NetworkAccessGenerativeAIInsights

Logs generated by Generative AI interactions through network access, containing details about user activities and content access patterns.

Table attributes

Attribute Value
Resource types -
Categories Security, Network, IT & Management Tools
Solutions LogManagement
Basic table support Yes
Auxiliary / Lake table support Yes
DCR workspace transformation support No
Ingestion API support No
Sample Queries -

Columns

Column Type Description
Action string The action taken on the content. Possible values: allow, block.
Activity string The type of generative AI activity being performed.
AIAgentId string The identifier of the AI agent associated with the interaction.
AIAgentName string The display name of the AI agent associated with the interaction.
_BilledSize real The record size in bytes
Content string The content or query associated with the generative AI interaction.
DestinationUrl string The URL of the generative AI endpoint accessed.
ErrorCode string The upstream MCP error code returned in the response (for example, -32600 or -32601).
ErrorMessage string The error message returned in the response.
EventId string Unique identifier for the generative AI event.
EventType string The type of generative AI event that occurred.
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
LlmModel string The large language model used for the interaction (for example, gpt-4o, gpt-4.1, o3, or claude-3.5-sonnet).
McpClientName string The name of the MCP client initiating the MCP communication.
McpPrimitiveCount int The number of MCP primitives in the operation.
McpPrimitiveNames string The names of the MCP tools, resources, or prompts involved in the operation.
McpProtocolVersion string The negotiated MCP protocol version.
McpServerName string The name of the MCP server handling the MCP requests.
SessionId string Unique identifier for the session.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
SubActivity string The specific type of operation within the activity.
TenantId string The Log Analytics workspace ID
TimeGenerated datetime The date and time (UTC) that the event was generated.
TransactionId string Unique identifier for the transaction.
Type string The name of the table
UserPrincipalName string The UPN of the user who performed the activity.