Integration Category
Data Platform Integrations
Snowflake, Databricks, MongoDB Atlas — ManySignal monitors your data warehouses and analytics platforms for insider threats, credential abuse, and mass data exfiltration.
Data platform integrations
Snowflake
Query history, login events, role changes, data export monitoring
Databricks
Audit log, cluster lifecycle, notebook access, Unity Catalog events
MongoDB Atlas
Database access events, user auth, configuration changes
Apache Kafka
Consumer group monitoring and security event topic ingestion
Data platform integration FAQs
Why should security teams monitor data platforms?
Cloud data platforms (Snowflake, Databricks, BigQuery) store an organisation's most valuable data — customer records, financial data, intellectual property. Insider threats, compromised credentials, and misconfigured access controls targeting these platforms can result in catastrophic data breaches. The 2024 Snowflake-related breaches (Ticketmaster, Santander) demonstrated the scale of risk.
What Snowflake events does ManySignal monitor?
ManySignal ingests Snowflake ACCOUNT_USAGE views: QUERY_HISTORY (all executed queries), ACCESS_HISTORY (table-level data access), LOGIN_HISTORY (authentication events), and GRANTS_TO_USERS (privilege changes). Mass data export and credential anomalies are the primary detection targets.
Can ManySignal detect the Snowflake credential stuffing pattern from 2024?
Yes. ManySignal detects the specific pattern from the 2024 Snowflake breaches: authentication without MFA, from a new IP/country, to a Snowflake instance without IP allowlisting. These three signals together constitute a High severity alert.
Does ManySignal support Databricks Unity Catalog?
Yes. Unity Catalog audit events (table access, privilege grants, schema changes) are captured in Databricks audit logs and fully normalised by ManySignal for anomaly detection and compliance reporting.
How does ManySignal handle the Snowflake ACCOUNT_USAGE latency?
Snowflake ACCOUNT_USAGE views have a ~45-minute latency. ManySignal uses ACCOUNT_USAGE for historical correlation and periodically queries INFORMATION_SCHEMA for near-real-time session monitoring.
Can ManySignal detect mass data exports from Snowflake?
Yes. ManySignal alerts when a user retrieves more than a configurable row threshold in a session, or when COPY INTO commands export more than a configured volume. Thresholds are set per user or per role in the connector settings.
Does ManySignal integrate with Databricks MLflow?
MLflow model registry events (model creation, version promotion, deletion) are captured in Databricks audit logs. ManySignal alerts on unexpected model version promotions or access to production models from development accounts.
How does Kafka integration work with ManySignal?
ManySignal's Kafka consumer subscribes to configured security event topics, ingesting events in real time. OCSF, CEF, and JSON formats are supported. This is used for organisations that aggregate security events into Kafka before routing to their SOC platform.
What compliance frameworks benefit from data platform monitoring?
SOC 2 (CC6 — Logical and Physical Access), HIPAA (164.312 — Access Controls), PCI DSS (Requirement 7 — Restrict Access to Cardholder Data), and GDPR (Article 32 — Security of Processing) all require access monitoring for databases handling regulated data.
Does ManySignal support MongoDB Atlas for database security?
Yes. MongoDB Atlas audit log events including authentication, database access, and configuration changes are ingested by ManySignal. Anomalous query patterns and access from unexpected locations are detected.
Protect your cloud data warehouse
Connect Snowflake or Databricks to ManySignal and detect data access threats in real time.