Validate and Troubleshoot MSSP Sync
use this guide to validate client to central data propagation and troubleshoot common mssp sync issues if configuration is incomplete, start with configure ai soc for mssp docid\ azfpz c qlu3elvszkllw case management and reporting aggregates use the ingest record from client webhook threat intelligence artifact cache records use the central api ( privatetoken and central tiac app id ) perform a standard sync validation in the client tenant, ingest or update a known test record confirm the client record completes normal ai soc processing confirm ai soc mssp client configuration includes the correct central webhook url , central tenant id , client name , and central tiac app id values in the central tenant, search central case management for the same tracking context and confirm client name is populated verify record content and status were propagated in threat intelligence artifact cache , verify the related tiac record was created or updated repeat with a second case update to confirm incremental webhook propagation after the reporting job runs, search central soc reporting for a record with the same client name troubleshooting matrix symptom likely cause resolution no central case record for client update incorrect webhook url or tenant identifier, or webhook not enabled recheck central webhook url , central tenant id , and the central ingest record from client sensor authentication failures during case or reporting sync basic auth mismatch between ai soc mssp central sync authorization and the central ingestion webhook align authorization username and password in both tenants and retest central case exists but client name is empty or wrong client name not set or not unique in ai soc mssp client configuration set a unique client name and send another case update ti cache records are missing incorrect central tiac app id or invalid privatetoken recheck central tiac app id and replace privatetoken in ai soc mssp central sync update tia record fails with key errors tia central sync fields is not included on the client threat intelligence application complete include tia central sync fields in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw client tia enrichment still runs when the observable is already in central tiac the enrich tia record (create) flow is still enabled in core playbook ai soc main complete disable enrich tia record in ai soc main in configure ai soc for mssp docid\ azfpz c qlu3elvszkllw api based tiac updates fail invalid or expired privatetoken replace privatetoken in ai soc mssp central sync and verify admin permissions on the central tenant no central reporting records reporting playbooks not running, or webhook auth mismatch confirm ai soc mssp reporting and soc reporting sync in the client tenant, then recheck webhook credentials central soc reporting looks empty on sunday current week filter vs utc timestamps on central soc reporting workspace dashboards, change the current week date filter to a custom range, or check after sunday in your timezone see work with central soc reporting in use ai soc for mssp central hero ai or core client workflows fail incomplete ai soc tenant configuration recheck ai soc tenant configuration (including private token ) only some client tenants sync client specific configuration drift compare working and failing tenant asset values and normalize installer prompts to overwrite get application fields schema expected conflict between core and client extension for this unused core component accept the overwrite do not skip or deselect the component see accept get application fields schema overwrite in getting started for mssp docid\ ivvy6gxajwc34xvmnnqc configuration audit checklist use configure ai soc for mssp docid\ azfpz c qlu3elvszkllw as the full configuration reference confirm at minimum client tenant ai soc tenant configuration is configured for core ai soc operations (including private token ) tia central sync fields is included on the client threat intelligence application ( support tab, threat intelligence metadata ) enrich tia record (create) flow is disabled in the client ai soc main playbook ai soc mssp client configuration has complete and current values ( client name , central webhook url , central tenant id , and central tiac app id ) ai soc mssp central sync authorization values match the central ingestion webhook ai soc mssp central sync privatetoken is current and authorized for central tiac api operations central tenant ingest record from client webhook is enabled, reachable, and saved on catch records from client webhook basic auth values match client ai soc mssp central sync authorization values catch records from client , upsert central case management record , upsert central report record , and set requires re enrichment playbooks are present from install central case management , threat intelligence artifact cache , and central soc reporting are available for validation escalation guidance escalate when sync fails for all clients after credential or platform changes records propagate but critical fields (including client name ) are consistently incorrect central ingestion delays exceed your operational threshold when escalating, include client and central tenant names timestamp of test updates affected tracking ids which validation step failed (case webhook, tiac api, or reporting webhook)