Hodor Activity
Overview
Hodor manages identities and access to tools for AI agents through a Model Context Protocol (MCP) gateway. This integration collects tool-call activity sent by Hodor, including the workspace, actor, agent, provider, access contract, duration, and outcome when available.
- Vendor: Hodor
- Supported environment: SaaS
- Detection based on: Telemetry
- Supported application or feature: MCP tool-call activity
The integration supports Hodor's version 1 activity envelope. It covers calls recorded by Hodor's activity logger; it does not collect Hodor's separate administrative audit stream or all authentication and policy-denial events.
Prerequisites
- A Hodor workspace with an agent and a configured tool connection.
- Permission to create an intake in the target Sekoia community.
- Assistance from the Hodor team to enable external delivery for your workspace.
Hodor sends events directly to Sekoia over HTTPS. No collector or polling connector is required.
Configure
Create the intake in Sekoia
- Open Intakes in the Operations Center and click New intake.
- Search for and select Hodor Activity.
- Enter a name, select the entity, and save the intake.
- Copy the intake key from the intake details page.
Allow time for a newly created intake to become available to the HTTPS collector before enabling delivery. During activation, the collector can temporarily reject the new key. When testing a new custom format, its parser may also take time to become available to the ingestion workers.
See Manage intakes for more information.
Enable delivery from Hodor
External delivery is currently configured with assistance from the Hodor team. Contact your Hodor representative with:
- The Hodor workspace or workspaces whose activity you want to collect.
- The Sekoia intake key, shared through your agreed secure channel.
- The HTTP Intake URL for your Sekoia region, including its path when one is listed. For FRA1, the URL is
https://intake.sekoia.io. - The desired payload mode, described below.
The Hodor team configures and enables the Sekoia destination and links the selected workspaces. Once active, new recorded tool calls are forwarded automatically. Historical activity is not backfilled automatically when a destination is enabled.
Choose the payload mode
| Mode | Request and response bodies |
|---|---|
metadata (default) |
Omitted. Actor, agent, workspace, contract, action, and result metadata remain available. |
truncated |
Forwarded when present. A body whose serialized JSON exceeds 2,048 bytes is replaced by an object containing _truncated, _bytes, and a preview of the first 2,048 bytes. |
full |
Forwarded in full when present. |
Payload mode is configured per destination. Hodor applies its internal visibility rules before forwarding: do_not_store removes the bodies and workspace_redacted applies redaction. Bodies marked owner_only can still be exported when the destination uses truncated or full. Choose the destination mode accordingly. Metadata mode still includes identity information such as names and email addresses when available.
Verify collection
- After the Hodor team confirms activation, perform a tool call through an agent in a linked workspace.
- Open Sekoia's events page, search for
sekoiaio.intake.uuid:"<intake UUID>"using the UUID of your Hodor intake, and use a time range covering the call. - Verify the event timestamp,
event.action,organization.id,hodor.agent.id, andevent.outcomeagainst the call in Hodor. Optional identity and contract fields may be absent. - Confirm that parsing succeeded and that request and response fields match the configured payload mode.
A metadata-only event is sufficient to verify collection. Successful collection does not require request or response bodies.
Interpret the events
| Hodor value | Sekoia field | Meaning |
|---|---|---|
occurred_at |
@timestamp |
Time the activity occurred in Hodor. |
id |
hodor.event_id |
Hodor event identifier, retained across delivery retries and replays. Sekoia assigns its own event.id. |
workspace |
organization.id, organization.name |
Workspace attribution. |
actor |
user.id, user.email, user.full_name, user.name |
Human profile associated with the call. user.name uses the name, falling back to the email address. |
agent |
hodor.agent.* |
AI agent identity in Hodor. |
provider |
service.name |
Tool provider used for the call. |
contract |
hodor.contract.* |
Access contract associated with the call. |
action |
event.action |
Recorded action, for example /mcp/tools/search. The tool name can be prefixed with the name of the tool connection in Hodor, for example /mcp/tools/Linear__get_issue. |
result.is_error |
event.outcome |
true becomes failure, false becomes success, and an absent value becomes unknown. |
result.duration_ms |
event.duration |
Call duration converted from milliseconds to nanoseconds. |
result.status_code |
hodor.status_code |
Hodor's status used to attribute the result or fault. This can differ from the provider's HTTP status. |
result.error_message |
error.message |
Error details when supplied by Hodor. |
payload.request, payload.response |
hodor.request, hodor.response |
Optional bodies, subject to the payload mode and internal visibility rules. |
Use event.outcome to identify failed calls. A tool error can have hodor.status_code = 200, so a status of 200 alone does not establish success. A failed call alone also does not establish that a Hodor policy blocked it.
