Gain visibility into employee interactions with GenAI apps by logging and analyzing
prompts across your network.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
|
And one of the following:
- AI Access Security license
- CASB-PA license
- CASB-X license
|
GenAI Prompt Analysis provides a comprehensive audit trail of all user-submitted
prompts to GenAI applications across your enforcement points. You can capture,
sanitize, and log prompts submitted through NGFW, Prisma® Access, and Prisma®
Browser channels to maintain visibility into how employees use GenAI tools in your
organization.
Prompt analysis addresses critical security and compliance requirements by enabling
you to monitor GenAI usage patterns, detect potential data exfiltration through
prompts, and maintain a forensic record of all GenAI interactions. This visibility
supports regulatory compliance with AI governance frameworks and organizational
acceptable use policies.
When you enable prompt logging, the system captures the original user prompt as
submitted to the GenAI application, free from surrounding HTTP/API request code,
headers, or other non-prompt data. The system de-duplicates prompts to avoid
capturing interim versions that GenAI applications save during composition.
Access to prompt data follows a role-based model:
- Admins and Viewers can access sanitized and truncated prompts (up to 250
characters) in the GenAI Conversation Log.
- Super Admins can view the raw, unsanitized original user prompt in the
detailed view for forensic auditing, after acknowledging a warning
notification. All Super Admin access to raw prompts is logged for internal
audit purposes.
You log prompts to Strata Logging Service, which provides searchable,
near-real-time access to prompt data. You can export prompt logs to CSV or forward
them to your SIEM for integration with your existing security monitoring
workflows.
Strata Cloud Manager
Enable, view, and export GenAI prompt logs in Strata Cloud Manager.
Enable GenAI Prompt Logging.
Select .
Enable
Enable Prompt Logging.
This toggle is only available if your tenant has Strata Logging Service configured. When enabled, the
system captures prompt history and logs prompts to Strata Logging Service.
Select the GenAI applications to enable prompt logging for.
Choose one or more of the following supported
applications:
- ChatGPT
- ChatGPT Enterprise
- Google Gemini
- Claude
- Perplexity
- Harvey
Prompts are only logged if DLP inspection is configured
for the application. Ensure file and non-file inspection
is enabled to capture both text prompts and file upload
prompts.
Click
Save.
You must select at least one application before you can
save.
Review the opt-in confirmation and click
Confirm.
The confirmation dialog notifies you that enabling this feature
saves prompts to Strata Logging Service. Click
Cancel to return to the settings
without enabling prompt logging.
View the GenAI Conversation Log.
Select the
AI Access Security dropdown in
the Log Viewer.
Select
GenAI Conversation Log.
The Prompt History table displays the following information for
each logged prompt:
- Timestamp—Date and time the prompt was
submitted.
- User Email—Email address of the user who submitted
the prompt.
- Application—Name of the GenAI application.
- Classification—Application classification
(Sanctioned, Unsanctioned, or Tolerated).
- Prompt—Truncated prompt content (first 250
characters).
- File—Filename if a file was attached to the prompt
(blank if no file was attached).
- Channel—Enforcement channel (NGFW, Prisma Access,
or Prisma Browser).
- Action—Policy action applied to the prompt.
- App Risk—Application risk level (High, Medium, or
Low).
- Vendor—GenAI application vendor.
(
Optional) Use the search and filter options to narrow
results by any field.
You can search all fields, including the full prompt content
(not just the truncated 250-character display). Use "if
contains" matching for long-string fields.
(
Optional) Click a prompt entry to open the details
tab.
The details tab shows the full prompt text and additional
metadata. If you have Super Admin privileges, you can view the
raw, unsanitized original prompt after acknowledging a warning
notification.
Export GenAI Conversation Log data.
Select the
AI Access Security dropdown in
the Log Viewer.
Select
GenAI Conversation Log.
(
Optional) Apply filters to narrow the data you want to
export.
Click
Export to CSV.
The CSV export includes the full prompt text for all entries,
not the truncated 250-character version displayed in the log
viewer. All metadata fields (Timestamp, User Email,
Application, Classification, File, Channel, Action, App Risk,
and Vendor) are included in the export.
To forward GenAI Conversation Log data to your SIEM in near-real-time,
configure log forwarding under . Log forwarding sends the full prompt text (not
truncated) to your configured SIEM destination.
Panorama
Enable, view, and export GenAI prompt logs in Panorama® management server.
Enable GenAI Prompt Logging.
Select .
Enable
Enable Prompt Logging.
This toggle is only available if Strata Logging Service
is configured for log forwarding. When enabled, the system
captures prompt history and logs prompts to Strata Logging Service.
Select the GenAI applications to enable prompt logging for.
Choose one or more of the following supported
applications:
- ChatGPT
- ChatGPT Enterprise
- Google Gemini
- Claude
- Perplexity
- Harvey
Prompts are only logged if DLP inspection is configured
for the application. Ensure file and non-file inspection
is enabled to capture both text prompts and file upload
prompts.
Click
OK.
You must select at least one application before you can save
the configuration.
Review the opt-in confirmation and click
Confirm.
The confirmation dialog notifies you that enabling this feature
saves prompts to Strata Logging Service.
Commit your changes.
Select and Commit, then select
to push the configuration to your managed
firewalls.
View GenAI prompt logs.
Select .
Filter the log view for GenAI prompt entries.
The log displays the following information for each logged
prompt:
- Timestamp—Date and time the prompt was
submitted.
- User Email—Email address of the user who submitted
the prompt.
- Application—Name of the GenAI application.
- Classification—Application classification
(Sanctioned, Unsanctioned, or Tolerated).
- Prompt—Truncated prompt content (first 250
characters).
- File—Filename if a file was attached to the prompt
(blank if no file was attached).
- Channel—Enforcement channel (NGFW, Prisma Access,
or Prisma Browser).
- Action—Policy action applied to the prompt.
- App Risk—Application risk level (High, Medium, or
Low).
- Vendor—GenAI application vendor.
(
Optional) Use the search and filter options to narrow
results by any field.
You can search all fields, including the full prompt content
(not just the truncated 250-character display).
(
Optional) Click a prompt entry to view the full
details.
The details view shows the full prompt text and additional
metadata. If you have Super Admin privileges, you can view the
raw, unsanitized original prompt after acknowledging a warning
notification.
Export GenAI prompt log data.
Select .
(
Optional) Apply filters to narrow the data you want to
export.
Click
Export to CSV.
The CSV export includes the full prompt text for all entries,
not the truncated 250-character version displayed in the log
viewer. All metadata fields are included in the export.
To forward GenAI prompt logs to your SIEM, configure log forwarding
under . Configure a syslog or HTTPS server profile to forward
Data Filtering logs that include GenAI prompt data to your SIEM
destination.