Context
In August 2026 the UK AI Security Institute published "Incident report: unsanctioned agent behaviour during cyber testing". Investigating a single detected anomaly required manually reviewing 122 evaluation transcripts totalling 212,840 messages, because agent harnesses each log in their own proprietary format (Claude Code session files, OpenAI Agents SDK traces, Hermes-style SQLite archives, etc.). The report also documented behaviours that are inherently cross-log questions: emergent coordination between independent agent runs via public GitHub artifacts, and prompt-injection payloads planted specifically for other AI coding agents to ingest.
This is squarely a log-forensics problem, and it is what Vestigo is for. Meanwhile the producer side is standardizing: the industry is converging on OpenTelemetry with the GenAI semantic conventions (gen_ai.*) — spans such as invoke_agent / chat / execute_tool / invoke_workflow / retrieval, prompt/completion content as OTel log events, and token/duration metrics — with OpenInference (Arize) as a complementary, richer vocabulary (AGENT, LLM, TOOL, CHAIN, RETRIEVER span kinds). Both export as OTLP/JSON.
Proposal
Add agent-telemetry ingestion to the converter family (alongside nginx, suricata, cloudtrail, evtx, zeek), so agentic activity can be investigated with the same provenance, detectors, and Stories workflow as any other log source:
Tier 1 — standardized formats
- OTel GenAI semantic conventions: OTLP/JSON trace files (
gen_ai.* spans) plus the associated log-event records (prompt/completion messages)
- OpenInference span exports (JSONL/OTLP), mapping span kinds to a normalized
agent.span_kind attribute
Tier 2 — harness-native formats (as demand warrants)
Mapping & data-model considerations
- Event granularity: one event per span (with
start/end timestamps preserved; duration derivable), prompt/completion message events as their own rows linked by trace_id/span_id/parent_span_id — parent linkage must survive so agent call trees (orchestrator → sub-agents → tools) can be reconstructed.
- Provenance per house rules: raw span/message payloads hashed, byte offsets into the original export file retained, parser config hashed into identity — same as existing converters.
- Typed attributes rather than flattening everything to strings: token counts as numerics, tool names/arguments as structured fields, so detectors and the Explore grid can aggregate meaningfully.
Why it's more than ingestion: detection opportunities
Existing detectors become interesting on this data with little extra work, e.g.:
- tool-call frequency / novelty anomalies per agent session (burst of
execute_tool against never-before-seen targets)
- Sigma-style content rules over message events: prompt-injection patterns in tool/user messages, credential-shaped strings (tokens, PATs) in outbound agent messages, agent-to-agent coordination markers
- cross-run joins on shared artifacts (same external account/URL appearing in multiple independent agent traces — the AISI incident's coordination signature)
- token-usage and duration outliers per model/backend
Out of scope
- Live/online ingestion of OTLP streams (could follow; batch file ingest matches the current model)
- A dedicated "agent investigation" UI mode — Explorer + Stories should carry it
References
Context
In August 2026 the UK AI Security Institute published "Incident report: unsanctioned agent behaviour during cyber testing". Investigating a single detected anomaly required manually reviewing 122 evaluation transcripts totalling 212,840 messages, because agent harnesses each log in their own proprietary format (Claude Code session files, OpenAI Agents SDK traces, Hermes-style SQLite archives, etc.). The report also documented behaviours that are inherently cross-log questions: emergent coordination between independent agent runs via public GitHub artifacts, and prompt-injection payloads planted specifically for other AI coding agents to ingest.
This is squarely a log-forensics problem, and it is what Vestigo is for. Meanwhile the producer side is standardizing: the industry is converging on OpenTelemetry with the GenAI semantic conventions (
gen_ai.*) — spans such asinvoke_agent/chat/execute_tool/invoke_workflow/retrieval, prompt/completion content as OTel log events, and token/duration metrics — with OpenInference (Arize) as a complementary, richer vocabulary (AGENT,LLM,TOOL,CHAIN,RETRIEVERspan kinds). Both export as OTLP/JSON.Proposal
Add agent-telemetry ingestion to the converter family (alongside nginx, suricata, cloudtrail, evtx, zeek), so agentic activity can be investigated with the same provenance, detectors, and Stories workflow as any other log source:
Tier 1 — standardized formats
gen_ai.*spans) plus the associated log-event records (prompt/completion messages)agent.span_kindattributeTier 2 — harness-native formats (as demand warrants)
~/.claude/projects/**/*.jsonl)gen_ai.*JSONL sink — that file should ingest with zero extra work once Tier 1 lands)Mapping & data-model considerations
start/endtimestamps preserved; duration derivable), prompt/completion message events as their own rows linked bytrace_id/span_id/parent_span_id— parent linkage must survive so agent call trees (orchestrator → sub-agents → tools) can be reconstructed.Why it's more than ingestion: detection opportunities
Existing detectors become interesting on this data with little extra work, e.g.:
execute_toolagainst never-before-seen targets)Out of scope
References