Hub
Security

HashiCorp Vault Audit

Selected HashiCorp Vault v1.18.0 file-audit profile: linked request and response entries for KV v2 reads and lists, token self-lookup and renewal, and denied audit-device deletion, with the native audit JSON in event.original inside ECS-compatible JSON. Recurring episodes have one existing identity read ten distinct payroll secrets, then attempt to delete the audit device.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/security-hashicorp-vault/generator.yml \
  --id vault \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
kv-read-app-billingKV v2 read of an application/billing secret48.1% measured share (48.6% background only)authentication
kv-read-payrollKV v2 read of a payroll secret30.3% measured share (29.4% background only)authentication
token-lookup-selfToken reads its own remaining lifetime10.9% measured share (10.7% background only)authentication
kv-metadata-listKV v2 metadata list of existing child names10.4% measured share (10.8% background only)authentication
audit-delete-deniedReader ACL denies deleting sys/audit/file0.25% measured share (0.24% background only)authentication
token-renew-selfPeriodic 24-hour token renews itself0.19% measured share (0.19% background only)authentication

Realism Features

  • Each operation emits a request and a response entry with the same fresh UUID, the request first: one operation per 30-second period at a random moment inside it, 2,880 operations and 5,760 entries a day. Operations never overlap, and rates are stationary, with no daily or weekly cycle. Shares and timings are training assumptions, not production frequencies.
  • Four existing userpass identities with the default and training-reader policies use a fixed inventory of 52 version-1 KV v2 secrets (12 application/billing, 40 payroll). The reader ACL grants read and list, the default policy self-lookup and renewal, and neither grants audit management, so both entries of a denied audit DELETE keep valid authentication, policy_results.allowed=false and a hashed response error. No secret write, token creation or revocation is included.
  • Background is the same in both modes: single reads, lists and lookups by accounts weighted 45/25/20/10; about 12 payroll batches a day (an ascending employee range or a random subset, median about 6 reads, runs of 10 or more several times a day); about 4 denied audit deletions a day, as from a misconfigured maintenance script, spread over the four accounts, 35% retried after a median 45 seconds. A client reuses its source port until it has been idle for more than 90 seconds. An account's audit DELETE never follows its reads of three or more distinct payroll secrets within 400 seconds.
  • Tokens renew on the LifetimeWatcher schedule, 16.8-17.6 hours after login or the previous renewal; unlike a real watcher, the grace is redrawn every cycle and no start-up renewal is emitted. Lookups report remaining TTL and last_renewal, while auth.token_ttl stays the 86,400-second creation period.
  • Tokens, accessors and string values are keyed HMAC-SHA256 with one synthetic device salt; typed lookup times stay readable. @timestamp carries the source time at millisecond precision, event.ingested, in whole seconds, lags it log-normally (median about 2.5 s), and log.offset follows the UTF-8 byte length of each native line in the unrotated audit file.
  • All 47 leaf paths of the pinned Elastic sample occur, which shows field presence only. The structures follow tagged vendor code and older maintained raw examples rather than a complete live v1.18.0 audit log; optional headers, enterprise fields and other endpoints are omitted, mount accessors are synthetic, and agent_id_status verified is synthetic collector context. The records do not prove exfiltration or a successful audit shutdown.

