Meet [**Mobot**](/content/help/docs/search/mobot/index.html), our AI assistant that turns plain-language questions into log queries to accelerate investigations and simplify security workflows.

The Sumo Logic app for Claude Compliance provides security, compliance, and operations teams with centralized visibility into Claude platform activity, covering API usage, authentication events, billing operations, data access, integrations, SSO, and policy changes. Prebuilt dashboards and detection monitors help you identify suspicious behavior, investigate threats, and maintain governance across your Claude environment.

## Log types

This app uses Claude Compliance's activity logs and chat message logs.

### Sample log message

Activity Log

```json
{
  "actor": {
    "type": "user_actor",
    "user_agent": "Mozilla/5.0 (iPhone; CPU iPhone OS 17_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/120.0.6099.119 Mobile/15E148 Safari/604.1",
    "user_id": "user_01KQS2GBC9MK53Y7WE6G16G2Y8",
    "email_address": "alex.martinez482@example.org",
    "ip_address": "45.150.108.61"
  },
  "id": "activity_01KQS28XP295M0QR9VRCX7C3K0",
  "type": "org_join_request_instant_approved",
  "organization_uuid": "org_081m2TJpAuK364YHLwQCXe5r",
  "created_at": "2026-05-08T12:18:11.000538Z",
  "organization_id": "01KQS4ZBD35MR4678P2NNXZPW1"
}
```

Chat Messages Log

```json
{
    "id": "claude_chat_01BKzmfeRdSfq7otZxLhEAUp",
    "name": "Greeting",
    "created_at": "2026-05-07T17:29:59.354315Z",
    "updated_at": "2026-05-07T17:30:01.282925Z",
    "deleted_at": null,
    "organization_id": "org_013w9ZYpBvS942YQNwJAPw6z",
    "organization_uuid": "17c1b787-c3ac-46e3-a107-0b58fc85b293",
    "project_id": null,
    "model": "claude-sonnet-4-6",
    "user": {
        "id": "user_01XyDMpzjS89pFZXqSFUBDr6",
        "email_address": "giacomo@giacomo.plutoenterprise.org"
    },
    "chat_messages": [
        {
            "id": "claude_chat_msg_011Caoc3TT3u8K38ho6SPUPJ",
            "role": "user",
            "created_at": "2026-05-07T17:29:59.774439Z",
            "content": [
                {"type": "text", "text": "hey"}
            ],
            "files": null,
            "generated_files": null,
            "artifacts": null
        },
        {
            "id": "claude_chat_msg_011Caoc3TT4Gh3TnqUYitFAB",
            "role": "assistant",
            "created_at": "2026-05-07T17:30:01.282925Z",
            "content": [
                {"type": "text", "text": " Hey! How can I help you today?"}
            ],
            "files": null,
            "generated_files": null,
            "artifacts": null
        }
    ],
    "href": "https://claude.ai/chat/53a26065-dc3e-4f8d-99da-5fb6525f14b9",
    "has_more": false,
    "first_id": "eyJtc2dfdXVpZCI6ICIwMTllMDM3ZC0zYTRjLTc2NGMtOGMxMy1iZGI0ZDNkZTU4NzkifQ==",
    "last_id": "eyJtc2dfdXVpZCI6ICIwMTllMDM3ZC0zYTRjLTdjZWEtYjJlNi01M2E5YWNjMDRmYjQifQ=="
}
```

### Sample queries

Compliance Activities

```sumo
_sourceCategory="{{Logsdatasource}}" type actor

| json "type","organization_uuid","id","actor.type" as event_type,org_uuid,id,actor_type nodrop

// Global filter

| where if("{{event_type}}" = "*",true,event_type matches "{{event_type}}")
| where if("{{organization}}" = "*",true,org_uuid matches "{{organization}}")
| where if("{{actor_type}}" = "*",true,actor_type matches "{{actor_type}}")

// Panel specific

| count by id
| count
```

Activity Types

```sumo
_sourceCategory="{{Logsdatasource}}" type actor

| json "type","organization_uuid","id","actor.type" as event_type,org_uuid,id,actor_type nodrop

// Global filter

// Panel specific

| count by id,event_type
| count by event_type
| count
```

Messages by Role

```sumo
_sourceCategory="{{Logsdatasource}}" "claude_chat_msg"

| json "id", "updated_at", "user.id", "user.email_address", "name", "organization_id", "message.role", "message.content[0].type", "message.content[0].text", "message.model", "message.id" as id, updated_at, user_id, user_email, name, organization_id, role, message_type, message_value, model, message_id nodrop
| where user_email matches "{{user}}" or isBlank(user_email)
| where role matches "{{role}}" or isBlank(role)
| where model matches "{{model}}" or isBlank(model)
| where message_type matches "{{message_type}}" or isBlank(message_type)
| where message_value contains "{{message}}" or "{{message}}" == "*"
| where !isBlank(role)
| count by message_id, role
| count by role
| sort by _count, role
```

## Collection configuration

This app uses the [Universal Connector](/content/help/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/universal-connector-source/index.html) to collect **activity logs** from the Claude Compliance API and Sumo Logic's [Claude Compliance Source](/content/help/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/claude-compliance-source/index.html) to collect **chat messages logs** from the Claude Compliance Messages API.

