Skip to main content

Moderation Log Record

The DynamoGuard API writes one JSON line to standard output for every logged moderation request. Select these lines with message.logType equal to moderationLogs; the record is under message.log. To forward the lines to a SIEM, see Send DynamoGuard Moderation Logs To A SIEM.

Scope

Describes release 3.26. The line mirrors the API's internal log record, and its fields can change between releases. Check the release notes before you upgrade.

Example Line​

Captured from a 3.26 API: a POST /v1/moderation/analyze request with custom metadata, on an AI system with no policies attached. With policies attached, each entry in appliedPolicies carries the fields listed in Record Fields.

{"level":"info","message":{"log":{"analyses":[{"appliedPolicies":[],"finalAction":"NONE","text":"SIEM test prompt 1","textType":"MODEL_INPUT"}],"metadata":{"channel":"siem-test","seq":1},"source":{"model":"6aa45a51522dbbae086e0439","user":"6aa459da522dbbae086e02f2"}},"logType":"moderationLogs"},"metadata":{"component":"api","reqId":"6d7278b0-ae19-11f1-83ef-6d661bbadc4f"},"timestamp":"11-12:46:05.906"}

Fields that are not set, such as chat and multiturnMetadata here, are omitted.

Top-Level Fields​

FieldValue
levelinfo
message.logTypemoderationLogs. Filter on this field.
message.logThe moderation record. See Record Fields.
metadata.reqIdRequest ID. The API returns the same value to the caller in the X-Request-Id response header. A request that arrives with its own X-Request-Id header keeps that value. A caller can set the join key itself. Trust a caller-supplied value only where you control every caller.
metadata.componentapi
timestampDay of month and time, DD-HH:mm:ss.SSS, with no month, year, or time zone. Use the timestamp your collector records instead.

Record Fields​

Fields marked Redacted are replaced with [REDACTED] when SENSITIVE_USER_REQUEST_DATA_REDACTION_IN_LOGS is "true". The default, "false", leaves them in plain text.

FieldPresentRedactedDescription
source.userAlwaysNoID of the DynamoAI user whose token made the request
source.modelWhen the request is bound to an AI systemNoAI system ID. An analyze request without modelId has no source.model.
source.clientWhen the request sets clientIdNoClient ID from the request
source.sessionChat requestsNoChat session ID
source.emailStreaming requestsNoEmail of the requesting user
analyses[]AlwaysNoOne entry per analyzed text, at most two. See Analyses Per Request Type.
analyses[].textAlwaysRedactedThe analyzed text
analyses[].textTypeAlwaysNoMODEL_INPUT or MODEL_RESPONSE
analyses[].finalActionAlwaysNoMost severe action across the applied policies: BLOCK, SANITIZE, REDACT, WARN, or NONE
analyses[].errorOn errorRedactedError text
analyses[].appliedPolicies[].policyAlwaysNoPolicy ID
analyses[].appliedPolicies[].actionAlwaysNoAction this policy produced
analyses[].appliedPolicies[].outputsAlwaysRedactedGuardrail output for this policy
analyses[].appliedPolicies[].workerRequestIdAlwaysNoModeration server request ID, the request_id in moderation server logs
chat.queryId, chat.prompt, chat.preprocessedPrompt, chat.response, chat.desanitizedResponse, chat.postprocessedResponse, chat.errorChat requestsRedacted (all except queryId)Chat input, output, and processing stages
metadataWhen the request sets itNoCustom metadata from the request
multiturnMetadataWhen the request sets itNoMulti-turn metadata from the request

Overall Decision​

The line has no overall action field. Take the most severe analyses[].finalAction, in this order: BLOCK, SANITIZE, REDACT, WARN, NONE. The API applies the same order when it computes action for the logs API.

Analyses Per Request Type​

Requestanalyses entries
POST /v1/moderation/analyze, textType MODEL_INPUTOne: the prompt
POST /v1/moderation/analyze, textType MODEL_RESPONSETwo: the preceding prompt, with finalAction NONE and no applied policies, then the response
Chat, POST /v1/moderation/model/AI_SYSTEM_ID/chat/SESSION_IDTwo: the input analysis, then the output analysis
Streaming analysisTwo: the input, then the streamed output

Fields The Line Does Not Carry​

  • The log ID that the logs API returns. The line and the API record cannot be joined on an ID.
  • The request type, the overall action, the AI system name, and, except for streaming, the user email.