Shadow LLMs
Use these insights to identify usage anomalies arising from publicly available LLMs and take action based on unknown or risky traffic data.
LLMs in Use
View the most commonly used LLMs in your network, along with their usage volumes. Use search to confirm whether there is ongoing communication with specific LLMs.
Top Subscriptions or Tenants with Usage
View the top subscriptions or tenants using a specific LLM. Switch between different views to identify changes in LLM traffic for the subscriptions or tenants.
Top Sources communicating with LLMs
View the top sources communicating with across any LLM in your environment. Drill deeper to specify an LLM and see the top sources communicating with it.
Traffic Query Results
Filter traffic results by source IP, source zone, port, protocol, and much more. Filter the Source Zone column to see all of your Azure sources in one place.
NOTE: Switching between flows and bytes may change your displayed results. Suppose a resource with denied traffic has a large number of flows but zero bytes. In this case, switching the displayed results from flows to bytes would remove the resource from a Top 10 list due to the low byte count, replacing it with another resource that has a higher byte count.
View flow, IP, and resource details using slide-outs
Slide-outs provide additional information about specific flows, IP addresses, and resources. Click each to launch a slide-out and view additional details.