Hodor's status convention attributes provider refusals to 4xx codes, provider availability failures to 502, 503, or 504, and internal gateway errors to 500. The parser preserves the recorded code without interpreting it as a raw upstream HTTP response.
Retries or replays can produce more than one Sekoia event for the same Hodor activity. Use hodor.event_id to correlate those copies.
Troubleshooting
| Symptom | Checks |
|---|---|
| No events arrive | Confirm that the destination is enabled, the workspace is linked, the intake key and regional URL match, and a new tool call has been recorded since activation. Ask the Hodor team to inspect delivery errors. |
A newly created intake returns Invalid intake key |
Verify the key and regional URL. If the intake was just created, allow time for activation, then retry with a new test event. |
A new custom format reports Cannot find a parser for event |
Confirm that the format contains the saved parser, allow time for activation, then verify a new event. The error can also affect an isolated event shortly after other events parsed successfully. Events that failed are not parsed again, so send a new event to check. A successful test in the parser editor alone does not verify the ingestion workers. |
| Events arrive but parsing fails | Verify that the intake uses Hodor Activity and that the event is a version 1 Hodor activity envelope. Share an anonymized failing event with support. |
| Request or response fields are missing | Check the destination's payload mode and the event's hodor.payload_visibility. Metadata mode and do_not_store omit the bodies. |
| Actor or contract fields are missing | These attributes are optional. Missing values do not prevent parsing the rest of the event. |
Event samples and extracted fields
The following samples use synthetic data. They show the Hodor envelope received by the parser after the HTTPS intake removes its transport wrapper.
Raw Events Samples
In this section, you will find examples of raw logs as generated natively by the source. These examples are provided to help integrators understand the data format before ingestion into Sekoia.io. It is crucial for setting up the correct parsing stages and ensuring that all relevant information is captured.
{
"schema_version": 1,
"source": "hodor",
"id": "f8dd5cc8a79054ff93ac8c56330f54bc",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "do_not_store",
"payload_mode": "full",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "6cd3f10eaace5a309c50b7070baa9515",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": null
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "beb97f8c282a5a34b113bb3cef2b2af6",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": {
"tool": "search",
"arguments": {
"query": "example project"
}
},
"response": {
"content": [
{
"type": "text",
"text": "Example document"
}
],
"isError": false
}
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "full",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "1da55f15c70e54fcb2cc410482c6a671",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": 70,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "7924f9e446d25aacacc229fe298d5ebe",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 500,
"duration_ms": 42,
"is_error": true,
"error_message": "Gateway execution failed"
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "5ef2f684612757578cf847887ffa1746",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "abc1e1cb795f5bd19da77dce3adf4eeb",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": null
},
"actor": {
"profile_id": null,
"email": null,
"name": null
},
"agent": {
"id": null,
"name": null,
"description": null
},
"provider": null,
"contract": {
"id": null,
"label": null,
"description": null
},
"result": {
"status_code": 200,
"duration_ms": 0,
"is_error": false,
"error_message": null
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": null,
"extras": {}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "ff2d3bd16b095f6b8c6cdc1d0063e4a6",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": {
"tool": "search",
"arguments": {
"query": "example project"
}
},
"response": {
"content": [
{
"type": "text",
"text": "Example document"
}
],
"isError": false
}
},
"metadata": {
"payload_visibility": "owner_only",
"payload_mode": "full",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "847b09d001c35de9aa7786ef39133acc",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 403,
"duration_ms": 42,
"is_error": true,
"error_message": "Provider refused access"
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "44d238c427d65a6e81227b89f6326010",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 502,
"duration_ms": 42,
"is_error": true,
"error_message": "Provider unavailable"
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "3fb6754d7f6450a4a7cb828ac18983f0",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": {
"tool": "search",
"arguments": {
