Skip to content

feat(ingest): converters for AI agent telemetry — OTel GenAI semconv, OpenInference, harness-native formats #307

Description

@overcuriousity

Context

In August 2026 the UK AI Security Institute published "Incident report: unsanctioned agent behaviour during cyber testing". Investigating a single detected anomaly required manually reviewing 122 evaluation transcripts totalling 212,840 messages, because agent harnesses each log in their own proprietary format (Claude Code session files, OpenAI Agents SDK traces, Hermes-style SQLite archives, etc.). The report also documented behaviours that are inherently cross-log questions: emergent coordination between independent agent runs via public GitHub artifacts, and prompt-injection payloads planted specifically for other AI coding agents to ingest.

This is squarely a log-forensics problem, and it is what Vestigo is for. Meanwhile the producer side is standardizing: the industry is converging on OpenTelemetry with the GenAI semantic conventions (gen_ai.*) — spans such as invoke_agent / chat / execute_tool / invoke_workflow / retrieval, prompt/completion content as OTel log events, and token/duration metrics — with OpenInference (Arize) as a complementary, richer vocabulary (AGENT, LLM, TOOL, CHAIN, RETRIEVER span kinds). Both export as OTLP/JSON.

Proposal

Add agent-telemetry ingestion to the converter family (alongside nginx, suricata, cloudtrail, evtx, zeek), so agentic activity can be investigated with the same provenance, detectors, and Stories workflow as any other log source:

Tier 1 — standardized formats

  • OTel GenAI semantic conventions: OTLP/JSON trace files (gen_ai.* spans) plus the associated log-event records (prompt/completion messages)
  • OpenInference span exports (JSONL/OTLP), mapping span kinds to a normalized agent.span_kind attribute

Tier 2 — harness-native formats (as demand warrants)

Mapping & data-model considerations

  • Event granularity: one event per span (with start/end timestamps preserved; duration derivable), prompt/completion message events as their own rows linked by trace_id/span_id/parent_span_id — parent linkage must survive so agent call trees (orchestrator → sub-agents → tools) can be reconstructed.
  • Provenance per house rules: raw span/message payloads hashed, byte offsets into the original export file retained, parser config hashed into identity — same as existing converters.
  • Typed attributes rather than flattening everything to strings: token counts as numerics, tool names/arguments as structured fields, so detectors and the Explore grid can aggregate meaningfully.

Why it's more than ingestion: detection opportunities

Existing detectors become interesting on this data with little extra work, e.g.:

  • tool-call frequency / novelty anomalies per agent session (burst of execute_tool against never-before-seen targets)
  • Sigma-style content rules over message events: prompt-injection patterns in tool/user messages, credential-shaped strings (tokens, PATs) in outbound agent messages, agent-to-agent coordination markers
  • cross-run joins on shared artifacts (same external account/URL appearing in multiple independent agent traces — the AISI incident's coordination signature)
  • token-usage and duration outliers per model/backend

Out of scope

  • Live/online ingestion of OTLP streams (could follow; batch file ingest matches the current model)
  • A dedicated "agent investigation" UI mode — Explorer + Stories should carry it

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions