Slack Audit Logs Integration
Overview
Slack provides team messaging and collaboration with enterprise audit logging capabilities. KYRA MDR collects Slack audit logs via the Audit Logs API for security monitoring and compliance. Requires Slack Enterprise Grid plan.
Prerequisites
- A KYRA MDR Collector installed and running
- Slack Enterprise Grid plan
- Slack app with
auditlogs:readscope installed at organization level - Organization Owner or Admin role
Configuration
Configure Slack Audit Logs app:
- Go to Slack API > Your Apps > Create New App
- Add OAuth scopes:
auditlogs:read - Install the app at the organization level
- Copy the OAuth Token
- Configure the KYRA MDR collector:
sources: - type: slack api_token: <oauth-token> poll_interval: 120s- Restart the collector service
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| User Login | User authentication events | Access monitoring, brute force detection |
| User Logout | User session termination | Session management |
| File Operations | File upload, download, share events | Data loss prevention |
| Channel Operations | Channel creation, archival, deletion | Collaboration monitoring |
| App Operations | App install, approval, removal | Shadow IT detection |
| Admin Actions | Workspace and org admin changes | Security policy auditing |
Troubleshooting
Audit logs not available: Slack Audit Logs API is only available for Enterprise Grid plans.
Missing events: Ensure the Slack app is installed at the organization level, not individual workspace level.
Token issues: Slack OAuth tokens do not expire, but they can be revoked. Check the app installation status.
Contact kyra@seekerslab.com for support.