GenAI Prompt Logging
Focus
Focus
AI Access Security

GenAI Prompt Logging

Table of Contents

GenAI Prompt Logging

Gain visibility into employee interactions with GenAI apps by logging and analyzing prompts across your network.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Strata Logging Service license
And one of the following:
  • AI Access Security license
  • CASB-PA license
  • CASB-X license
GenAI Prompt Logging provides a comprehensive audit trail of all user-submitted prompts to GenAI applications across your enforcement points. You can capture, sanitize, and log prompts submitted through NGFW, Prisma Access, and Prisma Browser channels to maintain visibility into how employees use GenAI tools in your organization.
Prompt logging addresses critical security and compliance requirements by enabling you to monitor GenAI usage patterns, detect potential data exfiltration through prompts, and maintain a forensic record of all GenAI interactions. This visibility supports regulatory compliance with AI governance frameworks and organizational acceptable use policies.
When you enable prompt logging, the system captures the original user prompt as submitted to the GenAI application, free from surrounding HTTP/API request code, headers, or other non-prompt data. The system de-duplicates prompts to avoid capturing interim versions that GenAI applications save during composition.
Access to prompt data follows a role-based model:
  • Admins and Viewers can access sanitized and truncated prompts (up to 250 characters) in the GenAI Conversation Log.
  • Super Admins can view the raw, unsanitized original user prompt in the detailed view for forensic auditing, after acknowledging a warning notification. All Super Admin access to raw prompts is logged for internal audit purposes.
You log prompts to Strata Logging Service, which provides searchable, near-real-time access to prompt data. You can export prompt logs to CSV or forward them to your SIEM for integration with your existing security monitoring workflows.
Enable, view, and export GenAI prompt logs in Strata Cloud Manager
  1. Enable GenAI Prompt Logging.
    1. Log in to Strata Cloud Manager.
    2. Select ConfigurationData Loss PreventionSettingsGenAI Prompt Analysis.
    3. Enable the toggle at the GenAI Prompt Analysis pane.
      This toggle is only available if your tenant has Strata Logging Service configured. When enabled, the system captures prompt history and logs prompts to Strata Logging Service.
    4. Select the GenAI applications for which you want to enable prompt logging.
      • ChatGPT
      • Claude
      • Google Gemini
      • Perplexity
      Prompts are only logged if Enterprise DLP inspection is configured for the application. Ensure file and non-file inspection is enabled to capture both text prompts and file upload prompts.
    5. Click Save.
      You must select at least one application before you can save.
  2. View the GenAI Conversation Log.
    1. Select the Strata Cloud ManagerLog ViewerAI AccessAI Conversation Log
    2. To open a specific log record, click on that log's detail icon (first column on the left).
      The log details page consists of two tabs. The general traffic details which contains 32 specific parameters including details like who performed the action, what the action was, when it happened, and other associated details.
    3. (Optional) Use the search and filter options to narrow results by any field.
      You can search all fields, including the full prompt content (not just the truncated 250-character display). Use "if contains" matching for long-string fields.
  3. Export GenAI Conversation Log data.
    1. Select the AI Access dropdown in the Log Viewer.
    2. Select AI Conversation Log.
    3. (Optional) Apply filters to narrow the data you want to export.
    4. Click Export.
      The CSV export includes the full prompt text for all entries, not the truncated 250-character version displayed in the log viewer. All metadata fields ( for example, Timestamp, User ID, App Name, App ID) are included in the export.
    To forward AI Conversation Log data to your SIEM in near-real-time, configure log forwarding under SettingsLog Forwarding. Log forwarding sends the full prompt text (not truncated) to your configured SIEM destination.