This tutorial covers configuration of HCP Vault audit logs streaming to your existing Datadog environment.
HCP Vault audit logs streaming is available for all production grade clusters. The feature is not available for Development tier clusters.
To configure audit logs streaming to Splunk Cloud or Enterprise, you will need to have:
Your Datadog region and API key
An account with Admin or Contributor role assigned in HCP
A production grade HCP Vault cluster
From the HCP Vault cluster Overview page, select the Audit Logs view.
Click Enable log Streaming.
From the Enable audit logs streaming view, select Datadog as the provider and click Next.
Under Datadog configuration, enter your API Key and select the Datadog site region that matches your existing Datadog environment.
At this time, HCP Vault only supports audit logs streaming to one log endpoint at a time.
Refer to the Datadog documentation for details on log exploration.
To edit a audit log streaming integration, perform the following steps.
From the Audit Logs page, click on the Manage drop-down, then Edit configuration.
Edit the configuration, then click Save.
To disable a audit log streaming integration, from the Audit Logs page, click on the Manage drop-down, then Disable streaming.