Moderation Log Record
The DynamoGuard API writes one JSON line to standard output for every logged moderation request. Select these lines with message.logType equal to moderationLogs; the record is under message.log. To forward the lines to a SIEM, see Send DynamoGuard Moderation Logs To A SIEM.
Describes release 3.26. The line mirrors the API's internal log record, and its fields can change between releases. Check the release notes before you upgrade.
Example Line
Captured from a 3.26 API: a POST /v1/moderation/analyze request with custom metadata, on an AI system with no policies attached. With policies attached, each entry in appliedPolicies carries the fields listed in Record Fields.
{"level":"info","message":{"log":{"analyses":[{"appliedPolicies":[],"finalAction":"NONE","text":"SIEM test prompt 1","textType":"MODEL_INPUT"}],"metadata":{"channel":"siem-test","seq":1},"source":{"model":"6aa45a51522dbbae086e0439","user":"6aa459da522dbbae086e02f2"}},"logType":"moderationLogs"},"metadata":{"component":"api","reqId":"6d7278b0-ae19-11f1-83ef-6d661bbadc4f"},"timestamp":"11-12:46:05.906"}
Fields that are not set, such as chat and multiturnMetadata here, are omitted.
Top-Level Fields
| Field | Value |
|---|---|
level | info |
message.logType | moderationLogs. Filter on this field. |
message.log | The moderation record. See Record Fields. |
metadata.reqId | Request ID. The API returns the same value to the caller in the X-Request-Id response header. A request that arrives with its own X-Request-Id header keeps that value. A caller can set the join key itself. Trust a caller-supplied value only where you control every caller. |
metadata.component | api |
timestamp | Day of month and time, DD-HH:mm:ss.SSS, with no month, year, or time zone. Use the timestamp your collector records instead. |
Record Fields
Fields marked Redacted are replaced with [REDACTED] when SENSITIVE_USER_REQUEST_DATA_REDACTION_IN_LOGS is "true". The default, "false", leaves them in plain text.
| Field | Present | Redacted | Description |
|---|---|---|---|
source.user | Always | No | ID of the DynamoAI user whose token made the request |
source.model | When the request is bound to an AI system | No | AI system ID. An analyze request without modelId has no source.model. |
source.client | When the request sets clientId | No | Client ID from the request |
source.session | Chat requests | No | Chat session ID |
source.email | Streaming requests | No | Email of the requesting user |
analyses[] | Always | No | One entry per analyzed text, at most two. See Analyses Per Request Type. |
analyses[].text | Always | Redacted | The analyzed text |
analyses[].textType | Always | No | MODEL_INPUT or MODEL_RESPONSE |
analyses[].finalAction | Always | No | Most severe action across the applied policies: BLOCK, SANITIZE, REDACT, WARN, or NONE |
analyses[].error | On error | Redacted | Error text |
analyses[].appliedPolicies[].policy | Always | No | Policy ID |
analyses[].appliedPolicies[].action | Always | No | Action this policy produced |
analyses[].appliedPolicies[].outputs | Always | Redacted | Guardrail output for this policy |
analyses[].appliedPolicies[].workerRequestId | Always | No | Moderation server request ID, the request_id in moderation server logs |
chat.queryId, chat.prompt, chat.preprocessedPrompt, chat.response, chat.desanitizedResponse, chat.postprocessedResponse, chat.error | Chat requests | Redacted (all except queryId) | Chat input, output, and processing stages |
metadata | When the request sets it | No | Custom metadata from the request |
multiturnMetadata | When the request sets it | No | Multi-turn metadata from the request |
Overall Decision
The line has no overall action field. Take the most severe analyses[].finalAction, in this order: BLOCK, SANITIZE, REDACT, WARN, NONE. The API applies the same order when it computes action for the logs API.
Analyses Per Request Type
| Request | analyses entries |
|---|---|
POST /v1/moderation/analyze, textType MODEL_INPUT | One: the prompt |
POST /v1/moderation/analyze, textType MODEL_RESPONSE | Two: the preceding prompt, with finalAction NONE and no applied policies, then the response |
Chat, POST /v1/moderation/model/AI_SYSTEM_ID/chat/SESSION_ID | Two: the input analysis, then the output analysis |
| Streaming analysis | Two: the input, then the streamed output |
Fields The Line Does Not Carry
- The log ID that the logs API returns. The line and the API record cannot be joined on an ID.
- The request type, the overall action, the AI system name, and, except for streaming, the user email.