GenAI Prompt Analysis
Focus
Focus
AI Access Security

GenAI Prompt Analysis

Table of Contents

GenAI Prompt Analysis

Gain visibility into employee interactions with GenAI apps by logging and analyzing prompts across your network.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Strata Logging Service license
And one of the following:
  • AI Access Security license
  • CASB-PA license
  • CASB-X license
GenAI Prompt Analysis provides a comprehensive audit trail of all user-submitted prompts to GenAI applications across your enforcement points. You can capture, sanitize, and log prompts submitted through NGFW, Prisma® Access, and Prisma® Browser channels to maintain visibility into how employees use GenAI tools in your organization.
Prompt analysis addresses critical security and compliance requirements by enabling you to monitor GenAI usage patterns, detect potential data exfiltration through prompts, and maintain a forensic record of all GenAI interactions. This visibility supports regulatory compliance with AI governance frameworks and organizational acceptable use policies.
When you enable prompt logging, the system captures the original user prompt as submitted to the GenAI application, free from surrounding HTTP/API request code, headers, or other non-prompt data. The system de-duplicates prompts to avoid capturing interim versions that GenAI applications save during composition.
Access to prompt data follows a role-based model:
  • Admins and Viewers can access sanitized and truncated prompts (up to 250 characters) in the GenAI Conversation Log.
  • Super Admins can view the raw, unsanitized original user prompt in the detailed view for forensic auditing, after acknowledging a warning notification. All Super Admin access to raw prompts is logged for internal audit purposes.
You log prompts to Strata Logging Service, which provides searchable, near-real-time access to prompt data. You can export prompt logs to CSV or forward them to your SIEM for integration with your existing security monitoring workflows.

Strata Cloud Manager

Enable, view, and export GenAI prompt logs in Strata Cloud Manager.
  1. Enable GenAI Prompt Logging.
    1. Select Data Loss PreventionSettingsGenAI Prompt Analysis.
    2. Enable Enable Prompt Logging.
      This toggle is only available if your tenant has Strata Logging Service configured. When enabled, the system captures prompt history and logs prompts to Strata Logging Service.
    3. Select the GenAI applications to enable prompt logging for.
      Choose one or more of the following supported applications:
      • ChatGPT
      • ChatGPT Enterprise
      • Google Gemini
      • Claude
      • Perplexity
      • Harvey
      Prompts are only logged if DLP inspection is configured for the application. Ensure file and non-file inspection is enabled to capture both text prompts and file upload prompts.
    4. Click Save.
      You must select at least one application before you can save.
    5. Review the opt-in confirmation and click Confirm.
      The confirmation dialog notifies you that enabling this feature saves prompts to Strata Logging Service. Click Cancel to return to the settings without enabling prompt logging.
  2. View the GenAI Conversation Log.
    1. Select the AI Access Security dropdown in the Log Viewer.
    2. Select GenAI Conversation Log.
      The Prompt History table displays the following information for each logged prompt:
      • Timestamp—Date and time the prompt was submitted.
      • User Email—Email address of the user who submitted the prompt.
      • Application—Name of the GenAI application.
      • Classification—Application classification (Sanctioned, Unsanctioned, or Tolerated).
      • Prompt—Truncated prompt content (first 250 characters).
      • File—Filename if a file was attached to the prompt (blank if no file was attached).
      • Channel—Enforcement channel (NGFW, Prisma Access, or Prisma Browser).
      • Action—Policy action applied to the prompt.
      • App Risk—Application risk level (High, Medium, or Low).
      • Vendor—GenAI application vendor.
    3. (Optional) Use the search and filter options to narrow results by any field.
      You can search all fields, including the full prompt content (not just the truncated 250-character display). Use "if contains" matching for long-string fields.
    4. (Optional) Click a prompt entry to open the details tab.
      The details tab shows the full prompt text and additional metadata. If you have Super Admin privileges, you can view the raw, unsanitized original prompt after acknowledging a warning notification.
  3. Export GenAI Conversation Log data.
    1. Select the AI Access Security dropdown in the Log Viewer.
    2. Select GenAI Conversation Log.
    3. (Optional) Apply filters to narrow the data you want to export.
    4. Click Export to CSV.
      The CSV export includes the full prompt text for all entries, not the truncated 250-character version displayed in the log viewer. All metadata fields (Timestamp, User Email, Application, Classification, File, Channel, Action, App Risk, and Vendor) are included in the export.
    To forward GenAI Conversation Log data to your SIEM in near-real-time, configure log forwarding under SettingsLog Forwarding. Log forwarding sends the full prompt text (not truncated) to your configured SIEM destination.

Panorama

Enable, view, and export GenAI prompt logs in Panorama® management server.
  1. Enable GenAI Prompt Logging.
    1. Select DeviceSetupDLPGenAI Prompt Analysis.
    2. Enable Enable Prompt Logging.
      This toggle is only available if Strata Logging Service is configured for log forwarding. When enabled, the system captures prompt history and logs prompts to Strata Logging Service.
    3. Select the GenAI applications to enable prompt logging for.
      Choose one or more of the following supported applications:
      • ChatGPT
      • ChatGPT Enterprise
      • Google Gemini
      • Claude
      • Perplexity
      • Harvey
      Prompts are only logged if DLP inspection is configured for the application. Ensure file and non-file inspection is enabled to capture both text prompts and file upload prompts.
    4. Click OK.
      You must select at least one application before you can save the configuration.
    5. Review the opt-in confirmation and click Confirm.
      The confirmation dialog notifies you that enabling this feature saves prompts to Strata Logging Service.
    6. Commit your changes.
      Select CommitCommit to Panorama and Commit, then select CommitPush to Devices to push the configuration to your managed firewalls.
  2. View GenAI prompt logs.
    1. Select MonitorLogsData Filtering.
    2. Filter the log view for GenAI prompt entries.
      The log displays the following information for each logged prompt:
      • Timestamp—Date and time the prompt was submitted.
      • User Email—Email address of the user who submitted the prompt.
      • Application—Name of the GenAI application.
      • Classification—Application classification (Sanctioned, Unsanctioned, or Tolerated).
      • Prompt—Truncated prompt content (first 250 characters).
      • File—Filename if a file was attached to the prompt (blank if no file was attached).
      • Channel—Enforcement channel (NGFW, Prisma Access, or Prisma Browser).
      • Action—Policy action applied to the prompt.
      • App Risk—Application risk level (High, Medium, or Low).
      • Vendor—GenAI application vendor.
    3. (Optional) Use the search and filter options to narrow results by any field.
      You can search all fields, including the full prompt content (not just the truncated 250-character display).
    4. (Optional) Click a prompt entry to view the full details.
      The details view shows the full prompt text and additional metadata. If you have Super Admin privileges, you can view the raw, unsanitized original prompt after acknowledging a warning notification.
  3. Export GenAI prompt log data.
    1. Select MonitorLogsData Filtering.
    2. (Optional) Apply filters to narrow the data you want to export.
    3. Click Export to CSV.
      The CSV export includes the full prompt text for all entries, not the truncated 250-character version displayed in the log viewer. All metadata fields are included in the export.
    To forward GenAI prompt logs to your SIEM, configure log forwarding under DeviceLog Settings. Configure a syslog or HTTPS server profile to forward Data Filtering logs that include GenAI prompt data to your SIEM destination.