Solutions and Applications
...
AI SOC Ingestion
Configure the Application After Import
complete the following steps after importing the ssp and before you use the widget add an application description the ai ingestion application has hero ai visibility turned on by default for hero ai to answer questions accurately about the application, the description must explain what the application contains and how it's used to add a description open the ai ingestion application and select app settings enter a description in the description field use the following as a starting point\ the ai ingestion (ai) application provides a guided workflow for building vendor specific alert ingestion components for the ai soc pipeline it stores records of ingestion configurations organized by vendor source save your changes assign workspace roles the ai ingestion workspace has no roles assigned by default to grant access go to the management tab, open workspaces , and then open ai ingestion workspace select edit and open the permissions tab use add roles to add the role(s) that should have access to this workspace, and set the appropriate permissions (read, update, and so on) for each role anyone with those roles assigned to them will have access to the ai ingestion application enable hero ai visibility for the vendor product field (optional) the vendor product field has hero ai visibility turned off by default to let hero ai query and filter by vendor open the ai ingestion application in application builder and select the vendor product field turn on visible to hero ai enter a field description, for example the name of the vendor or source system that submitted this record example values crowdstrike, splunk, palo alto save your changes view ingestion audit information the ai ingestion application includes an audit tab that displays the same fields described above (such as vendor product , api specification uploaded , and name of component(s) generated ) use the audit tab to review ingestion configuration and activity; no additional report configuration is required considerations keep the following in mind when you use the ai ingestion ssp connectors aren't included in ssps reconfigure any http assets or credentials after import the workflow has no stages configured on import it is enabled but empty configure stages and actions before use the application acronym is ai and the tracking id prefix is ai if you deploy multiple instances of this application, update the acronym and prefix to avoid id conflicts hero ai is required for ai assisted widget features if hero ai isn't enabled, you can still use the widget's manual path to select endpoints and configure components records, record history, and secure key store values aren't included in the ssp and aren't transferred on import related documentation docid\ ddizyeiqevgzg8ay0fcc5 β overview of the ai soc solution docid b7njxu5xnzyrjcngqg5j β install ai soc and configure ingestion playbooks docid b7njxu5xnzyrjcngqg5j β connect siem, edr, and other tools