aiFWall Logo aiFObserve

Distributed, Contextual Visibility & Governance for Enterprise AI Traffic. No Agents, No APIs, No

Palo Alto Cortex XDR OTLP Capture Guide For Unified aiFObserve

Best Capture Source

Use Traffic logs as the primary source because they contain session direction, bytes, packets, ports, policy, application, and user fields. Use URL logs, Threat logs, and AI Security logs as optional enrichment, not as replacements for Traffic logs.

Basic Logging

On the security policy rules that allow outbound SaaS and AI traffic:

  1. Enable Traffic logging.
  2. Use Log At Session End as the default.
  3. Add Log At Session Start only for short-lived API calls, long-lived sessions, or troubleshooting where early visibility is worth the volume.
  4. Forward logs to Strata Logging Service, Panorama, HTTPS forwarding, or syslog.

Minimum fields to export:

Extended Logging

User And App Identity

The _user_app_id converter emits an identity evidence table that records whether user, tenant, app, and provider values came from native fields, headers, app fields, host/URL inference, or vendor fallback.

AI Provider And Location Evidence

Keep destination IP, destination country, URL host, SNI, application, tenant, and region/location fields. The unified compliance evidence builder uses these to report AI providers, detected locations, and data boundary checks.

Practical Policy Pattern

Create separate security rules for sanctioned AI applications and AI API destinations. Apply Traffic logging, URL logging, SaaS visibility, and AI Runtime Security profiles to those rules. This makes the converted sessions cleaner and improves recommendation quality.

Notes

Traffic logs are the best source for session volume and packet counters. AI Security logs are event-centric and are most useful as incident evidence.

Sources Used By The Original Firewall Guide