> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beyondguard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Logs, Watermarking, and Telemetry

> Every query, decision, and interaction is logged with watermarking for full traceability — including timing, token, and cost metrics — and streamed to your SIEM.

The **Logs** module is the central record of everything happening in BeyondGuard. Every query, response, security evaluation, and system interaction — across the AI Proxy and Beyond Chat — is logged in detail and made queryable.

<iframe src="https://www.youtube.com/embed/Mz55agpf3p8" title="YouTube video player" frameborder="0" className="w-full aspect-video rounded-xl" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen />

## Log records

Apply advanced filtering by **date range, endpoint, organization, username, or query text**. Each record includes the query time, user information, endpoint name, processing duration, and security status (`SAFE` / `UNSAFE`).

## Watermarking and traceability

The logging infrastructure uses **watermarking** on every query for full traceability. Open a query's details to copy the **Response Body** in JSON format and examine exactly why specific security headers were triggered.

In detailed analysis, a log shows precisely:

* Which security policy was triggered,
* How threshold values were evaluated, and
* Which vulnerability a justified `UNSAFE` decision is based on.

A **Log ID** on each record (and on error responses) lets support teams match a user complaint to the exact log entry within seconds.

## Performance and cost metrics

Each log carries operational metrics:

* **Timing Details** — the processing time spent on each security control, useful for performance optimization.
* **Token Details** — for queries processed through an LLM, the model used, the number of input/output tokens, and the approximate cost.

Together these make the Logs module a comprehensive auditing screen — detailed enough for security teams and complete enough for administrators to monitor system behavior end to end.

## SIEM and observability integrations

The **Integration Settings** module streams security alerts, error logs, and compliance records from the AI Proxy into your existing SIEM, observability, and notification infrastructure. Supported targets include:

<CardGroup cols={3}>
  <Card title="SIEM">
    Splunk, IBM QRadar, Azure Sentinel, Wazuh, OSSIM, Elasticsearch
  </Card>

  <Card title="Observability">
    Datadog, New Relic, Grafana, OpenTelemetry
  </Card>

  <Card title="Notifications">
    Slack, Webhooks
  </Card>
</CardGroup>

Through these integrations, every event can be monitored in real time, reported in line with SOC processes, and automated to speed up incident response — delivering the visibility and traceability enterprise audits require.

## Related

<CardGroup cols={2}>
  <Card title="Dashboard & Monitoring" icon="chart-line" href="/platform/dashboard">
    The aggregate view over these records.
  </Card>

  <Card title="Compliance" icon="scale-balanced" href="/guides/compliance">
    Use these logs as audit evidence.
  </Card>

  <Card title="Shadow AI" icon="eye" href="/platform/shadow-ai">
    A dedicated log stream for unsanctioned AI usage.
  </Card>

  <Card title="Guard Gateway API" icon="code" href="/api-reference/guard-gateway">
    The response fields that appear in logs.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.