Configure AI SOC for MSSP
use this guide to configure client and central tenants after you install the ai soc for mssp solution layers for install order and first validation, see getting started for mssp docid\ ivvy6gxajwc34xvmnnqc choose your path if you are configuring go to core client tenant pat asset configure the client tenant /#configure the client tenant client tia applet for central ti sync include tia central sync fields /#include tia central sync fields disable core tia enrichment on the client disable enrich tia record in ai soc main /#disable enrich tia record in ai soc main central ingestion webhook configure the central tenant /#configure the central tenant mssp sync assets on a client tenant configure mssp client sync assets /#configure mssp client sync assets credential and asset overview asset or credential tenant purpose ai soc tenant configuration client pat based swimlane api access for hero ai flows (from ai soc core solution ) field private token ai soc mssp client configuration client client name , central webhook url , central tenant id , and central tiac app id (from ai soc mssp client extension ) ai soc mssp central sync client webhook basic auth for case and reporting sync, and privatetoken for central tiac api calls (from ai soc mssp client extension ) ingest record from client webhook central receives case management records and soc reporting aggregates from client tenants required for case and reporting sync ai soc tenant configuration comes from ai soc core solution mssp sync assets come from ai soc mssp client extension open each by its title under orchestration β assets privatetoken on ai soc mssp central sync is an admin personal access token authorized for the central tenant it is used to create and update full threat intelligence artifact cache records over the api it is not used to post case or report payloads; those use the webhook and authorization username and password it is also not the same value as private token on the client ai soc tenant configuration asset configure the client tenant complete these steps in each client tenant after ai soc core solution and ai soc mssp client extension are installed ai soc tenant configuration open ai soc tenant configuration under orchestration β assets configure base url client swimlane host account id swimlane account identifier tenant id client tenant identifier private token valid swimlane pat that belongs to an orchestrator or administrator in the client tenant save and activate the asset when required for additional core asset detail, see configure custom assets docid\ qdckijlols 7dwzjgrbqk confirm client mssp reporting confirm the ai soc mssp reporting application and ai soc mssp reporting workspace are installed with ai soc mssp client extension confirm ai soc mssp reporting and soc reporting sync playbooks are present reporting sync uses the same central webhook as case sync; it is required for central soc reporting open the reporting workspace once to verify default dashboards load for your rbac role include tia central sync fields the ai soc mssp client extension includes the tia central sync fields applet add it to the client threat intelligence application so central tiac create and update can write the required metadata fields if this applet is missing, ai soc mssp central sync can fail on update tia record with key errors in the client tenant , open application builder for the threat intelligence application select the support layout tab from applet display , add tia central sync fields to the threat intelligence metadata section save the application repeat this step in every client tenant after you install ai soc mssp client extension disable enrich tia record in ai soc main in each client tenant , disable the enrich tia record (create) flow in the core playbook ai soc main if this flow stays enabled, the client tenant enriches tia observables even when a matching record already exists in central threat intelligence artifact cache that duplicate enrichment defeats the purpose of the central ti cache in the client tenant , open orchestration β playbooks open ai soc main (from ai soc core solution ) select the enrich tia record action (create) disable the flow save the playbook disable the enrich tia record (create) flow do not disable the ai soc main playbook the ai soc mssp client extension checks central threat intelligence artifact cache first client enrichment is reserved for cache miss, stale data, or requires re enrichment , not for this core create flow repeat this step in every client tenant after you install ai soc core solution and ai soc mssp client extension configure the central tenant complete these steps in the central tenant after ai soc mssp central solution is installed central ingestion webhook this webhook is required client case record monitoring and soc reporting sync both post to it navigate to orchestration β playbooks open catch records from client (the playbook that contains the ingest record from client webhook sensor) select the ingest record from client sensor under authentication, set username and password for incoming client sync requests the package may ship with a default username until you change it; use credentials you will copy to each client ai soc mssp central sync asset enable the sensor if it is disabled after install copy the webhook url from the sensor configuration save the playbook record the webhook url, username, and password in your onboarding worksheet for additional client tenants the central mssp solution does not ship separate central configuration assets after install, the only required central configuration is ingest record from client webhook authentication playbooks, workspaces, and applications are present from the package; you do not configure them beyond enabling the webhook sensor and confirming they load after install, these central objects are available without further configuration playbooks catch records from client , upsert central case management record , upsert central report record , set requires re enrichment workspaces ai soc mssp central , central soc reporting workspace , usage statistics workspace applications central case management , threat intelligence artifact cache , central soc reporting , usage statistics configure mssp client sync assets complete these steps in each client tenant after the central ingestion webhook is configured open assets under orchestration configure ai soc mssp client configuration ( ai soc mssp client configuration ) field what to enter client name unique mssp client or tenant display name this value is stamped on central case and reporting records so you can filter by client central webhook url url of the central ingest record from client webhook central tenant id central tenant identifier central tiac app id central threat intelligence artifact cache application identifier configure ai soc mssp central sync ( ai soc mssp central sync ) under authorization , set username and password to match the central ingest record from client webhook credentials set privatetoken to a valid swimlane admin personal access token for central api operations (tiac create and update) save and verify both mssp assets are active find the central ti cache application id to find central tiac app id in the central tenant , open threat intelligence artifact cache copy the application identifier from the application url or application settings (format varies by environment) enter that value in the client ai soc mssp client configuration asset you can also use the swimlane api to retrieve the application identifier configuration checklist client tenant ai soc tenant configuration is configured (including private token ) tia central sync fields is included on the client threat intelligence application support tab, under threat intelligence metadata enrich tia record (create) flow is disabled in the client ai soc main playbook ai soc mssp client configuration and ai soc mssp central sync are active client name is set and matches how you identify the customer in central central case management and central soc reporting central webhook url , central tenant id , and central tiac app id are complete central tenant ingest record from client webhook is enabled with known credentials central case management , threat intelligence artifact cache , and central soc reporting are accessible after install next steps if you need to go to install solution layers and run first validation getting started for mssp docid\ ivvy6gxajwc34xvmnnqc add another customer tenant onboard a client tenant docid\ fgkw7if8vsr9 hchdexus work day to day in the central tenant use ai soc for mssp central docid\ gualyzlqa 7acfkpszhcq troubleshoot sync issues validate and troubleshoot mssp sync docid\ qyesknwk rnsc1w1uax d