AI Runtime Security API
Focus
Focus
Strata Logging Service

AI Runtime Security API

Table of Contents

AI Runtime Security API

The AI Security logs contain information to help you monitor and investigate threats found in your AI network traffic with AI Runtime Security API.
See the following for information related to supported log formats:
AI RUNTIME SECURITY API Field
(Display Name)
Description
action
(ACTION)
Identifies the action that the API conveyed back to caller. Action can be allow/block/alert in the logs.
CEF field name: PanOSAction
EMAIL field name: Action
HTTPS field name: Action
LEEF field name: Action
agent_framework
(AGENT FRAMEWORK)
Agent builder framework used to build Agents such as AWS_Agent_Builder, Microsoft_copilot_studio and others.
CEF field name: PanOSAgentFramework
EMAIL field name: AgentFramework
HTTPS field name: AgentFramework
LEEF field name: AgentFramework
agent_id
(AGENT ID)
ID of the AI Agent.
CEF field name: PanOSAgentID
EMAIL field name: AgentID
HTTPS field name: AgentID
LEEF field name: AgentID
ai_app_cloud_provider
(AI APP CLOUD PROVIDER)
Cloud provider for the AI Application. Will be configured in SCM and AI Runtime API Cloud will send to SLS.
CEF field name: PanOSAIAppCloudProvider
EMAIL field name: AIAppCloudProvider
HTTPS field name: AIAppCloudProvider
LEEF field name: AIAppCloudProvider
ai_app_csp_name
(AI APP CSP NAME)
Name of the cloud provider where the app is hosted.
CEF field name: PanOSAIAppCSPName
EMAIL field name: AIAppCSPName
HTTPS field name: AIAppCSPName
LEEF field name: AIAppCSPName
ai_app_environment
(AI APP ENVIRONMENT)
Customer Environment where AI Application is deployed. Will be configured in SCM and AI Runtime API Cloud will send to the SLS.
CEF field name: PanOSAIAppEnvironment
EMAIL field name: AIAppEnvironment
HTTPS field name: AIAppEnvironment
LEEF field name: AIAppEnvironment
ai_app_user_domain
(AI APP USER DOMAIN)
Domain name of the AI application user.
CEF field name: PanOSAIAppUserDomain
EMAIL field name: AIAppUserDomain
HTTPS field name: AIAppUserDomain
LEEF field name: AIAppUserDomain
ai_app_user_group_id
(AI APP USER GROUP ID)
Group ID of the AI application user.
CEF field name: PanOSAIAppUserGroupID
EMAIL field name: AIAppUserGroupID
HTTPS field name: AIAppUserGroupID
LEEF field name: AIAppUserGroupID
ai_app_user_group_name
(AI APP USER GROUP NAME)
Group name of the AI application user.
CEF field name: PanOSAIAppUserGroupName
EMAIL field name: AIAppUserGroupName
HTTPS field name: AIAppUserGroupName
LEEF field name: AIAppUserGroupName
ai_app_user_name
(AI APPLICATION USER NAME)
End User using AI Application. Will be configured in SCM and AI Runtime API Cloud will send to the SLS.
EMAIL field name: AIApplicationUserName
HTTPS field name: AIApplicationUserName
LEEF field name: AIApplicationUserName
ai_application_name
(AI APPLICATION NAME)
Vendor of the API producing the data. Will be configured in SCM and AI Runtime API Cloud will send to the SLS.
CEF field name: PanOSAIApplicationName
EMAIL field name: AIApplicationName
HTTPS field name: AIApplicationName
LEEF field name: AIApplicationName
ai_incident_report_id
(AI INCIDENT REPORT ID)
AI Runtime API report id.
CEF field name: PanOSAIIncidentReportID
EMAIL field name: AIIncidentReportID
HTTPS field name: AIIncidentReportID
LEEF field name: AIIncidentReportID
ai_incident_subtype
(AI INCIDENT SUBTYPE)
URL Security, Prompt Injection, Data Rule, .
CEF field name: PanOSAIIncidentSubtype
EMAIL field name: AIIncidentSubtype
HTTPS field name: AIIncidentSubtype
LEEF field name: AIIncidentSubtype
ai_incident_type
(AI INCIDENT TYPE)
AI Application Protection, AI Model Protection, AI Data Protection, Latency Limit, Model Denied.
