Skip to content

SIEM targets

A SIEM target is an external destination that receives structured security and inference events from the gateway. By default it receives security events (authentication and authorization failures) and blocked inference requests; to stream an event for every request, set the target's events to ["all"]. SIEM targets feed enterprise security-information-and-event-management systems for audit, retention, and correlation.

Supported target types

The gateway supports four target types, selected through the SIEM type drop-down list of the gateway settings dialog:

Target Drop-down label Identifier Transport
Splunk HEC Splunk HEC splunk_hec HTTPS POST
Elasticsearch and OpenSearch Elasticsearch / OpenSearch elasticsearch HTTPS POST, one document per event to /<index>/_doc
Vector HTTP source Vector vector HTTP or HTTPS POST (the scheme follows the configured URL)
Syslog Syslog / CEF syslog UDP or TCP, in CEF or RFC 5424 format

OpenSearch reuses the Elasticsearch implementation; both accept the single-document /<index>/_doc ingest API.

Event content

Every event contains:

  • The request timestamp.
  • The tenant, gateway, and token identifiers.
  • The gateway's request id (id) and the caller's own correlation id (client_request_id, the X-Request-Id it sent, when conforming) — in every JSON-bodied format: Splunk, Elasticsearch/OpenSearch, Vector, and syslog in RFC 5424 mode. The CEF format carries a curated field set and does not include either correlation id.
  • The provider and model used.
  • Input and output token counts.
  • The request cost in USD (the cost_usd field).
  • Whether the response was served from cache (a boolean cached flag).
  • Every guardrail verdict.
  • For a blocked/flagged request, its threat-taxonomy classification — the matched OWASP-LLM-Top-10 categories and MITRE-ATLAS techniques.
  • The request prompt and response body, when full-payload logging is enabled on the gateway — as stored in the request log: inline base64 attachment bytes are replaced by a [binary omitted: N bytes] marker, and the payload fields together are bounded to 12 MiB per entry. See the Logs API.

Authentication and authorization failures (sign-in denials, access-denied) are emitted as a separate security-event category — on by default, independent of the inference-event filter. See SIEM integration.

Who can configure a target, and what is validated

A SIEM target is an egress destination the gateway connects to, so setting one is a platform-operator decision, not tenant self-service: siem (per tenant) and config.siem (per gateway) are platform-admin-only to set. A tenant_admin attempting to change either is refused 403. See the accepted shape and what is rejected.

Every target is schema-validated at the write boundary and its destination is checked against the gateway's SSRF egress policy — an http/https url (or a syslog host) that resolves to a loopback, private (RFC1918), or link-local address, or uses a non-http(s) scheme, is rejected (the write returns 400 and nothing is stored). The same check is re-applied at delivery time: HTTP transports connect to the pinned, re-validated IP, and the syslog transports re-validate the host and apply a socket timeout before connecting — so a target that only later resolves to an internal address delivers nothing (logged at WARN) rather than reaching it. An operator-vouched internal collector can be permitted through the gateway's egress allowlist (a deployment setting, by host:port).

Delivery semantics

Events are delivered asynchronously and on a fire-and-forget basis: each event is dispatched on its own background timer and is not retried if delivery fails. A delivery failure is logged at WARN level on the gateway; it is not surfaced in the UI and does not block or fail the originating request.

💡 Note: The gateway is the source of truth for billing. SIEM events are a copy intended for external retention and correlation; do not use SIEM events as the primary cost record.

See also