Databricks Integration
Databricks audit log ingestion for data platform and MLOps security.
What this integration does
Databricks meets agentic SOC
Databricks emits comprehensive audit logs covering workspace access, cluster lifecycle, notebook execution, job runs, and MLflow model registry activity. ManySignal ingests Databricks audit logs from Azure Monitor or AWS S3 delivery targets, providing security visibility into your data engineering and machine learning workloads.
Databricks audit log ingestion from Azure Monitor or AWS S3
Workspace access and permission change monitoring
Cluster lifecycle event tracking (create, resize, terminate)
Data collected
- Workspace authentication and authorisation events
- Cluster create, resize, start, stop, and terminate events
- Notebook execution and export events
- Job and run lifecycle events with trigger actor
- Unity Catalog table, view, and schema access events
Actions supported
- Terminate a Databricks cluster via REST API on verdict
- Revoke workspace access via group membership removal
- Alert on notebook export outside business hours
- Trigger incident on Unity Catalog sensitive table access
Getting started
Set up in minutes
- 1
Configure audit log delivery
- 2
Grant ManySignal storage access
- 3
Add the connector in ManySignal
- 4
Configure Unity Catalog alerts
Databricks Integration: frequently asked questions
How frequently are Databricks audit logs delivered?
Databricks delivers audit logs to storage every 15 minutes. ManySignal polls for new log batches and ingests them as they arrive, providing approximately 15-30 minute event latency.
Does ManySignal support Databricks on all three cloud providers?
AWS and Azure are fully supported via S3 and Azure Storage delivery. GCP support is available via GCS delivery in preview.
Can ManySignal detect data exfiltration via Databricks?
Yes. ManySignal detects mass notebook export events, cluster-attached external storage access, and data transfers to unexpected destinations via Databricks cluster network connections.
Does ManySignal support Databricks Unity Catalog?
Yes. Unity Catalog audit events (table access, schema changes, privilege grants) are captured in Databricks audit logs and fully normalised by ManySignal.
How are MLflow model registry events handled?
MLflow events including model version creation, transition to production, and deletion are captured in audit logs. ManySignal alerts on unexpected model version promotions or access to production models from development accounts.
Can I detect when a Databricks notebook is exported or downloaded?
Yes. Notebook export events appear in audit logs. ManySignal alerts on notebook exports outside approved IP ranges or outside business hours.
Does ManySignal correlate Databricks events with cloud IAM?
Yes. Databricks instance profile (AWS) or managed identity (Azure) events are correlated with the underlying cloud IAM events for complete identity chain visibility.
What cluster event types are covered?
Create, edit, delete, start, restart, terminate, and resize events are captured, including the requesting user and cluster policy used.
Is Databricks SQL (SQL Analytics) covered?
Yes. SQL warehouse start/stop events and query audit events from Databricks SQL are included in the audit log stream.
Can this detect crypto mining abuse of Databricks clusters?
Yes. Unusually large cluster sizes, clusters running outside expected job windows, and high compute utilisation without corresponding data processing activity are detected as potential resource hijacking.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.