Portal · Activity
Activity
Find captured AI sessions, narrow the view, and open the evidence behind a user, model, tool, or time window.
- Session evidencePeople, tools, models, and timing
- Trace detailTranscript, files, topics, actions, and plans
- Operational analyticsTokens, cost, latency, and model usage
From signal to session evidence
Activity is the fastest way to confirm that Cortex is receiving new work. Each row represents a captured session, with the person, tool, models, timing, and estimated spend attached.
What Activity shows
- Person: The signed-in user associated with the captured session.
- Session: One continuous run of a supported tool or AI application.
- Models: The providers and models used during the session.
- Timing: First and last captured activity.
- Estimated spend: A planning estimate for the captured activity.
Inspect a session
| View | Use it to answer |
|---|---|
| Session overview | Who worked, when it happened, and which models were used |
| Transcript | What the user and model exchanged |
| Files and topics | Which context and subjects appeared |
| Actions and security | Which tools ran and which security signals were detected |
| Plans and analytics | How the work unfolded, plus tokens, cost, and latency |
Use filters to narrow the list before opening a session. Keep the selected date range with any number you share.
If expected activity is missing
- Any path: Send a new prompt from a configured source. Existing sessions do not pick up new routing settings.
- Endpoint capture: Confirm Cortex Defender is running, the source is enabled, and cloud sync has no backlog.
- Centralized capture: Confirm the Cortex Gateway URL and header are correct, then verify the personal capture token used for attribution.
- Portal check: Open Coverage to see whether the path is inactive or not configured.
Do not treat an empty Activity view as proof that no AI work happened. It means no matching activity was captured for the current scope and filters.
Go deeper
Was this helpful?