Agentic SOC is a built-in threat detection and response module in Security Center. It provides unified log analysis, automated incident response, and out-of-the-box threat detection rules. This topic describes how to choose a billing method and activate the service.
Purchase planning
Choose a billing method
You can flexibly combine billing methods for log ingestion traffic and log storage capacity based on your needs. For example, use subscription for log ingestion traffic and pay-as-you-go for Log Management.
|
Billing method |
Best for |
Billing items |
|
Subscription |
Predictable resource usage cycles. Stable business scenarios. Long-term resource needs. |
Log Ingestion Traffic: Tiered pricing, minimum 100 GB/day, step size 100 GB/day. Log Storage Capacity: Minimum 1,000 GB, step size 1,000 GB. Intelligent Usage Analysis: Must match Log Ingestion Traffic. Number of Managed Instances: Minimum 10 instances/month, step size 10 instances/month. |
|
Pay-as-you-go |
Unpredictable resource usage cycles. Highly variable traffic. |
Log Ingestion Traffic: Tiered cumulative billing based on actual daily ingestion, minimum 1 GB. Intelligent Usage Analysis: Billed by actual analysis usage (GB). Number of Managed Instances: Billed by actual Agent instance invocations. Log Management: Billed by daily cumulative storage, minimum 1 TB. |
Choose a service
Agentic SOC provides two service tiers. Compare the following sections to determine which tier meets your requirements.
-
Agentic SOC (Basic): Rule-based threat detection and response with preset playbooks and lightweight AI models.
-
Security Operations Agent: An advanced tier built on Agentic SOC. Uses a Multi-Agent architecture powered by large-scale AI models for autonomous incident investigation, threat detection, and response coordination.
Intelligence level differences
|
Dimension |
Agentic SOC (Basic) |
Security Operations Agent |
|
Positioning |
Tool-assisted with limited intelligence |
Digital security expert, 24/7 digital workforce |
|
Driving method |
Rule-based and feature-driven with lightweight/edge models |
Semantic awareness and dynamic reasoning with large-scale models |
|
Core logic |
Preset, static, linear playbooks with partial lightweight model capabilities |
Goal-driven autonomous closed loop with Multi-Agent architecture on top of Agentic SOC |
|
Extensibility |
Limited by human FTE |
Highly automated with compute-scalable capacity |
AI Agent differences
For more information about Agents, see Security operations agents.
|
Dimension |
Agentic SOC (Basic) |
Security Operations Agent |
|
Security AI Assistant: product consultation, alert explanation, and incident summary |
Supported |
Supported |
|
Incident Investigation Agent: malicious web traffic tracing and analysis |
Not supported |
Supported |
|
Threat Detection Agent: incident generation, deep investigation, traceability analysis, and impact assessment |
Not supported |
Supported |
|
Response Coordination Agent: incident response and entity assessment |
Not supported |
Supported |
|
Security Report Agent: alert analysis reports, security operations reports, and incident investigation reports |
Incident investigation reports not supported. |
Supported |
Billing differences
|
Dimension |
Agentic SOC (Basic) |
Security Operations Agent |
|
Billing items |
Billed by Log Ingestion Traffic and Log Storage Capacity independently. Purchase each based on your needs. |
In addition to Agentic SOC billing items, also requires Intelligent Usage Analysis and Number of Managed Instances. |
Purchase steps
Subscription
-
Log on to the Security Center console.
-
On the Agentic SOC page, click Activate Subscription. On the Quick Purchase tab, Billing Method defaults to Subscription.
-
Click Create Service-linked Role to complete cloud service access authorization. Skip this step if you have already created the role.
After authorization, Security Center automatically creates the service-linked role AliyunServiceRoleForSasCloudSiem so that Agentic SOC can access resources in your other cloud services. For more information, see Service-linked roles for Security Center.
-
Select the service to purchase: Agentic SOC or Security Operations Agent. For the differences between these two services, see Choose a service.
-
Set the purchase quantity based on your selected service.
-
Agentic SOC: Billed by Log Ingestion Traffic and Log Storage Capacity independently. Purchase each based on your needs.
-
Security Operations Agent: In addition to Agentic SOC billing items, also requires Intelligent Usage Analysis and Number of Managed Instances.
-
Log ingestion traffic
-
Definition: The daily volume of logs ingested into Agentic SOC for analysis, measured in GB/day.
-
Sizing guidance: Estimate your required log ingestion traffic using one of these methods:
-
Based on existing Simple Log Service (SLS) capacity:
Log ingestion traffic (GB/day) = Log storage capacity / TTL
-
Log storage capacity is the storage used by the log sources you plan to ingest into Agentic SOC.
-
TTL is the log retention period.
-
-
Based on Events Per Second (EPS):
Log ingestion traffic (GB/day) = EPS × 86400 × SIZE / (1024 × 1024)
-
EPS is the number of raw log events ingested per second.
-
SIZE is the average log entry size, typically 3 KB to 7 KB.
