Telemetry Sources
AgentGuard draws on the following telemetry sources:- DCF logs — provide application-layer AI-protocol signal for traffic that traverses Distributed Cloud Firewall.
- VPC flow logs — provide breadth for traffic that DCF is not in path for, with AI attribution resolved from the destination FQDN and cloud resource identity.
- DNS logs — provide a third attribution signal: because they capture the domain a workload queried, they can identify the AI vendor a workload reached even when the corresponding connection is not present in DCF logs or VPC flow logs.
Source Modes
When querying traffic data, you can choose a source mode to trade fidelity against breadth:- DCF — uses only DCF logs; provides full AI-protocol classification for in-path traffic but is limited to traffic DCF inspects.
- VPC — uses only VPC flow logs; provides the widest traffic coverage but omits AI-protocol detail and some per-flow fields such as Kubernetes namespace and workload type.
- Merged — combines both sources with per-minute five-tuple de-duplication; DCF metadata takes precedence for AI attribution where both sources cover the same flow.
DNS logs are not a selectable source mode. They contribute AI-vendor
attribution in the background regardless of the source mode you select.
AI Classification
AgentGuard classifies AI traffic in DCF logs by recognizing the LLM, MCP, and Agent protocol families. Each workload is tagged with the AI sub-types it exhibits. In VPC flow log data, destinations are attributed to AI vendors by FQDN and cloud resource identity.Full AI-protocol classification requires DCF to be in path for the traffic in
question. VPC-only analysis attributes traffic to AI vendors by FQDN but does
not classify by protocol family.