M ManySignal
MS
PI
Integration

Ping Identity Integration

Enterprise identity telemetry from PingFederate, PingOne, and PingAccess.

What this integration does

Ping Identity meets agentic SOC

Ping Identity's enterprise SSO and access management platform generates rich authentication and authorisation event streams. ManySignal ingests PingFederate audit logs, PingOne activity events, and PingAccess access logs via the PingOne Audit Log API and syslog-based exports, normalising all events to OCSF for correlation with endpoint and cloud telemetry.

PingFederate authentication and STS event ingestion

PingOne audit log collection via REST API

PingAccess gateway access log parsing

Data collected

  • PingFederate SSO authentication success and failure events
  • PingOne user lifecycle events (create, modify, delete, suspend)
  • PingAccess application access log entries
  • OAuth 2.0 token issuance and refresh events
  • MFA challenge and response events

Actions supported

  • Suspend PingOne user account on verdict
  • Force PingOne session termination
  • Trigger PingFederate account lock via admin API
  • Alert on federation partner configuration change

Getting started

Set up in minutes

  1. 1

    Create a PingOne admin API credential

  2. 2

    Configure audit log export

  3. 3

    Add the connector in ManySignal

  4. 4

    Validate event flow

Ping Identity Integration: frequently asked questions

Does ManySignal support PingFederate on-premises deployments?

Yes. For on-prem PingFederate, configure syslog or HTTP audit log export to ManySignal's log receiver. Cloud-based PingOne is also supported via the REST API.

Can ManySignal detect SAML token forgery via Ping?

ManySignal correlates SAML assertions with user context, flagging assertions from unusual source IPs, at unusual times, or with abnormal attribute sets that may indicate Golden SAML-style attacks.

What PingFederate audit log categories should I enable?

Enable Authentication, PasswordManagement, OAuthAudit, STS, and AdaptiveAuthentication categories for full coverage.

How does this compare to Okta integration?

Functionally equivalent — both provide authentication telemetry and support automated response. The Ping integration uses syslog/HTTP for on-prem and REST API for cloud, while Okta uses the System Log API.

Can ManySignal correlate Ping events with CrowdStrike endpoint data?

Yes. ManySignal's entity graph links Ping user identities to endpoint sessions, enabling correlated detections that span identity and endpoint telemetry.

Is PingDirectory supported?

PingDirectory LDAP access logs can be ingested via the syslog connector. Specific PingDirectory-native API support is on the roadmap.

How are Adaptive MFA failures handled?

PingOne adaptive MFA step-up failures are ingested as authentication events. ManySignal correlates repeated MFA failures with other signals to detect MFA fatigue and push bombing attacks.

What response actions are available?

ManySignal can call the PingOne User Management API to suspend accounts, force password resets, or terminate sessions. PingFederate admin API actions are available for on-prem deployments with API access enabled.

Is there a latency impact from log collection?

Log collection is asynchronous and has no impact on the PingFederate or PingOne authentication path. Events appear in ManySignal within 30–90 seconds of occurrence.

Can I filter which applications generate events?

Yes. ManySignal supports application-level filtering in the connector configuration, allowing you to include or exclude specific PingOne application IDs from ingestion.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.