CEF field name: PanOSAIIncidentType
EMAIL field name: AIIncidentType
HTTPS field name: AIIncidentType
LEEF field name: AIIncidentType
ai_model_name
(AI MODEL NAME)
e.g. Gemini 1.5 Pro, GPT-4. Will be generated in AI Runtime API Cloud and sent to the SLS.
CEF field name: PanOSAIModelName
EMAIL field name: AIModelName
HTTPS field name: AIModelName
LEEF field name: AIModelName
ai_security_policy_id
(AI SECURITY POLICY ID)
ID of AI Security Policy.
CEF field name: PanOSAISecurityPolicyID
EMAIL field name: AISecurityPolicyID
HTTPS field name: AISecurityPolicyID
LEEF field name: AISecurityPolicyID
ai_security_policy_name
(AI SECURITY POLICY NAME)
Name of AI Security Policy.
EMAIL field name: AISecurityPolicyName
HTTPS field name: AISecurityPolicyName
LEEF field name: AISecurityPolicyName
ai_security_profile_id
(AI SECURITY PROFILE ID)
ID of AI Security Profile.
CEF field name: PanOSAISecurityProfileID
EMAIL field name: AISecurityProfileID
HTTPS field name: AISecurityProfileID
LEEF field name: AISecurityProfileID
ai_security_profile_name
(AI SECURITY PROFILE NAME)
Name of AI Security Profile.
EMAIL field name: AISecurityProfileName
HTTPS field name: AISecurityProfileName
LEEF field name: AISecurityProfileName
ai_subtype_details
(AI SUBTYPE DETAILS)
If AI Data Protection - Data Filtering was triggered, this field would provide the name of the specific DLP rule that was triggered. If AI Application Protection - URL Security was triggered, this field would provide the specific URL category that was triggered.
CEF field name: PanOSAISubtypeDetails
EMAIL field name: AISubtypeDetails
HTTPS field name: AISubtypeDetails
LEEF field name: AISubtypeDetails
api_key_name
(API KEY NAME)
Identifies the API Key name used for Scan Request. Sent from AI Runtime API Cloud.
CEF field name: PanOSAPIKeyName
EMAIL field name: APIKeyName
HTTPS field name: APIKeyName
LEEF field name: APIKeyName
api_region
(API REGION)
Indicates the region where api is invoked from.
CEF field name: PanOSAPIRegion
EMAIL field name: APIRegion
HTTPS field name: APIRegion
LEEF field name: APIRegion
app_id
(APP ID)
App Id.
CEF field name: PanOSAppId
EMAIL field name: AppId
HTTPS field name: AppId
LEEF field name: AppId
asset_id
(ASSET ID)
Unique identifier for an asset. Agent is an asset.
CEF field name: PanOSAssetID
EMAIL field name: AssetID
HTTPS field name: AssetID
LEEF field name: AssetID
completed_ts
(COMPLETED TS)
Time that the scan was completed by AI Runtime API.
CEF field name: PanOSCompletedTS
EMAIL field name: CompletedTS
HTTPS field name: CompletedTS
LEEF field name: CompletedTS
content_masked
(CONTENT MASKED)
Indicates whether we masked inline content when customer requested DLP scan.
CEF field name: PanOSContentMasked
EMAIL field name: ContentMasked
HTTPS field name: ContentMasked
LEEF field name: ContentMasked
content_type
(CONTENT TYPE)
Content type.
CEF field name: PanOSContentType
EMAIL field name: ContentType
HTTPS field name: ContentType
LEEF field name: ContentType
csp_id
(CSP ID)
The ID that uniquely identifiers a Customer Support Product (CSP) that this log record should be associated with.
CEF field name: PanOSCSPID
EMAIL field name: CSPID
HTTPS field name: CSPID
LEEF field name: CSPID
customer_id
(CORTEX DATA LAKE TENANT ID)
The ID that uniquely identifies the Cortex Data Lake instance which received this log record.
EMAIL field name: CortexDataLakeTenantId
HTTPS field name: CortexDataLakeTenantId
LEEF field name: s
detection_service_flags
(DETECTION SERVICE FLAGS)
Indicates the detection services that were requested for this scan.
EMAIL field name: DetectionServiceFlags
HTTPS field name: DetectionServiceFlags
LEEF field name: DetectionServiceFlags
final_prompt_action
(FINAL PROMPT ACTION)
Indicates the final prompt action for a given scan.
