M ManySignal
MS
HV
Integration

Hashicorp Vault Integration

Secrets access audit trail ingested and anomalised in real time.

What this integration does

HashiCorp Vault meets agentic SOC

HashiCorp Vault's audit device emits a detailed log of every secrets access, authentication event, and policy change. ManySignal ingests Vault audit logs via file, syslog, or socket audit devices, enriching each event with the requesting entity's broader activity context to detect anomalous secrets access patterns and potential credential exfiltration.

File, syslog, and socket audit device log ingestion

Secrets engine event normalisation (KV, AWS, PKI, Database)

Token and lease lifecycle event tracking

Data collected

  • Vault audit log entries (every read/write/auth operation)
  • Token creation, renewal, and revocation events
  • Secrets engine dynamic credential issuance
  • Policy modification and ACL change events
  • Authentication method configuration changes

Actions supported

  • Revoke a Vault token via admin API on verdict
  • Seal Vault instance in critical incident response
  • Create investigation snapshot of active leases
  • Alert on high-value secrets path access

Getting started

Set up in minutes

  1. 1

    Enable an audit device

  2. 2

    Configure log forwarding

  3. 3

    Create a ManySignal API token in Vault

  4. 4

    Map secrets paths to asset labels

Hashicorp Vault Integration: frequently asked questions

Does ManySignal support Vault Enterprise namespaces?

Yes. ManySignal normalises Vault Enterprise namespace information from audit log entries and supports per-namespace event filtering.

What is the performance impact of enabling audit devices?

Vault audit devices are synchronous — if the audit device is unavailable, Vault will refuse requests. Use socket or syslog devices with buffering to minimise latency impact. Monitor device health in ManySignal's connector dashboard.

Can ManySignal detect compromised AppRole credentials?

Yes. Anomalous AppRole RoleID/SecretID usage from unexpected IP addresses or at unusual times is detected as a high-severity alert, correlated with other identity and network signals.

How does ManySignal handle HMAC-hashed values in Vault audit logs?

Vault HMACs sensitive values by default. ManySignal processes the HMAC values for correlation purposes. Enable 'log_raw = true' on the audit device to log plaintext values — use with caution and ensure log transport is encrypted.

Can I alert on access to specific secrets paths?

Yes. Configure path-based alert rules in ManySignal's Vault connector settings. For example, trigger a Critical alert any time the 'pki/root/sign-self-issued' path is accessed.

Does this work with HCP Vault (cloud managed)?

Yes. HCP Vault supports audit log streaming to external SIEM systems. Configure HCP Vault to stream to ManySignal's log receiver endpoint.

What response actions can ManySignal take?

ManySignal can call the Vault API to revoke tokens, revoke leases, or revoke dynamic credentials issued by the database or AWS secrets engines. Vault admin token credentials are stored encrypted in ManySignal.

How long are Vault audit logs retained in ManySignal?

Retention follows your ManySignal plan's log retention policy (typically 90 days to 1 year). Vault's own log retention is managed by your log rotation configuration.

Can ManySignal correlate Vault events with Kubernetes workload identity?

Yes. Vault's Kubernetes auth method logs include the service account and namespace. ManySignal correlates these with Kubernetes audit log events to build a full workload-to-secrets access trail.

Is Vault OSS (open source) supported?

Yes. ManySignal works with both Vault OSS and Vault Enterprise. Enterprise features (namespaces, Sentinel policies) are reflected in audit log fields that ManySignal normalises.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.