Skip to content

HVD: vault: enrich audit device guidance with schema reference and two-device setup (HVD-1830) - #3082

Draft
danbr-ibm wants to merge 1 commit into
mainfrom
migrate-hvd-pr-387-audit-device
Draft

HVD: vault: enrich audit device guidance with schema reference and two-device setup (HVD-1830)#3082
danbr-ibm wants to merge 1 commit into
mainfrom
migrate-hvd-pr-387-audit-device

Conversation

@danbr-ibm

@danbr-ibm danbr-ibm commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

Summary

Addresses two customer pain points in the Vault Initial Configuration HVD, surfaced via FRB-6800 (Honeywell, BCG, 7+ enterprise accounts, $30M+ signal) and VSM-226:

  1. Missing audit log field dictionary - SIEM engineers building integrations in Splunk/Datadog had no field-level reference for the JSON log structure. Customers had already found the upstream schema docs and found them insufficient.
  2. Insufficient two-device configuration guidance - the existing HVD said to configure two devices but didn't say which two, why, or answer the common follow-up questions (does it double I/O? which disk? what options?).

Source PR being migrated: https://github.com/hashicorp/hvd-docs/pull/387

Changes

Updated files:

  • content/validated-designs/docs/docs/vault/installation-guide/vms/post-installation-configuration.mdx
  • content/validated-designs/docs/docs/vault/administration-guide/monitoring-and-observability.mdx

Main guidance themes migrated:

  • Device type descriptions with stronger recommendations for file, syslog, and socket audit devices
  • Recommended two-device setup using file plus syslog
  • Recommended enable commands including elide_list_responses=true and hmac_accessor=false
  • Verification step using vault audit list
  • Enterprise audit device features including filtering, fallback devices, and entry exclusion
  • Audit log entry schema reference with top-level, authentication, and request object fields

Notes

This is a draft PR created as part of the HVD migration from hashicorp/hvd-docs into hashicorp/web-unified-docs. The content is being moved as-is in draft form so any follow-up review and cleanup can happen in the correct repository.

Move the draft audit-device guidance from the old hvd-docs PR into web-unified-docs so the validated design can continue in the repository that now owns HVD content.

This preserves the source PR's expanded audit-device recommendations, two-device setup guidance, verification steps, and audit-log schema reference without trying to resolve draft-stage follow-up work during the migration itself.

Keeping the migration focused on content transfer makes the old and new PRs easier to compare and lets any remaining review happen in the correct repository.
@danbr-ibm danbr-ibm added AI used Warning: human SME checks required Validated Designs labels Aug 11, 2026
@github-actions

github-actions Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Vercel Previews Deployed

Name Status Preview Updated (UTC)
Dev Portal ✅ Ready (Inspect) Visit Preview Tue Aug 11 15:22:47 UTC 2026
Unified Docs API ✅ Ready (Inspect) Visit Preview Tue Aug 11 15:18:02 UTC 2026

@github-actions

Copy link
Copy Markdown
Contributor

Broken Link Checker

This PR contains broken links, but won't be blocked. Use this report to improve content quality:

Quick Actions

  • Internal links (HashiCorp sites): Please fix these - they impact user experience
  • External links: Consider if these are essential or can be updated/removed
  • Temporary issues: External sites may recover - check again before merging

Need Help?


Internal Links

Full Github Actions output

External Links

Summary

Status Count
🔍 Total 52
✅ Successful 6
⏳ Timeouts 0
🔀 Redirected 3
👻 Excluded 43
❓ Unknown 0
🚫 Errors 0
⛔ Unsupported 0

Redirects per input

Redirects in content/validated-designs/docs/docs/vault/administration-guide/monitoring-and-observability.mdx

Redirects in content/validated-designs/docs/docs/vault/installation-guide/vms/post-installation-configuration.mdx

Full Github Actions output

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI used Warning: human SME checks required Validated Designs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant