Skip to content

Hodor Activity

Overview

Hodor manages identities and access to tools for AI agents through a Model Context Protocol (MCP) gateway. This integration collects tool-call activity sent by Hodor, including the workspace, actor, agent, provider, access contract, duration, and outcome when available.

  • Vendor: Hodor
  • Supported environment: SaaS
  • Detection based on: Telemetry
  • Supported application or feature: MCP tool-call activity

The integration supports Hodor's version 1 activity envelope. It covers calls recorded by Hodor's activity logger; it does not collect Hodor's separate administrative audit stream or all authentication and policy-denial events.

Prerequisites

  • A Hodor workspace with an agent and a configured tool connection.
  • Permission to create an intake in the target Sekoia community.
  • Assistance from the Hodor team to enable external delivery for your workspace.

Hodor sends events directly to Sekoia over HTTPS. No collector or polling connector is required.

Configure

Create the intake in Sekoia

  1. Open Intakes in the Operations Center and click New intake.
  2. Search for and select Hodor Activity.
  3. Enter a name, select the entity, and save the intake.
  4. Copy the intake key from the intake details page.

Allow time for a newly created intake to become available to the HTTPS collector before enabling delivery. During activation, the collector can temporarily reject the new key. When testing a new custom format, its parser may also take time to become available to the ingestion workers.

See Manage intakes for more information.

Enable delivery from Hodor

External delivery is currently configured with assistance from the Hodor team. Contact your Hodor representative with:

  • The Hodor workspace or workspaces whose activity you want to collect.
  • The Sekoia intake key, shared through your agreed secure channel.
  • The HTTP Intake URL for your Sekoia region, including its path when one is listed. For FRA1, the URL is https://intake.sekoia.io.
  • The desired payload mode, described below.

The Hodor team configures and enables the Sekoia destination and links the selected workspaces. Once active, new recorded tool calls are forwarded automatically. Historical activity is not backfilled automatically when a destination is enabled.

Choose the payload mode

Mode Request and response bodies
metadata (default) Omitted. Actor, agent, workspace, contract, action, and result metadata remain available.
truncated Forwarded when present. A body whose serialized JSON exceeds 2,048 bytes is replaced by an object containing _truncated, _bytes, and a preview of the first 2,048 bytes.
full Forwarded in full when present.

Payload mode is configured per destination. Hodor applies its internal visibility rules before forwarding: do_not_store removes the bodies and workspace_redacted applies redaction. Bodies marked owner_only can still be exported when the destination uses truncated or full. Choose the destination mode accordingly. Metadata mode still includes identity information such as names and email addresses when available.

Verify collection

  1. After the Hodor team confirms activation, perform a tool call through an agent in a linked workspace.
  2. Open Sekoia's events page, search for sekoiaio.intake.uuid:"<intake UUID>" using the UUID of your Hodor intake, and use a time range covering the call.
  3. Verify the event timestamp, event.action, organization.id, hodor.agent.id, and event.outcome against the call in Hodor. Optional identity and contract fields may be absent.
  4. Confirm that parsing succeeded and that request and response fields match the configured payload mode.

A metadata-only event is sufficient to verify collection. Successful collection does not require request or response bodies.

Interpret the events

Hodor value Sekoia field Meaning
occurred_at @timestamp Time the activity occurred in Hodor.
id hodor.event_id Hodor event identifier, retained across delivery retries and replays. Sekoia assigns its own event.id.
workspace organization.id, organization.name Workspace attribution.
actor user.id, user.email, user.full_name, user.name Human profile associated with the call. user.name uses the name, falling back to the email address.
agent hodor.agent.* AI agent identity in Hodor.
provider service.name Tool provider used for the call.
contract hodor.contract.* Access contract associated with the call.
action event.action Recorded action, for example /mcp/tools/search. The tool name can be prefixed with the name of the tool connection in Hodor, for example /mcp/tools/Linear__get_issue.
result.is_error event.outcome true becomes failure, false becomes success, and an absent value becomes unknown.
result.duration_ms event.duration Call duration converted from milliseconds to nanoseconds.
result.status_code hodor.status_code Hodor's status used to attribute the result or fault. This can differ from the provider's HTTP status.
result.error_message error.message Error details when supplied by Hodor.
payload.request, payload.response hodor.request, hodor.response Optional bodies, subject to the payload mode and internal visibility rules.