"email": "[REDACTED]"
}
},
"response": {
"content": "[REDACTED]"
}
},
"metadata": {
"payload_visibility": "workspace_redacted",
"payload_mode": "full",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "2a138f759f2e54399538e929675a8d3e",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"result": {
"status_code": 200,
"error_message": null
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "fc09d487dd7b56a79fbb615d0b2ccbbe",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": true,
"error_message": "Tool returned an error"
},
"payload": {
"request": null,
"response": null
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "metadata",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
{
"schema_version": 1,
"source": "hodor",
"id": "24b4a4f1ab41541fb83a00971bab2810",
"occurred_at": "2026-08-14T11:01:00+00:00",
"kind": "mcp_tool_call",
"action": "/mcp/tools/search",
"workspace": {
"id": 11111111,
"name": "Example Organization"
},
"actor": {
"profile_id": 33333333,
"email": "alice@example.com",
"name": "Alice"
},
"agent": {
"id": 20,
"name": "Research assistant",
"description": "Search approved documents"
},
"provider": "notion",
"contract": {
"id": 40,
"label": "Research access",
"description": "Read approved knowledge sources"
},
"result": {
"status_code": 200,
"duration_ms": 42,
"is_error": false,
"error_message": null
},
"payload": {
"request": {
"tool": "search",
"arguments": {
"query": "example project"
}
},
"response": {
"_truncated": true,
"_bytes": 4814,
"preview": "{\"content\":\"Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Exam"
}
},
"metadata": {
"payload_visibility": "workspace_visible",
"payload_mode": "truncated",
"source_activity_id": null,
"extras": {
"workspace_provider_catalog_id": 50,
"tool_catalog_provider_id": 60
}
}
}
Event Categories
The following table lists the data source offered by this integration.
| Data Source | Description |
|---|---|
API monitoring |
AI agent tool calls through the Hodor MCP gateway, including the actor, target provider and outcome. |
Application logs |
Hodor agent, workspace and contract context associated with each tool call. |
In details, the following table denotes the type of events produced by this integration.
| Name | Values |
|---|---|
| Kind | event |
| Category | web |
| Type | access |
Transformed Events Samples after Ingestion
This section demonstrates how the raw logs will be transformed by our parsers. It shows the extracted fields that will be available for use in the built-in detection rules and hunting activities in the events page. Understanding these transformations is essential for analysts to create effective detection mechanisms with custom detection rules and to leverage the full potential of the collected data.
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"f8dd5cc8a79054ff93ac8c56330f54bc\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"do_not_store\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "f8dd5cc8a79054ff93ac8c56330f54bc",
"kind": "mcp_tool_call",
"payload_mode": "full",
"payload_visibility": "do_not_store",
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"6cd3f10eaace5a309c50b7070baa9515\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":null},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "6cd3f10eaace5a309c50b7070baa9515",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"alice@example.com"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"id": "33333333",
"name": "alice@example.com"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"beb97f8c282a5a34b113bb3cef2b2af6\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"query\":\"example project\"}},\"response\":{\"content\":[{\"type\":\"text\",\"text\":\"Example document\"}],\"isError\":false}},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "beb97f8c282a5a34b113bb3cef2b2af6",
"kind": "mcp_tool_call",
"payload_mode": "full",
"payload_visibility": "workspace_visible",
"request": {
"arguments": {
"query": "example project"
},
"tool": "search"
},
"response": {
"content": [
{
"text": "Example document",
"type": "text"
}
],
"isError": false
},
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"1da55f15c70e54fcb2cc410482c6a671\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":70,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "1da55f15c70e54fcb2cc410482c6a671",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"source_activity_id": "70",
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"7924f9e446d25aacacc229fe298d5ebe\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":500,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Gateway execution failed\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "failure",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"error": {
"message": "Gateway execution failed"
},
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "7924f9e446d25aacacc229fe298d5ebe",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"status_code": 500