CEF field name: PanOSFinalPromptAction
EMAIL field name: FinalPromptAction
HTTPS field name: FinalPromptAction
LEEF field name: FinalPromptAction
final_prompt_verdict
(FINAL PROMPT VERDICT)
Indicates the final prompt verdict for a given scan.
CEF field name: PanOSFinalPromptVerdict
EMAIL field name: FinalPromptVerdict
HTTPS field name: FinalPromptVerdict
LEEF field name: FinalPromptVerdict
final_response_action
(FINAL RESPONSE ACTION)
Indicates the final response action for a given scan.
CEF field name: PanOSFinalResponseAction
EMAIL field name: FinalResponseAction
HTTPS field name: FinalResponseAction
LEEF field name: FinalResponseAction
final_response_verdict
(FINAL RESPONSE VERDICT)
Indicates the final response verdict for a given scan.
EMAIL field name: FinalResponseVerdict
HTTPS field name: FinalResponseVerdict
LEEF field name: FinalResponseVerdict
is_code
(IS CODE)
Indicates if the request contains code.
CEF field name: PanOSIsCode
EMAIL field name: IsCode
HTTPS field name: IsCode
LEEF field name: IsCode
is_prompt
(IS PROMPT)
Indicates if the request includes a prompt.
CEF field name: PanOSIsPrompt
EMAIL field name: IsPrompt
HTTPS field name: IsPrompt
LEEF field name: IsPrompt
is_prompt_agent_requested
(IS PROMPT AGENT REQUESTED)
Indicates whether prompt was subjected to agentic security scan.
EMAIL field name: IsPromptAgentRequested
HTTPS field name: IsPromptAgentRequested
LEEF field name: IsPromptAgentRequested
is_prompt_dlp_requested
(IS PROMPT DLP REQUESTED)
Indicates whether DLP was requested for the prompt in the scan.
EMAIL field name: IsPromptDLPRequested
HTTPS field name: IsPromptDLPRequested
LEEF field name: IsPromptDLPRequested
is_prompt_mc_requested
(IS PROMPT MC REQUESTED)
Indicates whether Malicious Code was requested for the prompt in the scan.
CEF field name: PanOSIsPromptMCRequested
EMAIL field name: IsPromptMCRequested
HTTPS field name: IsPromptMCRequested
LEEF field name: IsPromptMCRequested
is_prompt_pi_requested
(IS PROMPT PI REQUESTED)
Indicates whether prompt injection was requested in the scan.
CEF field name: PanOSIsPromptPIRequested
EMAIL field name: IsPromptPIRequested
HTTPS field name: IsPromptPIRequested
LEEF field name: IsPromptPIRequested
is_prompt_tc_requested
(IS PROMPT TC REQUESTED)
Indicates whether Toxic Content was requested for the prompt in the scan.
CEF field name: PanOSIsPromptTCRequested
EMAIL field name: IsPromptTCRequested
HTTPS field name: IsPromptTCRequested
LEEF field name: IsPromptTCRequested
is_prompt_tg_requested
(IS PROMPT TG REQUESTED)
Indicates whether prompt was subjected to topic guardrails scan.
CEF field name: PanOSIsPromptTGRequested
EMAIL field name: IsPromptTGRequested
HTTPS field name: IsPromptTGRequested
LEEF field name: IsPromptTGRequested
is_prompt_urlf_requested
(IS PROMPT URLF REQUESTED)
Indicates whether URLF was requested for the prompt in the scan.
EMAIL field name: IsPromptURLFRequested
HTTPS field name: IsPromptURLFRequested
LEEF field name: IsPromptURLFRequested
is_response
(IS RESPONSE)
Indicates if the request includes a response.
CEF field name: PanOSIsResponse
EMAIL field name: IsResponse
HTTPS field name: IsResponse
LEEF field name: IsResponse
is_response_agent_requested
(IS RESPONSE AGENT REQUESTED)
Indicates where response was subjected to agentic security scan.
EMAIL field name: IsResponseAgentRequested
HTTPS field name: IsResponseAgentRequested
LEEF field name: IsResponseAgentRequested
is_response_cg_requested
(IS RESPONSE CG REQUESTED)
Indicates whether response was subjected to contextual grounding scan.