Use event.outcome to identify failed calls. A tool error can have hodor.status_code = 200, so a status of 200 alone does not establish success. A failed call alone also does not establish that a Hodor policy blocked it.

Hodor's status convention attributes provider refusals to 4xx codes, provider availability failures to 502, 503, or 504, and internal gateway errors to 500. The parser preserves the recorded code without interpreting it as a raw upstream HTTP response.

Retries or replays can produce more than one Sekoia event for the same Hodor activity. Use hodor.event_id to correlate those copies.

Troubleshooting

Symptom Checks
No events arrive Confirm that the destination is enabled, the workspace is linked, the intake key and regional URL match, and a new tool call has been recorded since activation. Ask the Hodor team to inspect delivery errors.
A newly created intake returns Invalid intake key Verify the key and regional URL. If the intake was just created, allow time for activation, then retry with a new test event.
A new custom format reports Cannot find a parser for event Confirm that the format contains the saved parser, allow time for activation, then verify a new event. The error can also affect an isolated event shortly after other events parsed successfully. Events that failed are not parsed again, so send a new event to check. A successful test in the parser editor alone does not verify the ingestion workers.
Events arrive but parsing fails Verify that the intake uses Hodor Activity and that the event is a version 1 Hodor activity envelope. Share an anonymized failing event with support.
Request or response fields are missing Check the destination's payload mode and the event's hodor.payload_visibility. Metadata mode and do_not_store omit the bodies.
Actor or contract fields are missing These attributes are optional. Missing values do not prevent parsing the rest of the event.

Event samples and extracted fields

The following samples use synthetic data. They show the Hodor envelope received by the parser after the HTTPS intake removes its transport wrapper.

Raw Events Samples

In this section, you will find examples of raw logs as generated natively by the source. These examples are provided to help integrators understand the data format before ingestion into Sekoia.io. It is crucial for setting up the correct parsing stages and ensuring that all relevant information is captured.

