AI Conversation Log
Focus
Focus
Strata Logging Service

AI Conversation Log

Table of Contents

AI Conversation Log

AI Access logs record traffic between users and generative AI (GenAI) applications that traverse your Palo Alto Networks security infrastructure.
See the following for information related to supported log formats:
AI CONVERSATION LOG Field
(Display Name)
Description
action.​value
(ACTION)
Action taken on the prompt. Values are Allow, Block, Alert. Phase 0 is always Allow.
CEF field name: PanOSAction
EMAIL field name: Action
HTTPS field name: Action
LEEF field name: Action
app_classification.​value
(APP CLASSIFICATION)
Application sanctioning classification as configured by the tenant admin. Values are Sanctioned, Unsanctioned, Tolerated.
CEF field name: PanOSAppClassification
EMAIL field name: AppClassification
HTTPS field name: AppClassification
LEEF field name: AppClassification
app_id
(APP ID)
FileManager application identifier for the GenAI application.
CEF field name: PanOSAppID
EMAIL field name: AppID
HTTPS field name: AppID
LEEF field name: AppID
app_name
(APP NAME)
Name of the GenAI application (e.g., openai-chatgpt, claude-post, google-gemini, perplexity-ai-base).
CEF field name: PanOSAppName
EMAIL field name: AppName
HTTPS field name: AppName
LEEF field name: AppName
channel.​value
(CHANNEL)
Network delivery channel through which the prompt was intercepted. Values are ngfw, prisma_access, prisma_access_browser, saas_api.
CEF field name: PanOSChannel
EMAIL field name: Channel
HTTPS field name: Channel
LEEF field name: Channel
content
(CONTENT)
Truncated prompt content text, first 1000 characters of the extracted user content.
CEF field name: PanOSContent
EMAIL field name: Content
HTTPS field name: Content
LEEF field name: Content
content_extracted
(CONTENT EXTRACTED)
URI reference to the full extracted prompt content text stored in object storage (S3). Used for retrieving the complete untruncated prompt in the detail view.
CEF field name: PanOSContentExtracted
EMAIL field name: ContentExtracted
HTTPS field name: ContentExtracted
LEEF field name: ContentExtracted
conversation_id
(CONVERSATION ID)
Conversation or chat session identifier from the GenAI application, used to group related prompts in a single conversation thread.
CEF field name: PanOSConversationID
EMAIL field name: ConversationID
HTTPS field name: ConversationID
LEEF field name: ConversationID
customer_id
(CORTEX DATA LAKE TENANT ID)
The ID that uniquely identifies the Cortex Data Lake instance which received this log record.
EMAIL field name: CortexDataLakeTenantId
HTTPS field name: CortexDataLakeTenantId
LEEF field name: CortexDataLakeTenantID
data_size
(DATA SIZE)
Size of the intercepted data payload in bytes.
CEF field name: PanOSDataSize
EMAIL field name: DataSize
HTTPS field name: DataSize
LEEF field name: DataSize
dlp_data_profiles
(DLP DATA PROFILES)
List of DLP data profile names that matched against the prompt content.
CEF field name: PanOSDLPDataProfiles
EMAIL field name: DLPDataProfiles
HTTPS field name: DLPDataProfiles
LEEF field name: DLPDataProfiles
dlp_incident_id
(DLP INCIDENT ID)
DLP incident identifier if the prompt triggered a DLP detection match.
CEF field name: PanOSDLPIncidentID
EMAIL field name: DLPIncidentID
HTTPS field name: DLPIncidentID
LEEF field name: DLPIncidentID
dlp_tenant_id
(DLP TENANT ID)
DLP tenant identifier for the tenant that owns this scan.
CEF field name: PanOSDLPTenantID
EMAIL field name: DLPTenantID
HTTPS field name: DLPTenantID
LEEF field name: DLPTenantID
file_name
(FILE NAME)
Name of the file attached to the GenAI prompt, if any.
CEF field name: PanOSFileName
EMAIL field name: FileName
HTTPS field name: FileName
LEEF field name: FileName
file_type
(FILE TYPE)
Type of the file attached to the GenAI prompt (e.g., txt, pdf, png).
CEF field name: PanOSFileType
EMAIL field name: FileType
HTTPS field name: FileType
LEEF field name: FileType
is_file_based
(IS FILE BASED)
Whether the GenAI request included a file upload.
CEF field name: PanOSIsFileBased
EMAIL field name: IsFileBased
HTTPS field name: IsFileBased
LEEF field name: IsFileBased
is_prompt
(IS PROMPT)
Whether the intercepted content is a user prompt sent to the GenAI application.
CEF field name: PanOSIsPrompt
EMAIL field name: IsPrompt
HTTPS field name: IsPrompt
LEEF field name: IsPrompt
is_response
(IS RESPONSE)
Whether the intercepted content is a response received from the GenAI application.
CEF field name: PanOSIsResponse
EMAIL field name: IsResponse
HTTPS field name: IsResponse
LEEF field name: IsResponse
log_source
(LOG SOURCE)
Identifies the origin of the data - the system that produced the data.
CEF field name: PanOSLogSource
EMAIL field name: LogSource
HTTPS field name: LogSource
