Validate and Troubleshoot MSSP Sync
Use this guide to validate client-to-central data propagation and troubleshoot common MSSP sync issues. If configuration is incomplete, start with Configure AI SOC for MSSPConfigure AI SOC for MSSP.
Case Management and reporting aggregates use the Ingest Record from Client webhook. Threat Intelligence Artifact Cache records use the central API (PrivateToken and Central_TIAC_App_ID).
Perform a Standard Sync Validation
- In the client tenant, ingest or update a known test record.
- Confirm the client record completes normal AI SOC processing.
- Confirm AI_SOC_MSSP_Client_Configuration includes the correct Central_Webhook_URL, Central_Tenant_ID, Client_Name, and Central_TIAC_App_ID values.
- In the central tenant, search Central Case Management for the same tracking context and confirm Client_Name is populated.
- Verify record content and status were propagated.
- In Threat Intelligence Artifact Cache, verify the related TIAC record was created or updated.
- Repeat with a second case update to confirm incremental webhook propagation.
- After the reporting job runs, search Central SOC Reporting for a record with the same Client_Name.
Troubleshooting Matrix
Symptom | Likely cause | Resolution |
|---|---|---|
No central case record for client update | Incorrect webhook URL or tenant identifier, or webhook not enabled | Recheck Central_Webhook_URL, Central_Tenant_ID, and the central Ingest Record from Client sensor |
Authentication failures during case or reporting sync | Basic auth mismatch between AI_SOC_MSSP_Central_Sync Authorization and the central ingestion webhook | Align Authorization username and password in both tenants and retest |
Central case exists but Client_Name is empty or wrong | Client_Name not set or not unique in AI SOC MSSP Client Configuration | Set a unique Client_Name and send another case update |
TI cache records are missing | Incorrect Central_TIAC_App_ID or invalid PrivateToken | Recheck Central_TIAC_App_ID and replace PrivateToken in AI_SOC_MSSP_Central_Sync |
Update_TIA_Record fails with key errors | TIA Central Sync Fields is not included on the client Threat Intelligence application | Complete Include TIA Central Sync Fields in Configure AI SOC for MSSPConfigure AI SOC for MSSP |
Client TIA enrichment still runs when the observable is already in central TIAC | The Enrich TIA Record (Create) flow is still enabled in Core playbook AI SOC Main | Complete Disable Enrich TIA Record in AI SOC Main in Configure AI SOC for MSSPConfigure AI SOC for MSSP |
API-based TIAC updates fail | Invalid or expired PrivateToken | Replace PrivateToken in AI_SOC_MSSP_Central_Sync and verify admin permissions on the central tenant |
No central reporting records | Reporting playbooks not running, or webhook auth mismatch | Confirm AI SOC MSSP - Reporting and SOC Reporting Sync in the client tenant, then recheck webhook credentials |
Central SOC Reporting looks empty on Sunday | Current week filter vs UTC timestamps | On Central SOC Reporting Workspace dashboards, change the Current week date filter to a custom range, or check after Sunday in your timezone. See Work With Central SOC Reporting in Use AI SOC for MSSP Central. |
Hero AI or core client workflows fail | Incomplete AI SOC Tenant Configuration | Recheck AI SOC Tenant Configuration (including Private_Token) |
Only some client tenants sync | Client-specific configuration drift | Compare working and failing tenant asset values and normalize |
Installer prompts to overwrite Get Application Fields Schema | Expected conflict between Core and Client Extension for this unused Core component | Accept the overwrite. Do not skip or deselect the component. See Accept Get Application Fields Schema overwrite in Getting Started for MSSPGetting Started for MSSP |
Configuration Audit Checklist
Use Configure AI SOC for MSSPConfigure AI SOC for MSSP as the full configuration reference. Confirm at minimum:
Client Tenant
- AI SOC Tenant Configuration is configured for core AI SOC operations (including Private_Token).
- TIA Central Sync Fields is included on the client Threat Intelligence application (Support tab, Threat Intelligence Metadata).
- Enrich TIA Record (Create) flow is disabled in the client AI SOC Main playbook.
- AI_SOC_MSSP_Client_Configuration has complete and current values (Client_Name, Central_Webhook_URL, Central_Tenant_ID, and Central_TIAC_App_ID).
- AI_SOC_MSSP_Central_Sync Authorization values match the central ingestion webhook.
- AI_SOC_MSSP_Central_Sync PrivateToken is current and authorized for central TIAC API operations.
Central Tenant
- Ingest Record from Client webhook is enabled, reachable, and saved on Catch Records from Client.
- Webhook basic auth values match client AI_SOC_MSSP_Central_Sync Authorization values.
- Catch Records from Client, Upsert Central Case Management Record, Upsert Central Report Record, and Set Requires Re-Enrichment playbooks are present from install.
- Central Case Management, Threat Intelligence Artifact Cache, and Central SOC Reporting are available for validation.
Escalation Guidance
Escalate when:
- Sync fails for all clients after credential or platform changes.
- Records propagate but critical fields (including Client_Name) are consistently incorrect.
- Central ingestion delays exceed your operational threshold.
When escalating, include:
- Client and central tenant names.
- Timestamp of test updates.
- Affected tracking IDs.
- Which validation step failed (case webhook, TIAC API, or reporting webhook).