EMAIL field name: IsResponseCGRequested
HTTPS field name: IsResponseCGRequested
LEEF field name: IsResponseCGRequested
is_response_dbs_requested
(IS RESPONSE DBS REQUESTED)
Indicates whether Database Security was requested for the response in the scan.
EMAIL field name: IsResponseDBSRequested
HTTPS field name: IsResponseDBSRequested
LEEF field name: IsResponseDBSRequested
is_response_dlp_requested
(IS RESPONSE DLP REQUESTED)
Indicates whether DLP was requested for the response in the scan.
EMAIL field name: IsResponseDLPRequested
HTTPS field name: IsResponseDLPRequested
LEEF field name: IsResponseDLPRequested
is_response_mc_requested
(IS RESPONSE MC REQUESTED)
Indicates whether Malicious Code was requested for the response in the scan.
EMAIL field name: IsResponseMCRequested
HTTPS field name: IsResponseMCRequested
LEEF field name: IsResponseMCRequested
is_response_tc_requested
(IS RESPONSE TC REQUESTED)
Indicates whether Toxic Content was requested for the response in the scan.
EMAIL field name: IsResponseTCRequested
HTTPS field name: IsResponseTCRequested
LEEF field name: IsResponseTCRequested
is_response_tg_requested
(IS RESPONSE TG REQUESTED)
Indicates where response was subjected to topic guardrails scan.
EMAIL field name: IsResponseTGRequested
HTTPS field name: IsResponseTGRequested
LEEF field name: IsResponseTGRequested
is_response_urlf_requested
(IS RESPONSE URLF REQUESTED)
Indicates whether URLF was requested for the response in the scan.
EMAIL field name: IsResponseURLFRequested
HTTPS field name: IsResponseURLFRequested
LEEF field name: IsResponseURLFRequested
latency
(LATENCY)
Cloud Latency in ms (core service processing + detection module processing). The time that core service process all the scans.
CEF field name: PanOSLatency
EMAIL field name: Latency
HTTPS field name: Latency
LEEF field name: Latency
log_source
(LOG SOURCE)
Identifies the origin of the data - the system that produced the data.
CEF field name: PanOSLogSource
EMAIL field name: LogSource
HTTPS field name: LogSource
LEEF field name: LogSource
log_source_group_id
(LOG SOURCE GROUP ID)
ID that uniquely identifies the logSourceGroupId of the log. That is, the log_source_id of the group.
CEF field name: LogSourceGroupID
EMAIL field name: LogSourceGroupID
HTTPS field name: LogSourceGroupID
LEEF field name: LogSourceGroupID
log_source_id
(DEVICE SN)
ID that uniquely identifies the source of the log - serial number of the firewall that generated the log.
CEF field name: deviceExternalID
EMAIL field name: DeviceSN
HTTPS field name: DeviceSN
LEEF field name: DeviceSN
log_source_name
(DEVICE NAME)
Name of the source of the log - hostname of the firewall that logged the network traffic.
CEF field name: dvchost
EMAIL field name: DeviceName
HTTPS field name: DeviceName
LEEF field name: DeviceName
log_source_tz_offset
(LOG SOURCE TIMEZONE OFFSET)
Time Zone offset from GMT of the source of the log.
EMAIL field name: LogSourceTimeZoneOffset
HTTPS field name: LogSourceTimeZoneOffset
LEEF field name: LogSourceTimeZoneOffset
log_time
(TIME RECEIVED)
Time the log was received in Cortex Data Lake. This is populated by the platform.
CEF field name: rt
EMAIL field name: TimeReceived
HTTPS field name: TimeReceived
LEEF field name: TimeReceived
log_type.​value
(LOG TYPE)
Identifies the log type.
CEF field name: DeviceEventClassID
EMAIL field name: LogType
HTTPS field name: LogType
LEEF field name: cat
max_latency_hit
(MAX LATENCY HIT)
No if blocked in-line, yes if detected asynchronously and hit the max latency.
CEF field name: PanOSMaxLatencyHit
EMAIL field name: MaxLatencyHit
HTTPS field name: MaxLatencyHit
LEEF field name: MaxLatencyHit
mcp_server
(MCP SERVER)
Mcp server name.
CEF field name: PanOSMCPServer
EMAIL field name: MCPServer
HTTPS field name: MCPServer
LEEF field name: MCPServer
platform_type
(PLATFORM TYPE)
Identifies the platform that generated the log.
