Panorama
Focus
Focus
AI Access Security

Panorama

Table of Contents


Panorama

Enable, view, and export GenAI prompt logs in Panorama® management server.
  1. Enable GenAI Prompt Logging.
    1. Select DeviceSetupDLPGenAI Prompt Analysis.
    2. Enable Enable Prompt Logging.
      This toggle is only available if Strata Logging Service is configured for log forwarding. When enabled, the system captures prompt history and logs prompts to Strata Logging Service.
    3. Select the GenAI applications to enable prompt logging for.
      Choose one or more of the following supported applications:
      • ChatGPT
      • ChatGPT Enterprise
      • Google Gemini
      • Claude
      • Perplexity
      • Harvey
      Prompts are only logged if DLP inspection is configured for the application. Ensure file and non-file inspection is enabled to capture both text prompts and file upload prompts.
    4. Click OK.
      You must select at least one application before you can save the configuration.
    5. Review the opt-in confirmation and click Confirm.
      The confirmation dialog notifies you that enabling this feature saves prompts to Strata Logging Service.
    6. Commit your changes.
      Select CommitCommit to Panorama and Commit, then select CommitPush to Devices to push the configuration to your managed firewalls.
  2. View GenAI prompt logs.
    1. Select MonitorLogsData Filtering.
    2. Filter the log view for GenAI prompt entries.
      The log displays the following information for each logged prompt:
      • Timestamp—Date and time the prompt was submitted.
      • User Email—Email address of the user who submitted the prompt.
      • Application—Name of the GenAI application.
      • Classification—Application classification (Sanctioned, Unsanctioned, or Tolerated).
      • Prompt—Truncated prompt content (first 250 characters).
      • File—Filename if a file was attached to the prompt (blank if no file was attached).
      • Channel—Enforcement channel (NGFW, Prisma Access, or Prisma Browser).
      • Action—Policy action applied to the prompt.
      • App Risk—Application risk level (High, Medium, or Low).
      • Vendor—GenAI application vendor.
    3. (Optional) Use the search and filter options to narrow results by any field.
      You can search all fields, including the full prompt content (not just the truncated 250-character display).
    4. (Optional) Click a prompt entry to view the full details.
      The details view shows the full prompt text and additional metadata. If you have Super Admin privileges, you can view the raw, unsanitized original prompt after acknowledging a warning notification.
  3. Export GenAI prompt log data.
    1. Select MonitorLogsData Filtering.
    2. (Optional) Apply filters to narrow the data you want to export.
    3. Click Export to CSV.
      The CSV export includes the full prompt text for all entries, not the truncated 250-character version displayed in the log viewer. All metadata fields are included in the export.
    To forward GenAI prompt logs to your SIEM, configure log forwarding under DeviceLog Settings. Configure a syslog or HTTPS server profile to forward Data Filtering logs that include GenAI prompt data to your SIEM destination.