Overview
Insights are security findings that Formal generates from your logs. An AI engine reviews LLM traffic against the OWASP Top 10 for LLM Applications (2025) (the risk categories Formal uses). Each insight describes a risk, the entity involved, and the log events behind it. Insights never change anything on their own. They don’t block traffic or edit configuration.Enable Insights
1
Open Insights
Go to Insights. You need the Insights permission.
2
Enable the engine
Under Enable Formal Insights, click Enable Insights.
Categories
Each insight also has a Severity: Critical, High, Medium, Low, or Info. A Confidence score shows how sure the engine is.
Triage Insights
The list shows Severity, Category, Insight, Entity, Events, Confidence, First Seen, Last Seen, and Created. Use the All, Unread, and Read filters to work through the queue.
When the engine sees the same issue again, it updates the existing insight instead of creating a duplicate. Its occurrence count grows and Last Seen moves forward.
Send Insights to Your SIEM
Formal forwards insights to your log integrations, alongside other logs. No extra setup is needed. Formal sends a record each time the engine creates or detects an insight again. A repeat keeps the sameid with a higher occurrence_count.
- Datadog and Splunk receive insights with the service name
insights. - AWS S3, Google Cloud Storage, and Azure Blob Storage receive them under
formal/logs/insights/.
"source": "insights". Key fields:
Filter on
source:insights in your SIEM to build alerts on new findings.
Next Steps
Log Integration
Forward logs and insights to your SIEM
AI Usage
See AI activity across your organization