Skip to main content
TA-guardrails app icon

TA-guardrails

Normalizes AI guardrail events from Bedrock, Azure Content Safety, Azure OpenAI, Vertex AI, Llama Guard, Lakera Guard, and NeMo Guardrails into CIM Intrusion Detection format.Built by kamal singh bisht
splunk product badge

Default Version 0.1.1

July 19, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The AI Guardrails Add-on for Splunk normalizes AI guardrail and content-safety events from seven different providers into a unified schema mapped to the CIM Intrusion Detection data model. The add-on processes telemetry from AWS Bedrock Guardrails, Azure AI Content Safety, Azure OpenAI content filters, Google Vertex AI safety ratings, and self-hosted systems including Llama Guard, Lakera Guard, and NeMo Guardrails. Each guardrail system emits structured event data when policies fire, including the attempted action, triggered policy, category, severity, associated identity, and timestamp. By normalizing this data into a single CIM-compliant format, the add-on enables security operations teams to correlate AI guardrail violations with existing identity, DLP, and insider-threat detection content in Splunk Enterprise Security. The add-on assigns seven distinct sourcetypes corresponding to each provider and extracts events into fields that support detection, alerting, and investigation workflows.