{
    "schema_version": 1,
    "source": "hodor",
    "id": "f8dd5cc8a79054ff93ac8c56330f54bc",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "do_not_store",
        "payload_mode": "full",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "6cd3f10eaace5a309c50b7070baa9515",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": null
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "beb97f8c282a5a34b113bb3cef2b2af6",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": {
            "tool": "search",
            "arguments": {
                "query": "example project"
            }
        },
        "response": {
            "content": [
                {
                    "type": "text",
                    "text": "Example document"
                }
            ],
            "isError": false
        }
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "full",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "1da55f15c70e54fcb2cc410482c6a671",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": 70,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "7924f9e446d25aacacc229fe298d5ebe",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 500,
        "duration_ms": 42,
        "is_error": true,
        "error_message": "Gateway execution failed"
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "5ef2f684612757578cf847887ffa1746",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "abc1e1cb795f5bd19da77dce3adf4eeb",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": null
    },
    "actor": {
        "profile_id": null,
        "email": null,
        "name": null
    },
    "agent": {
        "id": null,
        "name": null,
        "description": null
    },
    "provider": null,
    "contract": {
        "id": null,
        "label": null,
        "description": null
    },
    "result": {
        "status_code": 200,
        "duration_ms": 0,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": null,
        "extras": {}
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "ff2d3bd16b095f6b8c6cdc1d0063e4a6",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": {
            "tool": "search",
            "arguments": {
                "query": "example project"
            }
        },
        "response": {
            "content": [
                {
                    "type": "text",
                    "text": "Example document"
                }
            ],
            "isError": false
        }
    },
    "metadata": {
        "payload_visibility": "owner_only",
        "payload_mode": "full",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "847b09d001c35de9aa7786ef39133acc",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 403,
        "duration_ms": 42,
        "is_error": true,
        "error_message": "Provider refused access"
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "44d238c427d65a6e81227b89f6326010",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 502,
        "duration_ms": 42,
        "is_error": true,
        "error_message": "Provider unavailable"
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "3fb6754d7f6450a4a7cb828ac18983f0",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": {
            "tool": "search",
            "arguments": {
                "email": "[REDACTED]"
            }
        },
        "response": {
            "content": "[REDACTED]"
        }
    },
    "metadata": {
        "payload_visibility": "workspace_redacted",
        "payload_mode": "full",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "2a138f759f2e54399538e929675a8d3e",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "result": {
        "status_code": 200,
        "error_message": null
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "fc09d487dd7b56a79fbb615d0b2ccbbe",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": true,
        "error_message": "Tool returned an error"
    },
    "payload": {
        "request": null,
        "response": null
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "metadata",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}
{
    "schema_version": 1,
    "source": "hodor",
    "id": "24b4a4f1ab41541fb83a00971bab2810",
    "occurred_at": "2026-08-14T11:01:00+00:00",
    "kind": "mcp_tool_call",
    "action": "/mcp/tools/search",
    "workspace": {
        "id": 11111111,
        "name": "Example Organization"
    },
    "actor": {
        "profile_id": 33333333,
        "email": "alice@example.com",
        "name": "Alice"
    },
    "agent": {
        "id": 20,
        "name": "Research assistant",
        "description": "Search approved documents"
    },
    "provider": "notion",
    "contract": {
        "id": 40,
        "label": "Research access",
        "description": "Read approved knowledge sources"
    },
    "result": {
        "status_code": 200,
        "duration_ms": 42,
        "is_error": false,
        "error_message": null
    },
    "payload": {
        "request": {
            "tool": "search",
            "arguments": {
                "query": "example project"
            }
        },
        "response": {
            "_truncated": true,
            "_bytes": 4814,
            "preview": "{\"content\":\"Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Exam"
        }
    },
    "metadata": {
        "payload_visibility": "workspace_visible",
        "payload_mode": "truncated",
        "source_activity_id": null,
        "extras": {
            "workspace_provider_catalog_id": 50,
            "tool_catalog_provider_id": 60
        }
    }
}

Event Categories

The following table lists the data source offered by this integration.

Data Source Description
API monitoring AI agent tool calls through the Hodor MCP gateway, including the actor, target provider and outcome.
Application logs Hodor agent, workspace and contract context associated with each tool call.

In details, the following table denotes the type of events produced by this integration.

Name Values
Kind event
Category web
Type access

Transformed Events Samples after Ingestion

This section demonstrates how the raw logs will be transformed by our parsers. It shows the extracted fields that will be available for use in the built-in detection rules and hunting activities in the events page. Understanding these transformations is essential for analysts to create effective detection mechanisms with custom detection rules and to leverage the full potential of the collected data.

