Skip to content

[openai_chatgpt_enterprise] Add support of Application Log Datastream #20829

Description

@muskan-agarwal26

Add an app_log data stream to the openai_chatgpt_enterprise integration.

Collects ChatGPT Enterprise APP_LOG events (in-app connector requests and responses) from the OpenAI Compliance Logs Platform via CEL input. Collection is incremental using last_end_time as the cursor (list log files, then download each file).

Includes:

  • CEL-based data collection with two-phase list/download pagination
  • Ingest pipeline with ECS mappings (user.*, user_agent.*, source.geo.*, gen_ai.*)
  • Field definitions, pipeline and system tests, sample event, and documentation
  • Dashboard covering application/connector usage

Part of #19399.

Metadata

Metadata

Labels

New IntegrationIssue or pull request for creating a new integration package.Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions