Use Traffic logs as the primary source because they contain session direction, bytes, packets, ports, policy, application, and user fields. Use URL logs, Threat logs, and AI Security logs as optional enrichment, not as replacements for Traffic logs.
On the security policy rules that allow outbound SaaS and AI traffic:
Log At Session End as the default.Log At Session Start only for short-lived API calls, long-lived sessions, or troubleshooting where early visibility is worth the volume.Minimum fields to export:
The _user_app_id converter emits an identity evidence table that records whether user, tenant, app, and provider values came from native fields, headers, app fields, host/URL inference, or vendor fallback.
Keep destination IP, destination country, URL host, SNI, application, tenant, and region/location fields. The unified compliance evidence builder uses these to report AI providers, detected locations, and data boundary checks.
Create separate security rules for sanctioned AI applications and AI API destinations. Apply Traffic logging, URL logging, SaaS visibility, and AI Runtime Security profiles to those rules. This makes the converted sessions cleaner and improves recommendation quality.
Traffic logs are the best source for session volume and packet counters. AI Security logs are event-centric and are most useful as incident evidence.