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"5ef2f684612757578cf847887ffa1746\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "5ef2f684612757578cf847887ffa1746",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"abc1e1cb795f5bd19da77dce3adf4eeb\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":null},\"actor\":{\"profile_id\":null,\"email\":null,\"name\":null},\"agent\":{\"id\":null,\"name\":null,\"description\":null},\"provider\":null,\"contract\":{\"id\":null,\"label\":null,\"description\":null},\"result\":{\"status_code\":200,\"duration_ms\":0,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 0,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"event_id": "abc1e1cb795f5bd19da77dce3adf4eeb",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"ff2d3bd16b095f6b8c6cdc1d0063e4a6\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"query\":\"example project\"}},\"response\":{\"content\":[{\"type\":\"text\",\"text\":\"Example document\"}],\"isError\":false}},\"metadata\":{\"payload_visibility\":\"owner_only\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "ff2d3bd16b095f6b8c6cdc1d0063e4a6",
"kind": "mcp_tool_call",
"payload_mode": "full",
"payload_visibility": "owner_only",
"request": {
"arguments": {
"query": "example project"
},
"tool": "search"
},
"response": {
"content": [
{
"text": "Example document",
"type": "text"
}
],
"isError": false
},
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"847b09d001c35de9aa7786ef39133acc\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":403,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Provider refused access\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "failure",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"error": {
"message": "Provider refused access"
},
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "847b09d001c35de9aa7786ef39133acc",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"status_code": 403
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"44d238c427d65a6e81227b89f6326010\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":502,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Provider unavailable\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "failure",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"error": {
"message": "Provider unavailable"
},
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "44d238c427d65a6e81227b89f6326010",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"status_code": 502
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"3fb6754d7f6450a4a7cb828ac18983f0\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"email\":\"[REDACTED]\"}},\"response\":{\"content\":\"[REDACTED]\"}},\"metadata\":{\"payload_visibility\":\"workspace_redacted\",\"payload_mode\":\"full\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "3fb6754d7f6450a4a7cb828ac18983f0",
"kind": "mcp_tool_call",
"payload_mode": "full",
"payload_visibility": "workspace_redacted",
"request": {
"arguments": {
"email": "[REDACTED]"
},
"tool": "search"
},
"response": {
"content": "[REDACTED]"
},
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"2a138f759f2e54399538e929675a8d3e\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"result\":{\"status_code\":200,\"error_message\":null}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"kind": "event",
"module": "hodor",
"outcome": "unknown",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"event_id": "2a138f759f2e54399538e929675a8d3e",
"kind": "mcp_tool_call",
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"fc09d487dd7b56a79fbb615d0b2ccbbe\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":true,\"error_message\":\"Tool returned an error\"},\"payload\":{\"request\":null,\"response\":null},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"metadata\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "failure",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"error": {
"message": "Tool returned an error"
},
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "fc09d487dd7b56a79fbb615d0b2ccbbe",
"kind": "mcp_tool_call",
"payload_mode": "metadata",
"payload_visibility": "workspace_visible",
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
{
"message": "{\"schema_version\":1,\"source\":\"hodor\",\"id\":\"24b4a4f1ab41541fb83a00971bab2810\",\"occurred_at\":\"2026-08-14T11:01:00+00:00\",\"kind\":\"mcp_tool_call\",\"action\":\"/mcp/tools/search\",\"workspace\":{\"id\":11111111,\"name\":\"Example Organization\"},\"actor\":{\"profile_id\":33333333,\"email\":\"alice@example.com\",\"name\":\"Alice\"},\"agent\":{\"id\":20,\"name\":\"Research assistant\",\"description\":\"Search approved documents\"},\"provider\":\"notion\",\"contract\":{\"id\":40,\"label\":\"Research access\",\"description\":\"Read approved knowledge sources\"},\"result\":{\"status_code\":200,\"duration_ms\":42,\"is_error\":false,\"error_message\":null},\"payload\":{\"request\":{\"tool\":\"search\",\"arguments\":{\"query\":\"example project\"}},\"response\":{\"_truncated\":true,\"_bytes\":4814,\"preview\":\"{\\\"content\\\":\\\"Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Exam\"}},\"metadata\":{\"payload_visibility\":\"workspace_visible\",\"payload_mode\":\"truncated\",\"source_activity_id\":null,\"extras\":{\"workspace_provider_catalog_id\":50,\"tool_catalog_provider_id\":60}}}",
