Skip to main content

Overview

Insights are security findings that Formal generates from your logs. An AI engine reviews LLM traffic against the OWASP Top 10 for LLM Applications (2025) (the risk categories Formal uses). Each insight describes a risk, the entity involved, and the log events behind it. Insights never change anything on their own. They don’t block traffic or edit configuration.

Enable Insights

1

Open Insights

Go to Insights. You need the Insights permission.
2

Enable the engine

Under Enable Formal Insights, click Enable Insights.
The engine reviews new logs every 15 minutes. It only reviews LLM traffic, which reaches Formal through the Formal Endpoint or LLM Resources. Verify: After the next run, new insights appear on the page, or the page stays empty when there is nothing to report.

Categories

Each insight also has a Severity: Critical, High, Medium, Low, or Info. A Confidence score shows how sure the engine is.

Triage Insights

The list shows Severity, Category, Insight, Entity, Events, Confidence, First Seen, Last Seen, and Created. Use the All, Unread, and Read filters to work through the queue. When the engine sees the same issue again, it updates the existing insight instead of creating a duplicate. Its occurrence count grows and Last Seen moves forward.

Send Insights to Your SIEM

Formal forwards insights to your log integrations, alongside other logs. No extra setup is needed. Formal sends a record each time the engine creates or detects an insight again. A repeat keeps the same id with a higher occurrence_count.
  • Datadog and Splunk receive insights with the service name insights.
  • AWS S3, Google Cloud Storage, and Azure Blob Storage receive them under formal/logs/insights/.
Each forwarded insight is a JSON object with "source": "insights". Key fields: Filter on source:insights in your SIEM to build alerts on new findings.

Next Steps

Log Integration

Forward logs and insights to your SIEM

AI Usage

See AI activity across your organization