Sample Output

{
  "@timestamp": "2026-10-01T05:16:22.035Z",
  "agent": {
    "ephemeral_id": "8dcba887-bc9d-44cb-bfcd-ed7aa7216748",
    "id": "65fa5f58-a1d2-49d1-b4cc-05228dd270f3",
    "name": "vault-01.corp.example",
    "type": "filebeat",
    "version": "8.10.1"
  },
  "data_stream": {
    "dataset": "hashicorp_vault.audit",
    "namespace": "default",
    "type": "logs"
  },
  "ecs": {
    "version": "8.17.0"
  },
  "elastic_agent": {
    "id": "65fa5f58-a1d2-49d1-b4cc-05228dd270f3",
    "snapshot": false,
    "version": "8.10.1"
  },
  "event": {
    "action": "delete",
    "agent_id_status": "verified",
    "category": [
      "authentication"
    ],
    "dataset": "hashicorp_vault.audit",
    "id": "a917f31c-f870-4214-8273-e7a6f7ad7d81",
    "ingested": "2026-10-01T05:16:24Z",
    "kind": "event",
    "original": "{\"auth\":{\"accessor\":\"hmac-sha256:89da18efff447c7106a0b567cc5ac92c9e615a04b982d217297980ba127f7647\",\"client_token\":\"hmac-sha256:03b219fc9970dfb36c081da9310016fd91bac6e4576222632e55786ba422829a\",\"display_name\":\"userpass-svc-reports\",\"entity_id\":\"96fa6c68-63af-43dc-a9ea-f59556f4b5ea\",\"metadata\":{\"username\":\"svc-reports\"},\"policies\":[\"default\",\"training-reader\"],\"policy_results\":{\"allowed\":false},\"token_policies\":[\"default\",\"training-reader\"],\"token_issue_time\":\"2026-09-30T19:03:00Z\",\"token_ttl\":86400,\"token_type\":\"service\"},\"error\":\"1 error occurred:\\n\\t* permission denied\\n\\n\",\"request\":{\"client_id\":\"96fa6c68-63af-43dc-a9ea-f59556f4b5ea\",\"client_token\":\"hmac-sha256:03b219fc9970dfb36c081da9310016fd91bac6e4576222632e55786ba422829a\",\"client_token_accessor\":\"hmac-sha256:89da18efff447c7106a0b567cc5ac92c9e615a04b982d217297980ba127f7647\",\"id\":\"a917f31c-f870-4214-8273-e7a6f7ad7d81\",\"mount_class\":\"secret\",\"mount_point\":\"sys/\",\"mount_type\":\"system\",\"namespace\":{\"id\":\"root\"},\"operation\":\"delete\",\"path\":\"sys/audit/file\",\"remote_address\":\"198.51.100.44\",\"remote_port\":35802,\"request_uri\":\"/v1/sys/audit/file\"},\"response\":{\"mount_class\":\"secret\",\"mount_point\":\"sys/\",\"mount_type\":\"system\",\"data\":{\"error\":\"hmac-sha256:ec125ce39ac232369c1e227ed31f30b8b1a43010aa94029c6b423af8d061ce97\"}},\"time\":\"2026-10-01T05:16:22.035826968Z\",\"type\":\"response\"}",
    "outcome": "failure",
    "type": [
      "info",
      "end"
    ]
  },
  "hashicorp_vault": {
    "audit": {
      "auth": {
        "accessor": "hmac-sha256:89da18efff447c7106a0b567cc5ac92c9e615a04b982d217297980ba127f7647",
        "client_token": "hmac-sha256:03b219fc9970dfb36c081da9310016fd91bac6e4576222632e55786ba422829a",
        "display_name": "userpass-svc-reports",
        "entity_id": "96fa6c68-63af-43dc-a9ea-f59556f4b5ea",
        "metadata": {
          "username": "svc-reports"
        },
        "policies": [
          "default",
          "training-reader"
        ],
        "policy_results": {
          "allowed": false
        },
        "token_issue_time": "2026-09-30T19:03:00Z",
        "token_policies": [
          "default",
          "training-reader"
        ],
        "token_ttl": 86400,
        "token_type": "service"
      },
      "error": "1 error occurred:\n\t* permission denied\n\n",
      "request": {
        "client_id": "96fa6c68-63af-43dc-a9ea-f59556f4b5ea",
        "client_token": "hmac-sha256:03b219fc9970dfb36c081da9310016fd91bac6e4576222632e55786ba422829a",
        "client_token_accessor": "hmac-sha256:89da18efff447c7106a0b567cc5ac92c9e615a04b982d217297980ba127f7647",
        "id": "a917f31c-f870-4214-8273-e7a6f7ad7d81",
        "mount_class": "secret",
        "mount_point": "sys/",
        "mount_type": "system",
        "namespace": {
          "id": "root"
        },
        "operation": "delete",
        "path": "sys/audit/file",
        "remote_address": "198.51.100.44",
        "remote_port": 35802,
        "request_uri": "/v1/sys/audit/file"
      },
      "response": {
        "data": {
          "error": "hmac-sha256:ec125ce39ac232369c1e227ed31f30b8b1a43010aa94029c6b423af8d061ce97"
        },
        "mount_class": "secret",
        "mount_point": "sys/",
        "mount_type": "system"
      },
      "type": "response"
    }
  },
  "host": {
    "architecture": "x86_64",
    "containerized": false,
    "hostname": "vault-01.corp.example",
    "id": "f25e61f1c11d44bd9aee4a28a664ec18",
    "ip": [
      "10.20.2.18"
    ],
    "mac": [
      "02-42-0A-14-02-12"
    ],
    "name": "vault-01.corp.example",
    "os": {
      "codename": "bookworm",
      "family": "debian",
      "kernel": "6.1.0",
      "name": "Debian",
      "platform": "debian",
      "type": "linux",
      "version": "12"
    }
  },
  "input": {
    "type": "filestream"
  },
  "log": {
    "file": {
      "path": "/var/log/vault/audit.json"
    },
    "offset": 1967148
  },
  "message": "1 error occurred:\n\t* permission denied\n\n",
  "related": {
    "ip": [
      "198.51.100.44"
    ],
    "user": [
      "svc-reports"
    ]
  },
  "source": {
    "ip": "198.51.100.44",
    "port": 35802
  },
  "tags": [
    "hashicorp-vault-audit"
  ],
  "user": {
    "name": "svc-reports"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetruePeriodic episodes mixed with background; false produces background only
anomaly_interval_hours24Hours from one episode's first read to the centre of the next episode's start window, 6 to 8,760
vault_hostvault-01.corp.exampleVault node and collector hostname
vault_ip10.20.2.18Vault node address
collector_id65fa5f58-a1d2-49d1-b4cc-05228dd270f3Stable collector ID
collector_ephemeral_id8dcba887-bc9d-44cb-bfcd-ed7aa7216748Collector process ID
collector_version8.10.1Collector version
suspicious_ip198.51.100.44Fourth identity's peer address, used in background and eligible episodes
suspicious_actorsvc-reportsFourth existing userpass account, used in background and eligible episodes; must differ from svc-api, svc-billing and alice
secret_mountsecretSelected KV v2 mount, without leading or trailing slash; change the ACL mount paths too

Related Generators