LLM gateway security logging: fields and coverage

A useful gateway log lets an investigator reconstruct who was authorized, which request attempts occurred, and what usage was recorded. Start with a field contract and correlation rules. A large log archive is not automatically sufficient evidence.

Keep identity, attempts, and usage distinct

Field groupRecommended informationValidation check
Event identityEvent ID, logical request ID, attempt ID, UTC time, emitterCan retries be separated from duplicate delivery?
Access identityPseudonymous credential and workload referencesIs identity authenticated or merely client-supplied?
RoutingModel, provider, route, deployment referenceCan fallback to a different model be reconstructed?
UsageInput/output tokens, cost value, currency and calculation basisAre unavailable values null rather than zero?
OutcomeSuccess/failure, numeric status where known, durationAre cancellations and streaming completion handled?
ContextTrusted network reference, deployment or job referenceDoes the field identify the client or just the gateway?

An illustrative event

This is a proposed investigation format, not the current InferTrail ingestion schema. All identifiers and numbers below are synthetic.

{
  "event_id": "evt-example-1",
  "logical_request_id": "req-example-1",
  "attempt_id": "attempt-2",
  "timestamp": "2026-09-30T12:00:00Z",
  "principal_id": "hmac-key-example",
  "workload_id": null,
  "model": "deployment-a",
  "input_tokens": 200,
  "output_tokens": 80,
  "estimated_cost_usd": null,
  "outcome": "success"
}

A missing workload ID means the request cannot yet be assigned to an originating job. It does not mean every such request belongs to the same anonymous user. Preserve that distinction during aggregation.

Choose an explicit content boundary

Allowlist fields before export. Exclude raw credentials, authorization headers, cookies, prompts, responses, and free-text error bodies from the metadata dataset. Test unexpected nested fields and failure paths, not only a clean success example. Restrict raw lookup mappings and keep tenant identifiers separated.

Check LiteLLM's actual emitted payload

LiteLLM documents a standard logging payload with usage, timing, and identity metadata. Optional identity can be absent, and some callback events lack the standard payload. Validate your deployed version and success, failure, streaming, and retry paths against the official specification; do not assume every documented field is present on every event.

Measure loss and retention

Track accepted, written, rejected, and dropped events at each collector stage. Reconcile totals against a known request sample. Test duplicate delivery, queue overflow, a full disk, and shutdown. A collector that silently loses busy periods creates exactly the gap an investigator needs to understand.

Set retention from investigation requirements and applicable organizational policy. Verify that the lookup mapping and request records overlap in time; retaining one without the other can make attribution impossible. Document deletion and access controls along with the event schema.

Next: correlate gateway hops and use the records in a key-abuse investigation.