SIEM targets
A SIEM target is an external destination that receives structured security and inference events from the gateway. By default it receives security events (authentication and authorization failures) and blocked inference requests; to stream an event for every request, set the target's events to ["all"]. SIEM targets feed enterprise security-information-and-event-management systems for audit, retention, and correlation.
Supported target types
The gateway supports four target types, selected through the SIEM type drop-down list of the gateway settings dialog:
| Target | Drop-down label | Identifier | Transport |
|---|---|---|---|
| Splunk HEC | Splunk HEC | splunk_hec |
HTTPS POST |
| Elasticsearch and OpenSearch | Elasticsearch / OpenSearch | elasticsearch |
HTTPS POST, one document per event to /<index>/_doc |
| Vector HTTP source | Vector | vector |
HTTP or HTTPS POST (the scheme follows the configured URL) |
| Syslog | Syslog / CEF | syslog |
UDP or TCP, in CEF or RFC 5424 format |
OpenSearch reuses the Elasticsearch implementation; both accept the single-document /<index>/_doc ingest API.
Event content
Every event contains:
- The request timestamp.
- The tenant, gateway, and token identifiers.
- The gateway's request id (
id) and the caller's own correlation id (client_request_id, theX-Request-Idit sent, when conforming) — in every JSON-bodied format: Splunk, Elasticsearch/OpenSearch, Vector, and syslog in RFC 5424 mode. The CEF format carries a curated field set and does not include either correlation id. - The provider and model used.
- Input and output token counts.
- The request cost in USD (the
cost_usdfield). - Whether the response was served from cache (a boolean
cachedflag). - Every guardrail verdict.
- For a blocked/flagged request, its threat-taxonomy classification — the matched OWASP-LLM-Top-10 categories and MITRE-ATLAS techniques.
- The request prompt and response body, when full-payload logging is enabled on the gateway — as stored in the request log: inline base64 attachment bytes are replaced by a
[binary omitted: N bytes]marker, and the payload fields together are bounded to 12 MiB per entry. See the Logs API.
Authentication and authorization failures (sign-in denials, access-denied) are emitted as a separate security-event category — on by default, independent of the inference-event filter. See SIEM integration.
Who can configure a target, and what is validated
A SIEM target is an egress destination the gateway connects to, so setting one is a platform-operator decision, not tenant self-service: siem (per tenant) and config.siem (per gateway) are platform-admin-only to set. A tenant_admin attempting to change either is refused 403. See the accepted shape and what is rejected.
Every target is schema-validated at the write boundary and its destination is checked against the gateway's SSRF egress policy — an http/https url (or a syslog host) that resolves to a loopback, private (RFC1918), or link-local address, or uses a non-http(s) scheme, is rejected (the write returns 400 and nothing is stored). The same check is re-applied at delivery time: HTTP transports connect to the pinned, re-validated IP, and the syslog transports re-validate the host and apply a socket timeout before connecting — so a target that only later resolves to an internal address delivers nothing (logged at WARN) rather than reaching it. An operator-vouched internal collector can be permitted through the gateway's egress allowlist (a deployment setting, by host:port).
Delivery semantics
Events are delivered asynchronously and on a fire-and-forget basis: each event is dispatched on its own background timer and is not retried if delivery fails. A delivery failure is logged at WARN level on the gateway; it is not surfaced in the UI and does not block or fail the originating request.
💡 Note: The gateway is the source of truth for billing. SIEM events are a copy intended for external retention and correlation; do not use SIEM events as the primary cost record.
See also
- SIEM integration — how to configure a SIEM backend