AI Event Summary
- Last Updated: September 16, 2026
- 3 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
The AI Event Summary introduces a new interpretive layer that turns raw, technical event data into a clear, human-readable narrative directly in Event Detail. Instead of manually correlating flows, related events, and external intelligence, you can now generate a summary on demand, explaining what happened, why it matters, and what to do next. Once generated, the summary is stored with the event and remains available for later review.
The AI Event Summary can be generated from the AI summary tab in Event Detail. The content of the generated report is described on the Event Detail page. The number of AI summaries is limited by support tier and resets weekly on Sunday. The limit is shared across the entire Flowmon ADS instance and cannot be separated by individual users or tenants. This feature requires Flowmon ADS to have access to the Flowmon services portal. It leverages an LLM service operated within an isolated environment controlled by Progress. The AI Event Summary can be disabled in Settings > System Settings > General Settings > External Services.
When you click Generate, Flowmon ADS sends event data, related events, method configuration, and flow data for processing. Sensitive data is pseudonymized based on the settings in Settings > System Settings > General Settings > Threat hub. For pseudonymizing IP addresses and ranges, you can select a filter (the default setting is 'LAN'). For domains, you can specify your own comma-separated list, with support for the '*' wildcard character. Private IP addresses are pseudonymized regardless of the selected filter. Your public IP addresses should be included in the selected filter. The general recommendation is to include your public IP addresses in the "LAN" filter and keep it as the default setting. For pseudonymization, a one-way hashing function (MD5 with device-specific salt) is used together with local mapping, which is never shared externally and is only used to re-substitute the hashed values in the generated report after it is returned from the LLM.
Before the AI Event Summary is generated, Threat Hub enriches the submitted data using RAG (Retrieval-Augmented Generation) technology. This enrichment draws on relevant information from the internal knowledge base and external sources (including reputation and metadata for external IP addresses) supplementing the data already available in Flowmon ADS, so that the resulting summary is as accurate and well-contextualized as possible.
Example of data sent before and after pseudonymization
For an example of non-pseudonymized and pseudonymized data, refer to the following section: Threat hub settings.
How customer data is protected and processed
Customer data in the LLM service is processed using security and privacy controls in line with applicable data protection regulations (including GDPR).
- Purpose-limited use: Data is only processed to deliver the service and is not used to train or improve AI models.
- Data location: Processing occurs in Microsoft Azure (for example, East US) with contractual safeguards that help provide EU-level protection.
- GDPR compliance: Microsoft acts as a data processor; customers remain data controllers. Processing is governed by the Data Processing Agreement (DPA) and Standard Contractual Causes (SCCs), including for cross-border transfers.
- Security measures: Encryption in transit and at rest and strict access controls help reduce the risk of unauthorized access.
- Confidentiality: Data is not shared with other customers and remains isolated per customer.
- Retention: Data is only retained for the minimal time required to generate and deliver the AI Event Summary.
- AI safeguards: Data minimization and monitoring help reduce AI-related risks.