> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Insights

> Review AI-generated security findings about LLM traffic, triage them, and forward them to your SIEM

## Overview

[Insights](https://app.formal.ai/insights) are security findings that Formal generates from your logs. An AI engine reviews LLM traffic against the [OWASP Top 10 for LLM Applications (2025)](https://genai.owasp.org/llm-top-10/) (the risk categories Formal uses). Each insight describes a risk, the entity involved, and the log events behind it.

Insights never change anything on their own. They don't block traffic or edit configuration.

## Enable Insights

<Steps>
  <Step title="Open Insights">
    Go to [Insights](https://app.formal.ai/insights). You need the **Insights** permission.
  </Step>

  <Step title="Enable the engine">
    Under **Enable Formal Insights**, click **Enable Insights**.
  </Step>
</Steps>

The engine reviews new logs every 15 minutes. It only reviews LLM traffic, which reaches Formal through the [Formal Endpoint](/docs/guides/client-apps/desktop-app) or [LLM Resources](/docs/guides/core-concepts/resources/llm).

**Verify:** After the next run, new insights appear on the page, or the page stays empty when there is nothing to report.

## Categories

| Category | Example risk |
| - | - |
| LLM01: Prompt Injection | Instructions in tool output that try to redirect an agent |
| LLM02: Sensitive Information Disclosure | Secrets or personal data sent to a model |
| LLM03: Supply Chain | Untrusted packages, models, or plugins in agent workflows |
| LLM04: Data and Model Poisoning | Manipulated data that could corrupt model behavior |
| LLM05: Improper Output Handling | Model output used unsafely, such as in commands |
| LLM06: Excessive Agency | Agents acting with more autonomy or permissions than needed |
| LLM07: System Prompt Leakage | System instructions exposed to users |
| LLM08: Vector and Embedding Weaknesses | Weaknesses in retrieval and embedding pipelines |
| LLM09: Misinformation | Incorrect output that people rely on |
| LLM10: Unbounded Consumption | Runaway token or request usage |

Each insight also has a **Severity**: **Critical**, **High**, **Medium**, **Low**, or **Info**. A **Confidence** score shows how sure the engine is.

## Triage Insights

The list shows **Severity**, **Category**, **Insight**, **Entity**, **Events**, **Confidence**, **First Seen**, **Last Seen**, and **Created**. Use the **All**, **Unread**, and **Read** filters to work through the queue.

| Action | Effect |
| - | - |
| **Mark as Read** / **Mark as Unread** | Tracks which insights someone has reviewed. Select several rows to use **Mark Read** or **Mark Unread**. |
| **Open in Formal Agent** | Opens the insight in the [Formal Agent](/docs/guides/getting-started/formal-agent) to investigate it or draft a policy |
| **Dismiss** | Permanently deletes the insight. Add an optional note so the engine avoids similar insights in the future. |

When the engine sees the same issue again, it updates the existing insight instead of creating a duplicate. Its occurrence count grows and **Last Seen** moves forward.

## Send Insights to Your SIEM

Formal forwards insights to your [log integrations](/docs/guides/integrations/log), alongside other logs. No extra setup is needed. Formal sends a record each time the engine creates or detects an insight again. A repeat keeps the same `id` with a higher `occurrence_count`.

* Datadog and Splunk receive insights with the service name `insights`.
* AWS S3, Google Cloud Storage, and Azure Blob Storage receive them under `formal/logs/insights/`.

Each forwarded insight is a JSON object with `"source": "insights"`. Key fields:

| Field | Description |
| - | - |
| `id` | Insight ID |
| `title`, `description` | What the engine found |
| `category_id` | Category, such as `llm06_excessive_agency` |
| `severity` | `critical`, `high`, `medium`, `low`, or `info` |
| `confidence` | Confidence score |
| `subject_type`, `subject_id`, `subject_label` | The entity involved, such as a user |
| `evidence` | References to the log events behind the insight |
| `occurrence_count` | How many times the engine has detected this insight |
| `first_seen_at`, `last_seen_at` | When the underlying events happened |

Filter on `source:insights` in your SIEM to build alerts on new findings.

## Next Steps

<CardGroup cols={2}>
  <Card title="Log Integration" icon="pipe" href="/docs/guides/integrations/log">
    Forward logs and insights to your SIEM
  </Card>

  <Card title="AI Usage" icon="chart-line" href="/docs/guides/ai-governance/usage">
    See AI activity across your organization
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.