Jenkins Integration
Jenkins build and pipeline event monitoring for self-hosted CI/CD environments.
What this integration does
Jenkins meets agentic SOC
Jenkins is the most widely deployed self-hosted CI/CD system. ManySignal integrates via the Jenkins Audit Trail Plugin, the Audit Log Plugin, and the Jenkins REST API, ingesting build execution events, plugin configuration changes, user actions, and credential access events. This provides supply chain threat visibility for organisations running on-prem or private cloud Jenkins infrastructure.
Jenkins Audit Trail Plugin log ingestion
Build and pipeline run event collection
User authentication and configuration change monitoring
Data collected
- Build trigger events with actor, branch, and repository metadata
- User login, logout, and configuration action events
- Credential access events from Jenkins Credentials Plugin
- Plugin installation, update, and removal events
- Node online/offline and executor configuration events
Actions supported
- Abort a running Jenkins build via REST API on verdict
- Disable a Jenkins job on suspicious build activity
- Alert security team on plugin installation from unknown source
- Trigger incident ticket on credential access anomaly
Getting started
Set up in minutes
- 1
Install the Audit Trail Plugin
- 2
Configure log forwarding
- 3
Create a Jenkins API token
- 4
Configure response action credentials
Jenkins Integration: frequently asked questions
Does ManySignal require network access to the Jenkins controller?
For API-based actions (abort build, disable job), ManySignal's log agent must be able to reach the Jenkins REST API. For log ingestion only, the agent pushes outbound to ManySignal — no inbound access needed.
Can ManySignal detect malicious Groovy scripts in Jenkins pipelines?
ManySignal does not parse Groovy script content directly, but can detect anomalous build behaviour: unexpected outbound connections, unusual resource consumption, and credential access outside normal pipeline steps.
Does this work with Jenkins pipelines (Declarative and Scripted)?
Yes. Both Declarative and Scripted pipeline events are captured by the Audit Trail Plugin and appear in ManySignal's event timeline.
How does ManySignal handle Jenkins running on Kubernetes?
For Jenkins on Kubernetes (JCasC pattern), deploy the ManySignal log agent as a sidecar or DaemonSet. Kubernetes audit logs can also be ingested separately for complete visibility.
Can ManySignal detect shared credentials being accessed by multiple jobs?
Yes. Jenkins Credentials Plugin access events are logged by the Audit Trail Plugin. ManySignal detects when a credential is accessed by an unexpected job or user.
What alert severity is triggered on plugin installation?
Plugin installation from an unknown or non-official source triggers a High severity alert. Known-good plugin updates from the Jenkins Update Centre are treated as Low severity informational events.
Does ManySignal support Jenkins Blue Ocean events?
Blue Ocean uses the same Jenkins core API, so events generated through the Blue Ocean UI are captured by the Audit Trail Plugin in the same way as classic UI actions.
How does this compare to cloud CI/CD (CircleCI, GitHub Actions)?
Jenkins requires a locally deployed log agent due to its self-hosted nature, whereas cloud CI/CD integrates via API. The security event coverage is comparable, with Jenkins providing deeper access to system-level events.
Can ManySignal alert on failed builds from main/master branch?
Yes. Configure build outcome alerts for specific branches in ManySignal's Jenkins connector settings.
Is there support for multi-controller Jenkins configurations?
Yes. Deploy the ManySignal log agent on each Jenkins controller and configure each with a unique connector ID in ManySignal for centralised monitoring across all controllers.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.