### Vendor configuration

To collect logs, you need a Claude API key with access to the Compliance API. Use one of the following options to create the API key:

#### Console / API

Keys are created in the **Admin keys** section of Console Settings.
1. Click **Create key** to name your key.
2. Receive a secret access key and store it securely.

#### Claude.ai

Keys are created in the **Compliance access keys** section of Data Management Settings.
1. Click **Create key** to name your key.
2. Name the key and select its scopes. For activities select `read:compliance_activities` and for chat messages select `read:compliance_user_data`
3. Receive a secret access key and store it securely.

### Source configuration

#### Universal Connector (for Activity Logs)
01. On the Data Collection page, click **Add Source** next to a Hosted Collector.
02. Search for and select **Universal Connector**.
03. Configure the **General** settings:
    - **Name**. Enter a name for the source.
    - **Source Category**. Enter a value such as `claude_compliance`. This value is stored in the `_sourceCategory` metadata field and must match the source category used when installing the app.
04. Configure the **Authentication Configuration**:
    - **Authentication Type**. Select **API Key**.
    - **API Key**. Enter the Claude API key you copied above.
05. Configure the **Request Configuration**:
    - **HTTP Method**. Select `GET`
    - **Endpoint URL**. Enter `https://api.anthropic.com/v1/compliance/activities`

#### Claude Compliance C2C Source (for Chat Messages)
To collect Claude chat messages logs, configure a dedicated Claude Compliance Cloud-to-Cloud source.

## Installing the Claude Compliance app
This section shows you how to install the Sumo Logic app for Claude Compliance.

1. Select **App Catalog**.
2. In the 🔎 **Search Apps** field, run a search for your desired app, then select it.
3. Click **Install App**.
4. Click **Next** in the **Setup Data** section.
5. Click **Next**. You will be redirected to the **Preview & Done** section.

**Post-installation**
Once your app is installed, it will appear in your **Installed Apps** folder, and dashboard panels will begin filling automatically.

## Viewing the Claude Compliance dashboards
### Activity Overview
The **Claude Compliance - Activity Overview** dashboard delivers a high-level summary of all compliance-relevant activities occurring across your Claude environment, including event volumes, activity types, and threat counts.

### Billing Monitoring
The **Claude Compliance - Billing Monitoring** dashboard monitors billing-related compliance events, including subscription lifecycle changes, spend limit updates, prepaid activity, and recharge events across your organization.

### API Key Monitoring
The **Claude Compliance - API Key Monitoring** dashboard provides visibility into API key lifecycle events across your Claude environment, including creation, deletion, and modification of API, Admin, Service, and Signing keys.

### Data Access and Exfiltration Monitoring
The **Claude Compliance - Data Access and Exfiltration Monitoring** dashboard provides deep visibility into file, document, and data export activities across the Claude platform helping detect potential data exfiltration or unauthorized access.

### User Configuration and Invite Lifecycle Monitoring
The **Claude Compliance - User Configuration and Invite Lifecycle Monitoring** dashboard provides full visibility into user configuration changes, invite lifecycle events, role assignments, and organizational membership activity across your Claude environment.

### Chats
The **Claude Compliance – Chats** dashboard provides comprehensive oversight of Claude AI usage across your organization, surfacing key metrics including active users, deployed models, project distribution, and message volume trends.

## Create monitors for Claude Compliance app
From your App Catalog:
1. From the Sumo Logic navigation, select **App Catalog**.
2. In the **Search Apps** field, search for and then select your app.
3. Make sure the app is installed.
4. Navigate to **What's Included** tab and scroll down to the **Monitors** section.
5. Click **Create** next to the pre-configured monitors. In the create monitors window, adjust the trigger conditions and notifications settings based on your requirements.

### Claude Compliance monitors
| Name | Description | Trigger Type | Alert Condition |
| --- | --- | --- | --- |
| `Claude Compliance - Admin or Platform API Key Created` | Detects when an Admin API key or Platform API key is created within the organization. | Critical | Count > 0 |
| `Claude Compliance - API Logging Disabled` | Detects when Compliance API logging is disabled for an organization. | Critical | Count > 0 |
| `Claude Compliance - Compliance Activity From Embargoed Location` | Detects compliance-related activities originating from embargoed or geographically restricted locations. | Critical | Count > 0 |
