Log records
Apply advanced filtering by date range, endpoint, organization, username, or query text. Each record includes the query time, user information, endpoint name, processing duration, and security status (SAFE / UNSAFE).
Watermarking and traceability
The logging infrastructure uses watermarking on every query for full traceability. Open a query’s details to copy the Response Body in JSON format and examine exactly why specific security headers were triggered. In detailed analysis, a log shows precisely:- Which security policy was triggered,
- How threshold values were evaluated, and
- Which vulnerability a justified
UNSAFEdecision is based on.
Performance and cost metrics
Each log carries operational metrics:- Timing Details — the processing time spent on each security control, useful for performance optimization.
- Token Details — for queries processed through an LLM, the model used, the number of input/output tokens, and the approximate cost.
SIEM and observability integrations
The Integration Settings module streams security alerts, error logs, and compliance records from the AI Proxy into your existing SIEM, observability, and notification infrastructure. Supported targets include:SIEM
Splunk, IBM QRadar, Azure Sentinel, Wazuh, OSSIM, Elasticsearch
Observability
Datadog, New Relic, Grafana, OpenTelemetry
Notifications
Slack, Webhooks
Related
Dashboard & Monitoring
The aggregate view over these records.
Compliance
Use these logs as audit evidence.
Shadow AI
A dedicated log stream for unsanctioned AI usage.
Guard Gateway API
The response fields that appear in logs.