Skip to main content

Network Sources

Network Sources (Admin → Agent Registry → Network) surfaces the shadow AI found in your CASB/SWG logs: which corporate source IPs and users are calling LLM APIs, even where no SDK or endpoint agent is deployed. It’s fed by the CASB & Network connectors — Cisco Umbrella, Zscaler, and others.

The discovery window

Activity is reported over a rolling window — 30 days by default (configurable via NETWORK_DISCOVERY_WINDOW_DAYS). A few sub-views (top domains, top users, unknown domains) use a fixed 7-day window. On first connect, a connector runs a background backfill so history is available immediately.

What each source shows

Drilling into a source shows a per-observation table (domain, provider, connector, calls, user, last-seen).

Triage workflow

  • Register a source you recognize (it becomes part of your known inventory), or elevate it for follow-up.
  • Ignore / unignore sources that are expected/noise.
  • Review the unknown-domains queue to classify AI destinations the catalog didn’t recognize.
  • Explore analytics and the topology view for org-wide patterns.
  • Export to CSV.

Syncing

Run Sync per connector or Sync All; connectors also sync on a schedule (default every 30 minutes). Backfill progress and connector staleness are shown inline. Connector setup lives in Admin → Integrations → Network.