Anthropic Excessive Chat Creation
Description
Detects an unusually high number of Claude chat creation events for the same user email within a 24-hour period. Burst chat creation can indicate automated LLM abuse, resource hijacking to burn organizational quotas, or scripted workflows used to stage many parallel conversations for data processing or prompt-injection campaigns.
Query · esql
from logs-anthropic.audit-*
| where
data_stream.dataset == "anthropic.audit" and
event.action == "claude_chat_created" and
event.outcome == "success" and
user.email is not null
| stats
Esql.event_count = count(*),
Esql.event_id_values = values(event.id),
Esql.anthropic_audit_claude_chat_id_values = values(anthropic.audit.claude_chat_id),
Esql.anthropic_audit_claude_project_id_values = values(anthropic.audit.claude_project_id),
Esql.source_ip_values = values(source.ip),
Esql.user_agent_original_values = values(user_agent.original),
Esql.anthropic_audit_actor_type_values = values(anthropic.audit.actor.type),
Esql.user_id_values = values(user.id),
Esql.timestamp_first_seen = min(@timestamp),
Esql.timestamp_last_seen = max(@timestamp)
by user.email
| where Esql.event_count >= 20
| keep user.email, Esql.*
Investigation fields
Pivot points the source recommends for triage.
user.emailEsql.event_countEsql.event_id_valuesEsql.anthropic_audit_claude_chat_id_valuesEsql.anthropic_audit_claude_project_id_valuesEsql.source_ip_valuesEsql.user_agent_original_valuesEsql.anthropic_audit_actor_type_valuesEsql.user_id_valuesEsql.timestamp_first_seenEsql.timestamp_last_seen
Known false positives
- Power users, automation engineers, or evaluation scripts that create many short-lived chats during testing can exceed the threshold without malicious intent.
Analyst notes
Investigating Anthropic Excessive Chat Creation
One mailbox created a large burst of Claude chats in 24 hours — fits automation, quota burn, or scripted parallel workflows.
True-positive signals: scripting UA (curl/python/Go-http-client), many distinct project IDs, concurrent file uploads or deletions, or follow-on exports. False-positive signals: known eval/load-test accounts, onboarding templates from one admin with browser UA and no data-access follow-ons.
Possible investigation steps
- Prefer alerts with scripting UA and/or many distinct project IDs over browser UA confined to one known project.
- Correlate with high file uploads, chat deletions, or org data export from the same email in the same window.
False positive analysis
- Known eval/load-test seats and onboarding template creators with browser UA and no data-access follow-ons are FP.
Response and remediation
- When TP signals hold: revoke sessions, review project membership, and apply rate limits or policy changes for the actor.