organization |
app_installed with broad scopes | Supply chain risk | Third-party app with excessive permissions |
user_session_invalidated not by user | Account compromise | Admin force-logging out a user (indicator of incident response) |
retention_changed to shorter period | Evidence destruction | Message retention period shortened |
Troubleshooting
not_allowed_token_typeerror: The Audit Logs API requires a User OAuth Token (xoxp-), not a Bot Token (xoxb-). Reinstall the app with user token scopes.missing_scopeerror: Verify the app has theauditlogs:readscope under User Token Scopes (not Bot Token Scopes).paid_teams_onlyerror: Audit Logs API is exclusive to Enterprise Grid. Business+ and lower plans cannot access this API.- Empty results: The app must be installed at the organization level, not a single workspace. Go to Organization Settings > Apps to verify.
- Rate limiting (429): Slack allows approximately 25 requests per minute for the Audit Logs API. Increase
poll_intervaland use pagination cursors instead of overlapping time windows. - Missing IP addresses: IP addresses in
context.ip_addressmay benullfor API-initiated actions. Only interactive user actions include IP data.
Contact kyra@seekerslab.com for integration support.