Strata Cloud Manager
Focus
Focus
AI Access Security

Strata Cloud Manager

Table of Contents


Strata Cloud Manager

Enable, view, and export GenAI prompt logs in Strata Cloud Manager.
  1. Enable GenAI Prompt Logging.
    1. Select Data Loss PreventionSettingsGenAI Prompt Analysis.
    2. Enable Enable Prompt Logging.
      This toggle is only available if your tenant has Strata Logging Service configured. When enabled, the system captures prompt history and logs prompts to Strata Logging Service.
    3. Select the GenAI applications to enable prompt logging for.
      Choose one or more of the following supported applications:
      • ChatGPT
      • ChatGPT Enterprise
      • Google Gemini
      • Claude
      • Perplexity
      • Harvey
      Prompts are only logged if DLP inspection is configured for the application. Ensure file and non-file inspection is enabled to capture both text prompts and file upload prompts.
    4. Click Save.
      You must select at least one application before you can save.
    5. Review the opt-in confirmation and click Confirm.
      The confirmation dialog notifies you that enabling this feature saves prompts to Strata Logging Service. Click Cancel to return to the settings without enabling prompt logging.
  2. View the GenAI Conversation Log.
    1. Select the AI Access Security dropdown in the Log Viewer.
    2. Select GenAI Conversation Log.
      The Prompt History table displays the following information for each logged prompt:
      • Timestamp—Date and time the prompt was submitted.
      • User Email—Email address of the user who submitted the prompt.
      • Application—Name of the GenAI application.
      • Classification—Application classification (Sanctioned, Unsanctioned, or Tolerated).
      • Prompt—Truncated prompt content (first 250 characters).
      • File—Filename if a file was attached to the prompt (blank if no file was attached).
      • Channel—Enforcement channel (NGFW, Prisma Access, or Prisma Browser).
      • Action—Policy action applied to the prompt.
      • App Risk—Application risk level (High, Medium, or Low).
      • Vendor—GenAI application vendor.
    3. (Optional) Use the search and filter options to narrow results by any field.
      You can search all fields, including the full prompt content (not just the truncated 250-character display). Use "if contains" matching for long-string fields.
    4. (Optional) Click a prompt entry to open the details tab.
      The details tab shows the full prompt text and additional metadata. If you have Super Admin privileges, you can view the raw, unsanitized original prompt after acknowledging a warning notification.
  3. Export GenAI Conversation Log data.
    1. Select the AI Access Security dropdown in the Log Viewer.
    2. Select GenAI Conversation Log.
    3. (Optional) Apply filters to narrow the data you want to export.
    4. Click Export to CSV.
      The CSV export includes the full prompt text for all entries, not the truncated 250-character version displayed in the log viewer. All metadata fields (Timestamp, User Email, Application, Classification, File, Channel, Action, App Risk, and Vendor) are included in the export.
    To forward GenAI Conversation Log data to your SIEM in near-real-time, configure log forwarding under SettingsLog Forwarding. Log forwarding sends the full prompt text (not truncated) to your configured SIEM destination.