M ManySignal
MS
JK
Integration

Jenkins Integration

Jenkins build and pipeline event monitoring for self-hosted CI/CD environments.

What this integration does

Jenkins meets agentic SOC

Jenkins is the most widely deployed self-hosted CI/CD system. ManySignal integrates via the Jenkins Audit Trail Plugin, the Audit Log Plugin, and the Jenkins REST API, ingesting build execution events, plugin configuration changes, user actions, and credential access events. This provides supply chain threat visibility for organisations running on-prem or private cloud Jenkins infrastructure.

Jenkins Audit Trail Plugin log ingestion

Build and pipeline run event collection

User authentication and configuration change monitoring

Data collected

  • Build trigger events with actor, branch, and repository metadata
  • User login, logout, and configuration action events
  • Credential access events from Jenkins Credentials Plugin
  • Plugin installation, update, and removal events
  • Node online/offline and executor configuration events

Actions supported

  • Abort a running Jenkins build via REST API on verdict
  • Disable a Jenkins job on suspicious build activity
  • Alert security team on plugin installation from unknown source
  • Trigger incident ticket on credential access anomaly

Getting started

Set up in minutes

  1. 1

    Install the Audit Trail Plugin

  2. 2

    Configure log forwarding

  3. 3

    Create a Jenkins API token

  4. 4

    Configure response action credentials

Jenkins Integration: frequently asked questions

Does ManySignal require network access to the Jenkins controller?

For API-based actions (abort build, disable job), ManySignal's log agent must be able to reach the Jenkins REST API. For log ingestion only, the agent pushes outbound to ManySignal — no inbound access needed.

Can ManySignal detect malicious Groovy scripts in Jenkins pipelines?

ManySignal does not parse Groovy script content directly, but can detect anomalous build behaviour: unexpected outbound connections, unusual resource consumption, and credential access outside normal pipeline steps.

Does this work with Jenkins pipelines (Declarative and Scripted)?

Yes. Both Declarative and Scripted pipeline events are captured by the Audit Trail Plugin and appear in ManySignal's event timeline.

How does ManySignal handle Jenkins running on Kubernetes?

For Jenkins on Kubernetes (JCasC pattern), deploy the ManySignal log agent as a sidecar or DaemonSet. Kubernetes audit logs can also be ingested separately for complete visibility.

Can ManySignal detect shared credentials being accessed by multiple jobs?

Yes. Jenkins Credentials Plugin access events are logged by the Audit Trail Plugin. ManySignal detects when a credential is accessed by an unexpected job or user.

What alert severity is triggered on plugin installation?

Plugin installation from an unknown or non-official source triggers a High severity alert. Known-good plugin updates from the Jenkins Update Centre are treated as Low severity informational events.

Does ManySignal support Jenkins Blue Ocean events?

Blue Ocean uses the same Jenkins core API, so events generated through the Blue Ocean UI are captured by the Audit Trail Plugin in the same way as classic UI actions.

How does this compare to cloud CI/CD (CircleCI, GitHub Actions)?

Jenkins requires a locally deployed log agent due to its self-hosted nature, whereas cloud CI/CD integrates via API. The security event coverage is comparable, with Jenkins providing deeper access to system-level events.

Can ManySignal alert on failed builds from main/master branch?

Yes. Configure build outcome alerts for specific branches in ManySignal's Jenkins connector settings.

Is there support for multi-controller Jenkins configurations?

Yes. Deploy the ManySignal log agent on each Jenkins controller and configure each with a unique connector ID in ManySignal for centralised monitoring across all controllers.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.