{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"f8dd5cc8a79054ff93ac8c56330f54bc\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"do_not_store\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "f8dd5cc8a79054ff93ac8c56330f54bc",
        "kind": "mcp_tool_call",
        "payload_mode": "full",
        "payload_visibility": "do_not_store",
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"6cd3f10eaace5a309c50b7070baa9515\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":null},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "6cd3f10eaace5a309c50b7070baa9515",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "alice@example.com"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "id": "33333333",
        "name": "alice@example.com"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"beb97f8c282a5a34b113bb3cef2b2af6\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"query\":\"example project\"}},\"response\":{\"content\":[{\"type\":\"text\",\"text\":\"Example document\"}],\"isError\":false}},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "beb97f8c282a5a34b113bb3cef2b2af6",
        "kind": "mcp_tool_call",
        "payload_mode": "full",
        "payload_visibility": "workspace_visible",
        "request": {
            "arguments": {
                "query": "example project"
            },
            "tool": "search"
        },
        "response": {
            "content": [
                {
                    "text": "Example document",
                    "type": "text"
                }
            ],
            "isError": false
        },
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"1da55f15c70e54fcb2cc410482c6a671\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":70,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "1da55f15c70e54fcb2cc410482c6a671",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "source_activity_id": "70",
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"7924f9e446d25aacacc229fe298d5ebe\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":500,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Gateway execution failed\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "failure",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "error": {
        "message": "Gateway execution failed"
    },
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "7924f9e446d25aacacc229fe298d5ebe",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "status_code": 500
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"5ef2f684612757578cf847887ffa1746\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "5ef2f684612757578cf847887ffa1746",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"abc1e1cb795f5bd19da77dce3adf4eeb\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":null},\"actor\":{\"profile_id\":null,\"email\":null,\"name\":null},\"agent\":{\"id\":null,\"name\":null,\"description\":null},\"provider\":null,\"contract\":{\"id\":null,\"label\":null,\"description\":null},\"result\":{\"status_code\":200,\"duration_ms\":0,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 0,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "event_id": "abc1e1cb795f5bd19da77dce3adf4eeb",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"ff2d3bd16b095f6b8c6cdc1d0063e4a6\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"query\":\"example project\"}},\"response\":{\"content\":[{\"type\":\"text\",\"text\":\"Example document\"}],\"isError\":false}},\"metadata\":{\"payload_visibility\":\"owner_only\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "ff2d3bd16b095f6b8c6cdc1d0063e4a6",
        "kind": "mcp_tool_call",
        "payload_mode": "full",
        "payload_visibility": "owner_only",
        "request": {
            "arguments": {
                "query": "example project"
            },
            "tool": "search"
        },
        "response": {
            "content": [
                {
                    "text": "Example document",
                    "type": "text"
                }
            ],
            "isError": false
        },
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"847b09d001c35de9aa7786ef39133acc\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":403,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Provider refused access\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "failure",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "error": {
        "message": "Provider refused access"
    },
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "847b09d001c35de9aa7786ef39133acc",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "status_code": 403
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"44d238c427d65a6e81227b89f6326010\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":502,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Provider unavailable\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "failure",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "error": {
        "message": "Provider unavailable"
    },
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "44d238c427d65a6e81227b89f6326010",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "status_code": 502
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"3fb6754d7f6450a4a7cb828ac18983f0\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"email\":\"[REDACTED]\"}},\"response\":{\"content\":\"[REDACTED]\"}},\"metadata\":{\"payload_visibility\":\"workspace_redacted\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "3fb6754d7f6450a4a7cb828ac18983f0",
        "kind": "mcp_tool_call",
        "payload_mode": "full",
        "payload_visibility": "workspace_redacted",
        "request": {
            "arguments": {
                "email": "[REDACTED]"
            },
            "tool": "search"
        },
        "response": {
            "content": "[REDACTED]"
        },
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"2a138f759f2e54399538e929675a8d3e\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"result\":{\"status_code\":200,\"error_message\":null}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "kind": "event",
        "module": "hodor",
        "outcome": "unknown",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "event_id": "2a138f759f2e54399538e929675a8d3e",
        "kind": "mcp_tool_call",
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"fc09d487dd7b56a79fbb615d0b2ccbbe\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Tool returned an error\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "failure",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "error": {
        "message": "Tool returned an error"
    },
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "fc09d487dd7b56a79fbb615d0b2ccbbe",
        "kind": "mcp_tool_call",
        "payload_mode": "metadata",
        "payload_visibility": "workspace_visible",
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}
{
    "message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"24b4a4f1ab41541fb83a00971bab2810\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"query\":\"example project\"}},\"response\":{\"_truncated\":true,\"_bytes\":4814,\"preview\":\"{\\\"content\\\":\\\"Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Exam\"}},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"truncated\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
    "event": {
        "action": "/mcp/tools/search",
        "category": [
            "web"
        ],
        "dataset": "hodor.activity",
        "duration": 42000000,
        "kind": "event",
        "module": "hodor",
        "outcome": "success",
        "type": [
            "access"
        ]
    },
    "@timestamp": "2026-08-14T11:01:00Z",
    "hodor": {
        "agent": {
            "description": "Search approved documents",
            "id": "20",
            "name": "Research assistant"
        },
        "catalog_provider": {
            "id": "60"
        },
        "connector": {
            "id": "50"
        },
        "contract": {
            "description": "Read approved knowledge sources",
            "id": "40",
            "label": "Research access"
        },
        "event_id": "24b4a4f1ab41541fb83a00971bab2810",
        "kind": "mcp_tool_call",
        "payload_mode": "truncated",
        "payload_visibility": "workspace_visible",
        "request": {
            "arguments": {
                "query": "example project"
            },
            "tool": "search"
        },
        "response": {
            "_bytes": 4814,
            "_truncated": true,
            "preview": "{\"content\":\"Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Exam"
        },
        "schema_version": 1,
        "status_code": 200
    },
    "observer": {
        "product": "Hodor",
        "type": "proxy",
        "vendor": "Hodor"
    },
    "organization": {
        "id": "11111111",
        "name": "Example Organization"
    },
    "related": {
        "user": [
            "Alice"
        ]
    },
    "service": {
        "name": "notion"
    },
    "user": {
        "email": "alice@example.com",
        "full_name": "Alice",
        "id": "33333333",
        "name": "Alice"
    }
}

