Elastic medium stable kql
Unusual High Word Policy Blocks Detected
Detects repeated compliance violation 'BLOCKED' actions coupled with specific policy name such as 'word_policy', indicating persistent misuse or attempts to probe the model's denied topics.
Detection Logic
from logs-aws_bedrock.invocation-*
// Expand multivalued policy names
| mv_expand gen_ai.policy.name
| mv_expand gen_ai.policy.action
// Filter for blocked profanity-related policy violations
| where
gen_ai.policy.action == "BLOCKED"
and gen_ai.compliance.violation_detected == "true"
and gen_ai.policy.name == "word_policy"
// keep relevant user field
| keep user.id
// count blocked profanity attempts per user
| stats
Esql.ml_policy_blocked_profanity_count = count()
by user.id
// Filter for excessive policy violations
| where Esql.ml_policy_blocked_profanity_count > 5
// sort by violation volume
| sort Esql.ml_policy_blocked_profanity_count desc False Positives
- ⚠ New model deployments.
- ⚠ Testing updates to compliance policies.
Field Validations
Loading…
Comments (0)
Loading comments...