CEF field name: PlatformType
EMAIL field name: PlatformType
HTTPS field name: PlatformType
LEEF field name: PlatformType
request_response
(REQUEST RESPONSE)
Whether threat was detected in the request or response.
CEF field name: PanOSRequestResponse
EMAIL field name: RequestResponse
HTTPS field name: RequestResponse
LEEF field name: RequestResponse
scan_id
(SCAN ID)
Identifies the API's internal identifier for a specific API scan request. Sent from AI Runtime API Cloud.
CEF field name: PanOSScanID
EMAIL field name: ScanID
HTTPS field name: ScanID
LEEF field name: ScanID
scan_start_time
(SCAN START TIME)
Identifies the time of when the scan starts.
CEF field name: PanOSScanStartTime
EMAIL field name: ScanStartTime
HTTPS field name: ScanStartTime
LEEF field name: ScanStartTime
scan_sub_req_id
(SCAN SUB REQUEST ID)
Identifies the API's internal identifier for a specific API scan SUB request. Sent from AI Runtime API Cloud.
CEF field name: PanOSScanSUBRequestID
EMAIL field name: ScanSUBRequestID
HTTPS field name: ScanSUBRequestID
LEEF field name: ScanSUBRequestID
scan_type
(SCAN TYPE)
Identifies the type of scan.
CEF field name: PanOSScanType
EMAIL field name: ScanType
HTTPS field name: ScanType
LEEF field name: ScanType
session_url
(SESSION URL)
SCM Session URL link.
CEF field name: PanOSSessionUrl
EMAIL field name: SessionUrl
HTTPS field name: SessionUrl
LEEF field name: SessionUrl
sub_type.​value
(SUB TYPE)
Identifies the log subtype.
CEF field name: Name
EMAIL field name: SubType
HTTPS field name: SubType
LEEF field name: SubType
text_records
(TEXT RECORDS)
Text Records consumed.
CEF field name: PanOSTextRecords
EMAIL field name: TextRecords
HTTPS field name: TextRecords
LEEF field name: TextRecords
time_generated
(TIME GENERATED)
Time the log was generated on the data plane in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
CEF field name: start
EMAIL field name: TimeGenerated
HTTPS field name: TimeGenerated
LEEF field name: devTime
time_generated_high_res
(TIME GENERATED HIGH RESOLUTION)
Time the log was generated in data plane with millisec granularity in format YYYY-MM-DDTHH:MM:SS[.DDDDDD]Z.
EMAIL field name: TimeGeneratedHighResolution
HTTPS field name: TimeGeneratedHighResolution
token_64
(TOKENS 64)
Tokens 64 consumed.
CEF field name: PanOSTokens64
EMAIL field name: Tokens64
HTTPS field name: Tokens64
LEEF field name: Tokens64
tool_name
(TOOL NAME)
Tool name.
CEF field name: PanOSToolName
EMAIL field name: ToolName
HTTPS field name: ToolName
LEEF field name: ToolName
transaction_id
(TRANSACTION ID)
Identifies the API's internal identifier for a specific Transaction provided by Customer.
CEF field name: PanOSTransactionID
EMAIL field name: TransactionID
HTTPS field name: TransactionID
LEEF field name: TransactionID
tsg_id
(TSG ID)
The ID that uniquely identifiers a Tenant Sevice Group (TSG) that this log record should be associated with.
CEF field name: PanOSTSGID
EMAIL field name: TSGID
HTTPS field name: TSGID
LEEF field name: TSGID
vendor_name
(VENDOR NAME)
Identifies the vendor that produced the data.
CEF field name: Device Vendor
EMAIL field name: VendorName
HTTPS field name: VendorName
LEEF field name: Vendor
vendor_severity.​value
(VENDOR SEVERITY)
Severity level of the event as defined by the vendor writing this log record. Severity can be informational/low/medium/high in the API threat logs.
CEF field name: PanOSVendorSeverity
EMAIL field name: VendorSeverity
HTTPS field name: VendorSeverity
LEEF field name: VendorSeverity
verdict
(VERDICT)
Identifies the Verdict that the API conveyed back to caller. Verdict could be Benign/Malicious in the logs.
CEF field name: PanOSVerdict
EMAIL field name: Verdict
HTTPS field name: Verdict
LEEF field name: Verdict