> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# AI Traffic Flow Analytics

> AgentGuard aggregates observed AI traffic into source-to-destination flows, reports traffic volumes and top destinations, and supports filtering by source mode, time range, and AI vendor.

AI Traffic Flow Analytics is the traffic-visibility capability of
AgentGuard. It aggregates
observed AI traffic into source-to-destination flows and surfaces volumes,
vendors, and trends from existing telemetry sources.

## Telemetry Sources

AgentGuard draws on the following telemetry sources:

* **DCF logs** — provide application-layer AI-protocol signal for traffic that
  traverses Distributed Cloud Firewall.
* **VPC flow logs** — provide breadth for traffic that DCF is not in path for,
  with AI attribution resolved from the destination FQDN and cloud resource
  identity.
* **DNS logs** — provide a third attribution signal: because they capture the
  domain a workload queried, they can identify the AI vendor a workload
  reached even when the corresponding connection is not present in DCF logs
  or VPC flow logs.

## Source Modes

When querying traffic data, you can choose a source mode to trade fidelity
against breadth:

* **DCF** — uses only DCF logs; provides full AI-protocol classification for
  in-path traffic but is limited to traffic DCF inspects.
* **VPC** — uses only VPC flow logs; provides the widest traffic coverage but
  omits AI-protocol detail and some per-flow fields such as Kubernetes namespace and
  workload type.
* **Merged** — combines both sources with per-minute five-tuple de-duplication;
  DCF metadata takes precedence for AI attribution where both sources cover the
  same flow.

Use merged mode for the widest picture. Use DCF-only when you need full
AI-protocol classification. Use VPC-only where DCF is not yet in path.

<Note>
  DNS logs are not a selectable source mode. They contribute AI-vendor
  attribution in the background regardless of the source mode you select.
</Note>

## AI Classification

AgentGuard classifies AI traffic in DCF logs by recognizing the **LLM**,
**MCP**, and **Agent** protocol families. Each workload is tagged with the AI
sub-types it exhibits. In VPC flow log data, destinations are attributed to AI
vendors by FQDN and cloud resource identity.

<Note>
  Full AI-protocol classification requires DCF to be in path for the traffic in
  question. VPC-only analysis attributes traffic to AI vendors by FQDN but does
  not classify by protocol family.
</Note>

## Retention

Analysis is bounded by the telemetry retention window. Plan historical analysis
around this window and export or snapshot data when a longer record is required.

## Related Topics

* [AgentGuard](/docs/cloud/security/agentguard/agentguard-overview)
* [AI Workload Discovery](/docs/cloud/security/agentguard/agentguard-workload-discovery)
* [Protect Your Traffic with Distributed Cloud Firewall](/docs/cloud/security/dcf/about-dcf-security)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.