Skip to main content
TA LLM Gateway app icon

TA LLM Gateway

Technology Add-on for normalizing LLM gateway traffic from Bifrost and LiteLLM into Splunk. Provides consistent field extractions (model, provider, tokens, cost, latency, tool calls) and pre-built eventtypes across both gateways, enabling usage auditing, cost tracking, and OWASP LLM Top 10 / MITRE ATLAS detection.Built by Rod Soto
splunk product badge

Default Version 0.3.7

July 23, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Organizations routing LLM traffic through gateways like Bifrost and LiteLLM lack unified visibility into that traffic — prompts, provider routing, token spend, tool calls, and failures are scattered across each gateway's own logs in inconsistent formats. TA-llmgateway normalizes telemetry from both gateways into two Splunk sourcetypes (llmgateway:bifrost, llmgateway:litellm) with a shared field taxonomy — model, provider, latency, token usage, cost, tool calls, retries — regardless of which gateway or upstream LLM handled the request. Pre-built eventtypes flag errors, high-token-usage requests, off-hours activity, and retries out of the box, letting security and platform teams audit AI request activity, monitor usage and cost, and detect jailbreak or prompt-injection attempts (OWASP LLM Top 10 / MITRE ATLAS) through standard Splunk searches.