Hashicorp Vault Integration
Secrets access audit trail ingested and anomalised in real time.
What this integration does
HashiCorp Vault meets agentic SOC
HashiCorp Vault's audit device emits a detailed log of every secrets access, authentication event, and policy change. ManySignal ingests Vault audit logs via file, syslog, or socket audit devices, enriching each event with the requesting entity's broader activity context to detect anomalous secrets access patterns and potential credential exfiltration.
File, syslog, and socket audit device log ingestion
Secrets engine event normalisation (KV, AWS, PKI, Database)
Token and lease lifecycle event tracking
Data collected
- Vault audit log entries (every read/write/auth operation)
- Token creation, renewal, and revocation events
- Secrets engine dynamic credential issuance
- Policy modification and ACL change events
- Authentication method configuration changes
Actions supported
- Revoke a Vault token via admin API on verdict
- Seal Vault instance in critical incident response
- Create investigation snapshot of active leases
- Alert on high-value secrets path access
Getting started
Set up in minutes
- 1
Enable an audit device
- 2
Configure log forwarding
- 3
Create a ManySignal API token in Vault
- 4
Map secrets paths to asset labels
Hashicorp Vault Integration: frequently asked questions
Does ManySignal support Vault Enterprise namespaces?
Yes. ManySignal normalises Vault Enterprise namespace information from audit log entries and supports per-namespace event filtering.
What is the performance impact of enabling audit devices?
Vault audit devices are synchronous — if the audit device is unavailable, Vault will refuse requests. Use socket or syslog devices with buffering to minimise latency impact. Monitor device health in ManySignal's connector dashboard.
Can ManySignal detect compromised AppRole credentials?
Yes. Anomalous AppRole RoleID/SecretID usage from unexpected IP addresses or at unusual times is detected as a high-severity alert, correlated with other identity and network signals.
How does ManySignal handle HMAC-hashed values in Vault audit logs?
Vault HMACs sensitive values by default. ManySignal processes the HMAC values for correlation purposes. Enable 'log_raw = true' on the audit device to log plaintext values — use with caution and ensure log transport is encrypted.
Can I alert on access to specific secrets paths?
Yes. Configure path-based alert rules in ManySignal's Vault connector settings. For example, trigger a Critical alert any time the 'pki/root/sign-self-issued' path is accessed.
Does this work with HCP Vault (cloud managed)?
Yes. HCP Vault supports audit log streaming to external SIEM systems. Configure HCP Vault to stream to ManySignal's log receiver endpoint.
What response actions can ManySignal take?
ManySignal can call the Vault API to revoke tokens, revoke leases, or revoke dynamic credentials issued by the database or AWS secrets engines. Vault admin token credentials are stored encrypted in ManySignal.
How long are Vault audit logs retained in ManySignal?
Retention follows your ManySignal plan's log retention policy (typically 90 days to 1 year). Vault's own log retention is managed by your log rotation configuration.
Can ManySignal correlate Vault events with Kubernetes workload identity?
Yes. Vault's Kubernetes auth method logs include the service account and namespace. ManySignal correlates these with Kubernetes audit log events to build a full workload-to-secrets access trail.
Is Vault OSS (open source) supported?
Yes. ManySignal works with both Vault OSS and Vault Enterprise. Enterprise features (namespaces, Sentinel policies) are reflected in audit log fields that ManySignal normalises.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.