Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Logs generated by Generative AI interactions through network access, containing details about user activities and content access patterns.
Table attributes
| Attribute | Value |
|---|---|
| Resource types | - |
| Categories | Security, Network, IT & Management Tools |
| Solutions | LogManagement |
| Basic table support | Yes |
| Auxiliary / Lake table support | Yes |
| DCR workspace transformation support | No |
| Ingestion API support | No |
| Sample Queries | - |
Columns
| Column | Type | Description |
|---|---|---|
| Action | string | The action taken on the content. Possible values: allow, block. |
| Activity | string | The type of generative AI activity being performed. |
| AIAgentId | string | The identifier of the AI agent associated with the interaction. |
| AIAgentName | string | The display name of the AI agent associated with the interaction. |
| _BilledSize | real | The record size in bytes |
| Content | string | The content or query associated with the generative AI interaction. |
| DestinationUrl | string | The URL of the generative AI endpoint accessed. |
| ErrorCode | string | The upstream MCP error code returned in the response (for example, -32600 or -32601). |
| ErrorMessage | string | The error message returned in the response. |
| EventId | string | Unique identifier for the generative AI event. |
| EventType | string | The type of generative AI event that occurred. |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account |
| LlmModel | string | The large language model used for the interaction (for example, gpt-4o, gpt-4.1, o3, or claude-3.5-sonnet). |
| McpClientName | string | The name of the MCP client initiating the MCP communication. |
| McpPrimitiveCount | int | The number of MCP primitives in the operation. |
| McpPrimitiveNames | string | The names of the MCP tools, resources, or prompts involved in the operation. |
| McpProtocolVersion | string | The negotiated MCP protocol version. |
| McpServerName | string | The name of the MCP server handling the MCP requests. |
| SessionId | string | Unique identifier for the session. |
| SourceSystem | string | The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics |
| SubActivity | string | The specific type of operation within the activity. |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | The date and time (UTC) that the event was generated. |
| TransactionId | string | Unique identifier for the transaction. |
| Type | string | The name of the table |
| UserPrincipalName | string | The UPN of the user who performed the activity. |