Acutis Gate logo Acutis Gate identity for AI at work

MCP audit logging: send every AI tool call to your SIEM

Short answer: log every AI tool call as its own record: the real person (not a service account), their groups at that moment, the tool, the arguments, the result, the decision, the rule that made it, and the identity the call actually ran as. Ship those records to your SIEM as they are written, and chain them with hashes so an edit is detectable. Chat transcripts alone don't answer "who saw what".

What each record needs

  • Who: the person, their groups and role at that moment, and the client (Open WebUI, Claude Desktop, Cursor).
  • What: the tool, the action (read, write, execute), the resource, the full arguments and the result.
  • Why: the decision (allow, deny, approve, break-glass), the rule id and the policy version in force.
  • As whom: the identity the call ran as at the far end. "As the person" and "as a shared account" are very different answers to an auditor.
  • Integrity: a hash of each row chained to the previous one, so a deleted or edited row breaks the chain.

Set up the receiving side

  • Splunk: Settings → Data inputs → HTTP Event Collector → New Token, then copy the token. (Or a syslog input under Data inputs → UDP / TCP.)
  • Microsoft Sentinel: Content hub → install the Common Event Format solution, then Data connectors → Common Event Format (CEF) via AMA on a Linux forwarder.
  • QRadar, LogRhythm, Graylog: a syslog log source (TCP or TLS preferred).

Prove the path receives events before wiring any product:

Command line

# Syslog over UDP, from any Linux box (util-linux logger, RFC 5424)
logger --rfc5424 -n siem.corp.example -P 514 -d -t ai-gateway "test event from the AI gateway"

# Syslog over TCP
logger --rfc5424 -n siem.corp.example -P 514 -T -t ai-gateway "test event over TCP"

# Splunk HTTP Event Collector
curl -k https://splunk.corp.example:8088/services/collector/event \
  -H "Authorization: Splunk <your-hec-token>" \
  -d '{"event": "test event from the AI gateway", "sourcetype": "_json"}' 

What Acutis Gate sends

Acutis Gate is the only tool server the AI has, so it sees every call. Each one becomes a hash-chained audit row with full arguments and results, plus console events (policy saves, identity changes, failed sign-ins). Rows stream as they are written to:

  • Syslog over UDP, TCP or TLS, as JSON or ArcSight CEF (Sentinel, QRadar, LogRhythm and Splunk all parse CEF),
  • an HTTPS webhook signed with an HMAC,
  • Splunk HTTP Event Collector,
  • and a pull feed: page the trail as NDJSON by cursor, or tail it live.

In the Gate console it is one screen:

  1. Open Streaming → Add destination.
  2. Pick syslog (UDP, TCP or TLS) with JSON or CEF, a signed webhook, or Splunk HEC, and enter the address and token.
  3. Click Test: a test event arrives in your SIEM, and the destination shows its last delivery or error.

A denied HR lookup, as Gate's CEF output writes it:

CEF:0|Acutis|Gate|0.1|read|hris__get_salary|7|rt=2026-10-12T15:04:11Z suser=lchen@northwind.example suid=14 src=10.20.7.44 act=read outcome=deny request=hris://employees/priya.n/salary cs1Label=upstream cs1=hris cs2Label=tool cs2=hris__get_salary cs3Label=mode cs3=denied cs6Label=row_hash cs6=9c1e04f2a7 cn1Label=policy_version cn1=4 cn2Label=audit_id cn2=5512 deviceCustomString7Label=groups deviceCustomString7=Finance reason=default deny sourceServiceName=open-webui msg={"employee":"priya.n"}

Delivery is off the request path: if the SIEM is down, AI calls keep working, the destination shows its last error in the console, and the collector can page what it missed by cursor. Audit trail → Verify chain in the console proves no row was edited.

Every AI action, attributed and in your SIEM

Gate records each call with the real person, the rule and the identity it ran as, and streams it to Splunk, Sentinel, QRadar or any syslog SIEM.

Start a 14-day trial Tour the live Gate

Frequently asked questions

What should an AI audit log contain?

The person, their groups at that moment, the client, the tool, the full arguments and result, the decision and rule, the policy version, and the identity the call ran as, with each row hash-chained to the previous one.

Can MCP tool calls go to Microsoft Sentinel?

Yes. Send them as CEF over syslog to the Azure Monitor agent's CEF collector, or use a webhook. Acutis Gate streams every call as CEF or JSON over UDP, TCP or TLS syslog.

What happens to AI calls if the SIEM is down?

With Gate, nothing: delivery runs off the request path. Every row stays in Gate's own chain, and the collector can page what it missed by cursor when it is back.

How do I prove the AI audit trail was not edited?

Chain each row's hash to the previous row. Gate's Verify chain check names the first row that no longer matches.