"event": {
"action": "/mcp/tools/search",
"category": [
"web"
],
"dataset": "hodor.activity",
"duration": 42000000,
"kind": "event",
"module": "hodor",
"outcome": "success",
"type": [
"access"
]
},
"@timestamp": "2026-08-14T11:01:00Z",
"hodor": {
"agent": {
"description": "Search approved documents",
"id": "20",
"name": "Research assistant"
},
"catalog_provider": {
"id": "60"
},
"connector": {
"id": "50"
},
"contract": {
"description": "Read approved knowledge sources",
"id": "40",
"label": "Research access"
},
"event_id": "24b4a4f1ab41541fb83a00971bab2810",
"kind": "mcp_tool_call",
"payload_mode": "truncated",
"payload_visibility": "workspace_visible",
"request": {
"arguments": {
"query": "example project"
},
"tool": "search"
},
"response": {
"_bytes": 4814,
"_truncated": true,
"preview": "{\"content\":\"Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Example Exam"
},
"schema_version": 1,
"status_code": 200
},
"observer": {
"product": "Hodor",
"type": "proxy",
"vendor": "Hodor"
},
"organization": {
"id": "11111111",
"name": "Example Organization"
},
"related": {
"user": [
"Alice"
]
},
"service": {
"name": "notion"
},
"user": {
"email": "alice@example.com",
"full_name": "Alice",
"id": "33333333",
"name": "Alice"
}
}
Extracted Fields
The following table lists the fields that are extracted, normalized under the ECS format, analyzed and indexed by the parser. It should be noted that infered fields are not listed.
| Name | Type | Description |
|---|---|---|
@timestamp |
date |
Date/time when the event originated. |
error.message |
match_only_text |
Error message. |
event.action |
keyword |
The action captured by the event. |
event.category |
keyword |
Event category. The second categorization field in the hierarchy. |
event.dataset |
keyword |
Name of the dataset. |
event.duration |
long |
Duration of the event in nanoseconds. |
event.kind |
keyword |
The kind of the event. The highest categorization field in the hierarchy. |
event.module |
keyword |
Name of the module this data is coming from. |
event.outcome |
keyword |
The outcome of the event. The lowest level categorization field in the hierarchy. |
event.type |
keyword |
Event type. The third categorization field in the hierarchy. |
hodor.agent.description |
keyword |
Description of the AI agent at the time of the call. |
hodor.agent.id |
keyword |
Identifier of the AI agent identity in Hodor. |
hodor.agent.name |
keyword |
Name of the AI agent at the time of the call. |
hodor.catalog_provider.id |
keyword |
Identifier of the Hodor catalog provider used for the call. |
hodor.connector.id |
keyword |
Identifier of the Hodor workspace connector slot used for the call. |
hodor.contract.description |
keyword |
Description of the Hodor contract at the time of the call. |
hodor.contract.id |
keyword |
Identifier of the Hodor contract governing the agent's access. |
hodor.contract.label |
keyword |
Name of the Hodor contract at the time of the call. |
hodor.event_id |
keyword |
Original Hodor event identifier, preserved across delivery retries and replays. |
hodor.kind |
keyword |
Hodor activity kind, such as mcp_tool_call. |
hodor.payload_mode |
keyword |
External payload mode: metadata, truncated or full. |
hodor.payload_visibility |
keyword |
Internal payload visibility selected in Hodor. |
hodor.request |
object |
Tool request forwarded according to the configured Hodor payload mode and visibility. |
hodor.response |
object |
Tool response forwarded according to the configured Hodor payload mode and visibility. |
hodor.schema_version |
long |
Version of the Hodor delivery envelope. |
hodor.source_activity_id |
keyword |
Source activity identifier for a historical import; absent on live events. |
hodor.status_code |
long |
Fault-attributing status recorded by Hodor; this can differ from the upstream HTTP status. |
observer.product |
keyword |
The product name of the observer. |
observer.type |
keyword |
The type of the observer the data is coming from. |
observer.vendor |
keyword |
Vendor name of the observer. |
organization.id |
keyword |
Unique identifier for the organization. |
organization.name |
keyword |
Organization name. |
service.name |
keyword |
Name of the service. |
user.email |
keyword |
User email address. |
user.full_name |
keyword |
User's full name, if available. |
user.id |
keyword |
Unique identifier of the user. |
user.name |
keyword |
Short name or login of the user. |
For more information on the Intake Format, please find the code of the Parser, Smart Descriptions, and Supported Events here.