Use AI SOC for MSSP Central
use this guide for day to day analyst and operations workflows in the central tenant after mssp sync is configured this page does not cover installing solution layers, configuring webhooks or assets, or onboarding a new client tenant choose your path if you need to go to configure webhooks, assets, or sync for client or central tenants configure ai soc for mssp docid\ azfpz c qlu3elvszkllw add another customer client tenant onboard a client tenant docid\ fgkw7if8vsr9 hchdexus fix missing or stale sync validate and troubleshoot mssp sync docid\ qyesknwk rnsc1w1uax d first mssp deployment getting started for mssp docid\ ivvy6gxajwc34xvmnnqc mssp overview ai soc for mssp docid\ euf wh3ljlamphbnkmvos daily workflow open the ai soc mssp central workspace review incoming and recently updated records in central case management filter by client name to inspect tenant specific workloads identify records requiring follow up with client soc teams review ti cache updates for frequently recurring observables open central soc reporting workspace for cross client aggregates use usage statistics to track workload and adoption across clients central reporting and dashboards use central applications and workspaces to monitor clients client tenants also have ai soc mssp reporting for local aggregates that sync to central where what to use central tenant central case management , threat intelligence artifact cache , central soc reporting , usage statistics , ai soc mssp central workspace, central soc reporting workspace each client tenant ai soc mssp reporting / ai soc mssp reporting workspace , and the analyst ai soc workspace from core reporting goal recommended view compare workload by client central case list filtered by client name track weekly and historical aggregates central soc reporting workspace spot recurring indicators across clients threat intelligence artifact cache searches and filters check tenant participation usage statistics by client for client tenant ai soc dashboards, analysts work in that client tenant see dashboards docid\ aayntc5rumve6m xru 0 in the ai soc solution guide work with central soc reporting a cron playbook in the client tenant writes aggregate records to ai soc mssp reporting soc reporting sync posts those records to the central ingest record from client webhook upsert central report record stores them in central soc reporting dashboards in central soc reporting workspace read that aggregate data report fields field what it stores report type cases , mttd , or mttr report span new or total timestamp 00 00 00 on the day the report job runs (utc) report criteria dimension for the aggregate (see the combinations below) criteria value value for that dimension (for example, critical) count / value the aggregate number client name client name from the client ai soc mssp client configuration asset the ai soc mssp soc reporting playbook writes these report type and report criteria combinations report type report criteria cases total, severity, ai verdict, threat intelligence verdict, mitre techniques, manual verdict, signal source, owner, closed by hero ai mttd signal source mttr signal source owner is written for the total span only all other cases criteria are written for both new and total new is the aggregate for the past week total is near full history (lookback of 9999 weeks) dashboard filters default to current week , except trend line reports central soc reporting β current week filter on sundays central soc reporting dashboards default to a current week filter (except trend lines) that filter uses your local timezone reporting timestamps are stored in utc at midnight on the day the weekly job runs on sundays, the current week filter can return no results even when data exists on central soc reporting workspace dashboards, change the current week date filter to a custom range that includes the report timestamps, or check again after sunday in your timezone new is the last week of aggregates; total is near full history work with central case management use central case management as the aggregate visibility layer task action review new client activity sort by create time and filter by client name track case progression monitor status and last update fields over time validate propagation compare key values between client and central records confirm client ownership verify client name on each central record key central record fields to monitor field type why it matters client name confirm source tenant and avoid cross client confusion client tracking identifier correlate central records back to client records quickly record status and last updated detect stale sync or delayed updates source record url jump directly to the originating client record for verification work with threat intelligence artifact cache central tiac records are full artifact records synced from the client tenant over the api, not webhook metadata comparing enrichment across clients assumes threat intelligence vendors are the same across client tenants open threat intelligence artifact cache search for observables linked to active central records confirm latest verdict and enrichment data are present track repeated indicators across multiple clients use cache history to detect stale or missing propagation tracking id gaps when observable is unique the observable field in threat intelligence artifact cache must remain unique do not remove that uniqueness constraint when observable is unique, tracking id numbers may not be assigned sequentially some id numbers may be skipped if the system encounters duplicate observable values during record creation this does not indicate data loss; skipped ids correspond to suppressed duplicate entries request client side re enrichment use this workflow when central ti cache data is stale, incomplete, or must be refreshed after a provider or policy change open the ti cache record in threat intelligence artifact cache use requires re enrichment when it appears on the record layout or task list save the record and confirm the re enrichment request is stored on the ti cache record in the client tenant, confirm the observable receives a fresh enrichment pass on the next automation cycle your deployment uses for mssp ti sync use usage statistics use usage statistics to monitor operational health across clients metric type what to watch volume record growth by client and by period activity client update frequency and sync cadence coverage which clients are actively sending records trend sustained increase or drop in central activity operational best practices standardize client name values to avoid duplicate or fragmented reporting views validate webhook and token configuration after every credential rotation (see configure ai soc for mssp docid\ azfpz c qlu3elvszkllw ) review a sample of records from each active client every day escalate repeated sync lag quickly to prevent stale central visibility on sundays, if central soc reporting looks empty, change the current week date filter on central soc reporting workspace dashboards to a custom range before treating it as a sync failure