Skip to main content
TA-guardrails app icon

TA-guardrails

Normalizes AI guardrail events from Bedrock, Azure Content Safety, Azure OpenAI, Vertex AI, Llama Guard, Lakera Guard, and NeMo Guardrails into CIM Intrusion Detection format.

splunk product badge
screenshot

Default Version 0.1.1
July 19, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 8.x
Rating

0

(0)

Log in to rate this app
Support
Developer Supported
The AI Guardrails Add-on for Splunk normalizes AI guardrail and content-safety events from seven different providers into a unified schema mapped to the CIM Intrusion Detection data model. The add-on processes telemetry from AWS Bedrock Guardrails, Azure AI Content Safety, Azure OpenAI content filters, Google Vertex AI safety ratings, and self-hosted systems including Llama Guard, Lakera Guard, and NeMo Guardrails. Each guardrail system emits structured event data when policies fire, including the attempted action, triggered policy, category, severity, associated identity, and timestamp. By normalizing this data into a single CIM-compliant format, the add-on enables security operations teams to correlate AI guardrail violations with existing identity, DLP, and insider-threat detection content in Splunk Enterprise Security. The add-on assigns seven distinct sourcetypes corresponding to each provider and extracts events into fields that support detection, alerting, and investigation workflows.

Categories

Security, Fraud & Compliance, Artificial Intelligence

Created By

kamal singh bisht

Type

addon

Downloads

7

Resources

Log in to report this app listing