Anjung Sentinel is the local AI SecOps console for LogRhythm SIEM. It monitors enterprise AI use and Claude Enterprise agents, and lets EvolveX AI investigate with models that run on your own hardware.
Built on the LogRhythm data you already collect. Ten modules cover shadow AI, rogue agents, investigation, detection, local inference and proof for auditors.
Every prompt to ChatGPT, Copilot, DeepSeek, browser extensions and internal LLMs, parsed from the LogRhythm sources you already collect, scored for risk.
Each agent gets a 30-day behavioural baseline. Drift is scored every 15 minutes, and a rogue agent can be suspended from the console.
A persistent investigator that gathers context, runs follow-up searches and posts a cited triage summary within about 10 minutes.
Cases sharing a key, host, IP or agent are linked with a confidence score and a plain-language reason, then merged in one click.
Triage alerts, prioritise your shift and investigate cases in natural language from Claude Code or OpenAI Codex.
Seven rules for AI-era threats mapped to MITRE ATLAS and ATT&CK, plus plain-language rule drafting with backtest and two-person approval.
Run Llama, Qwen or Mistral on your own GPUs. Secrets are masked, context follows analyst permissions and actions need a human.
A 250-word digest for leadership and an Outcomes Navigator that ties SOC work to the business priorities that matter.
Every model request and AI-driven action is SHA-256 hash-chained, forwarded to LogRhythm and exportable for SOC 2 and ISO 27001.
From raw log record to a contained incident, without a single prompt leaving your network.
Proxy, firewall, endpoint, CASB, DLP, SaaS and AI gateway logs flow through LogRhythm as they do today.
AI interactions are recognised, secrets are masked at ingest, and each event gets a High, Medium or Low risk.
EvolveX AI opens the case, gathers context, links related cases and answers questions with citations.
Every request and action is hash-chained in the audit trail and summarised for leadership in the digest.
EvolveX AI works across the New-Scale Security Operations Platform as a persistent investigator: it gathers context when a case opens and keeps searching as the incident unfolds.
As measured by our own security operations team.
Guardrails that are locked on, not promised.
Network policy denies egress from inference and app pods. An egress counter watches firewall logs every 10 seconds.
Keys, passwords, tokens, national IDs and card numbers are replaced with reversible tokens before inference.
The model only sees log sources the analyst can already search in LogRhythm.
Any model output that maps to an action becomes a proposal. Only a person can run it.
Request access to the Anjung Sentinel Console. An administrator reviews every request.