Vector
Vector
Edition: Enterprise only
The Vector integration scans logs forwarded from Vector via the HTTP sink, enabling real-time secret detection on log streams.
Configuration
The Vector integration is configured via a local configuration file. Web configuration in TruffleHog is not available for this source.
Setup requires configuration in two places: a TruffleHog source that listens for incoming logs, and a Vector HTTP sink that forwards logs to it.
Local configuration
TruffleHog source configuration
Vector HTTP sink configuration
If present in the incoming log payload, the following fields are surfaced as metadata in the TruffleHog dashboard: host, hostname, timestamp, source_type. See the Vector HTTP sink documentation for the full set of sink options.
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
listenAddress | string | Yes | The address and port the webhook listener binds to (e.g., :8080). |
header.key | string | Yes | The HTTP header used for authentication. Typically Authorization. |
header.value | string | Yes | The expected header value. For bearer tokens, prefix the secret with Bearer . |
vector.locator_field | string | No | A jq-style path to a field in the incoming log used to build a link back to your logging system. |
vector.link_format | string | No | A URL template containing {locator}, replaced with the value extracted via locator_field. |
Capabilities
Feature | Supported |
|---|---|
Real-time scanning | ✅ |
Scan log streams | ✅ |
Scan base64-encoded data | ✅ |
Notes
- TruffleHog scans logs forwarded by Vector but does not block log delivery when credentials are detected. Detection is observe-only.