LEEF field name: LogSource
log_source_group_id
(LOG SOURCE GROUP ID)
ID that uniquely identifies the logSourceGroupId of the log. That is, the log_source_id of the group.
CEF field name: logSourceGroupID
EMAIL field name: LogSourceGroupID
HTTPS field name: LogSourceGroupID
LEEF field name: LogSourceGroupID
log_source_id
(DEVICE SN)
ID that uniquely identifies the source of the log - serial number of the firewall that generated the log.
CEF field name: deviceExternalID
EMAIL field name: DeviceSN
HTTPS field name: DeviceSN
LEEF field name: DeviceSN
log_source_name
(DEVICE NAME)
Name of the source of the log - hostname of the firewall that logged the network traffic.
CEF field name: dvchost
EMAIL field name: DeviceName
HTTPS field name: DeviceName
LEEF field name: DeviceName
log_source_tz_offset
(LOG SOURCE TIMEZONE OFFSET)
Time Zone offset from GMT of the source of the log.
EMAIL field name: LogSourceTimeZoneOffset
HTTPS field name: LogSourceTimeZoneOffset
LEEF field name: LogSourceTimeZoneOffset
log_time
(TIME RECEIVED)
Time the log was received in Cortex Data Lake. This is populated by the platform.
CEF field name: rt
EMAIL field name: TimeReceived
HTTPS field name: TimeReceived
LEEF field name: TimeReceived
log_type.​value
(LOG TYPE)
Identifies the log type.
CEF field name: DeviceEventClassID
EMAIL field name: LogType
HTTPS field name: LogType
LEEF field name: cat
platform_type
(PLATFORM TYPE)
Identifies the platform that generated the log.
CEF field name: PanOSPlatformType
EMAIL field name: PlatformType
HTTPS field name: PlatformType
LEEF field name: PlatformType
prompt_intents
(PROMPT INTENTS)
List of detected intents for the prompt. A prompt can match multiple prompt intents.
CEF field name: PanOSPromptIntents
EMAIL field name: PromptIntents
HTTPS field name: PromptIntents
LEEF field name: PromptIntents
prompt_topics
(PROMPT TOPICS)
List of detected topic categories for the prompt. A prompt can match multiple topics.
CEF field name: PanOSPromptTopics
EMAIL field name: PromptTopics
HTTPS field name: PromptTopics
LEEF field name: PromptTopics
report_id
(REPORT ID)
Unique DLP scan report identifier assigned during ingestion.
CEF field name: PanOSReportID
EMAIL field name: ReportID
HTTPS field name: ReportID
LEEF field name: ReportID
scan_region
(SCAN REGION)
Region where the DLP scan was processed (e.g., us-east4, europe-west1).
CEF field name: PanOSScanRegion
EMAIL field name: ScanRegion
HTTPS field name: ScanRegion
LEEF field name: ScanRegion
session_key
(SESSION KEY)
Session key from the network session baggage, used for correlating multiple requests in the same user session.
CEF field name: PanOSSessionKey
EMAIL field name: SessionKey
HTTPS field name: SessionKey
LEEF field name: SessionKey
snippets
(SNIPPETS)
DLP scan snippet details for matched content in the prompt.
CEF field name: PanOSSnippets
EMAIL field name: Snippets
HTTPS field name: Snippets
LEEF field name: Snippets
source.​value
(SOURCE)
Product source that captured the prompt. Values are Firewall, Prisma AIRS, AI Access.
CEF field name: PanOSSource
EMAIL field name: Source
HTTPS field name: Source
LEEF field name: Source
sub_type.​value
(SUB TYPE)
Identifies the log subtype.
CEF field name: Name
EMAIL field name: SubType
HTTPS field name: SubType
LEEF field name: SubType
time_generated
(TIME GENERATED)
Time the log was generated on the data plane in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
CEF field name: start
EMAIL field name: TimeGenerated
HTTPS field name: TimeGenerated
LEEF field name: devTime
time_generated_high_res
(TIME GENERATED HIGH RESOLUTION)
Time the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
EMAIL field name: TimeGeneratedHighResolution
HTTPS field name: TimeGeneratedHighResolution
tsg_id
(TSG ID)
The ID that uniquely identifiers a Tenant Sevice Group (TSG) that this log record should be associated with.
CEF field name: PanOSTSGID
EMAIL field name: TSGID
HTTPS field name: TSGID
LEEF field name: TSGID
url
(URL)
URL of the GenAI application API endpoint that received the prompt.
CEF field name: PanOSURL
EMAIL field name: URL
HTTPS field name: URL
LEEF field name: URL
user_id
(USER ID)
Email address of the user who submitted the prompt to the GenAI application.
CEF field name: PanOSUserID
EMAIL field name: UserID
HTTPS field name: UserID
LEEF field name: UserID
vendor_name
(VENDOR NAME)
Identifies the vendor that produced the data.
CEF field name: Device Vendor
EMAIL field name: VendorName
HTTPS field name: VendorName
LEEF field name: Vendor
verdict.​value
(DLP VERDICT)
DLP scan verdict indicating whether any detection matched. Values are MATCHED, NOT_MATCHED.
CEF field name: PanOSDLPVerdict
EMAIL field name: DLPVerdict
HTTPS field name: DLPVerdict
LEEF field name: DLPVerdict