Extracted Fields

The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.

Name Type Description
@timestamp date Date/time when the event originated.
error.message match_only_text Error message.
event.action keyword The action captured by the event.
event.category keyword Event category. The second categorization field in the hierarchy.
event.dataset keyword Name of the dataset.
event.duration long Duration of the event in nanoseconds.
event.kind keyword The kind of the event. The highest categorization field in the hierarchy.
event.module keyword Name of the module this data is coming from.
event.outcome keyword The outcome of the event. The lowest level categorization field in the hierarchy.
event.type keyword Event type. The third categorization field in the hierarchy.
hodor.agent.description keyword Description of the AI agent at the time of the call.
hodor.agent.id keyword Identifier of the AI agent identity in Hodor.
hodor.agent.name keyword Name of the AI agent at the time of the call.
hodor.catalog_provider.id keyword Identifier of the Hodor catalog provider used for the call.
hodor.connector.id keyword Identifier of the Hodor workspace connector slot used for the call.
hodor.contract.description keyword Description of the Hodor contract at the time of the call.
hodor.contract.id keyword Identifier of the Hodor contract governing the agent's access.
hodor.contract.label keyword Name of the Hodor contract at the time of the call.
hodor.event_id keyword Original Hodor event identifier, preserved across delivery retries and replays.
hodor.kind keyword Hodor activity kind, such as mcp_tool_call.
hodor.payload_mode keyword External payload mode: metadata, truncated or full.
hodor.payload_visibility keyword Internal payload visibility selected in Hodor.
hodor.request object Tool request forwarded according to the configured Hodor payload mode and visibility.
hodor.response object Tool response forwarded according to the configured Hodor payload mode and visibility.
hodor.schema_version long Version of the Hodor delivery envelope.
hodor.source_activity_id keyword Source activity identifier for a historical import; absent on live events.
hodor.status_code long Fault-attributing status recorded by Hodor; this can differ from the upstream HTTP status.
observer.product keyword The product name of the observer.
observer.type keyword The type of the observer the data is coming from.
observer.vendor keyword Vendor name of the observer.
organization.id keyword Unique identifier for the organization.
organization.name keyword Organization name.
service.name keyword Name of the service.
user.email keyword User email address.
user.full_name keyword User's full name, if available.
user.id keyword Unique identifier of the user.
user.name keyword Short name or login of the user.

For more information on the Intake Format, please find the code of the Parser, Smart Descriptions, and Supported Events here.

Further reading