-
-
-
Pricing: Tiered pricing. Minimum purchase: 100 GB/day. Step size: 100 GB/day. Pricing tiers (X = daily ingestion traffic):
X = 100 GB: CNY 3 per GB per day. 200 GB <= X < 9,999,999,999 GB: CNY 2.8 per GB per day.
Log storage capacity
-
Definition: The amount of log storage Agentic SOC uses to retain logs.
-
Sizing guidance: Allocate 120 GB per server, or use three times the storage capacity currently used by Security Center log analysis. For more information, see Log management.
-
Pricing: Minimum 1,000 GB. Step size: 1,000 GB. Price: CNY 500 per 1,000 GB per month.
Intelligent analysis flow
-
Definition: Required only when you purchase Security Operations Agent. Measures the AI analysis quota consumed by alert triage, incident investigation, traceability, attribution, and security report generation.
-
Sizing guidance: Does not support auto-filling. Must match your Log Ingestion Traffic purchase amount.
-
Pricing:
-
Minimum purchase: 100 GB/day. Auto-fill is not supported. Must match Log Ingestion Traffic.
-
Price: CNY 66.7 per 100 GB per day.
NoteUsage resets to zero at midnight every day. If exceeded, the system automatically throttles.
-
Onboarded assets
-
Definition: The count of instances managed by Security Operations Agent for cross-instance security operations and automated response.
-
Sizing guidance: Each invoked instance is counted. Instances include ECS, WAF, ALB, cross-cloud products, and on-premises security products.
-
Pricing:
-
Minimum purchase: 10 instances/month, step size: 10 instances/month.
-
CNY 10 per instance per month.
NoteEach instance is counted only once. Duplicates are automatically removed.
-
-
Choose whether to enable Access Policy.
-
If you select the access policy, Agentic SOC automatically ingests logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account after activation. For more information, see Recommended log ingestion policy.
-
If you do not select the access policy, no predefined ingestion settings are applied. After purchase, manually select log sources based on your needs. For instructions, see Product logs.
-
-
Review the Security Center Related Agreements, then click Order Now.
Pay-as-you-go
If you have already purchased log ingestion traffic using subscription, you cannot activate Agentic SOC on pay-as-you-go.
-
Log on to the Security Center console.
-
On the Agentic SOC page, click Activate Pay-as-you-go and select the services to activate.
-
Review the billing rule descriptions. Billing varies by activated service.
-
Billing method:
-
Agentic SOC: Billed by daily log ingestion traffic (GB) using tiered cumulative pricing. Daily cost is the sum of each tier.
ImportantThe minimum billing unit is 1 GB. Usage less than 1 GB is billed as 1 GB.
-
Security Operations Agent: In addition to tiered cumulative billing by daily log ingestion traffic (GB), the following billing items apply:
-
Intelligent Analysis Flow: Billed by the analysis usage (GB) consumed by the AI security agent for alert triage, incident investigation, traceability, attribution, and security report generation.
-
Onboarded Assets: Billed by the number of Agent instance invocations. Products such as ECS, WAF, ALB, cross-cloud products, and on-premises security vendor products are all counted as instances.
ImportantEach instance is counted only once. Duplicates are automatically removed.
-
-
-
Billing cycle: Billed by calendar day.
-
Price:
-
Log Ingestion Traffic: Tiered pricing by daily log ingestion traffic (GB).
Daily log ingestion traffic range
Price
Cost formula (Y = daily traffic in GB)
1–10 (GB/day)
CNY 15/GB
15 × Y (CNY)
11–50 (GB/day)
CNY 10/GB
15×10 + 10×(Y−10) (CNY)
51–100 (GB/day)
CNY 9/GB
15×10 + 10×40 + 9×(Y−50) (CNY)
>100 (GB/day)
CNY 8/GB
15×10 + 10×40 + 9×50 + 8×(Y−100) (CNY)
-
Intelligent Analysis Flow: CNY 1/GB/day.
-
Onboarded Assets: CNY 15 per instance per month.
-
-
-
Choose whether to enable One-click Ingestion.
-
If you select One-click Ingestion, Agentic SOC automatically ingests logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account after activation. For more information, see Recommended log ingestion policy.
After you enable the recommended log ingestion policy, the system automatically ingests the specified log types into Agentic SOC. Security Center generates a bill the next day based on your actual log ingestion volume.
-
If you do not enable One-click Ingestion, manually select log sources based on your needs. For instructions, see Product logs.
-
-
Click Activate and Authorize.
After this operation, Security Center automatically creates the service-linked role AliyunServiceRoleForSasCloudSiem so that Agentic SOC can access resources in your other cloud services. For more information, see Service-linked roles for Security Center.
Features available after activation
The features you can access depend on your billing method and which dimensions you purchased.
Subscription
|
Feature |
CTDR 1.0 |
CTDR 2.0 (Agentic SOC) |
|||
|
Log ingestion only |
Log ingestion + storage |
Log ingestion only |
Log storage only |
Log ingestion + storage |
|
|
Dashboard |
Not supported |
Supported |
Not supported |
Not supported |
Not supported |
|
Event Handling |
Supported |
Supported |
Supported |
Not supported |
Supported |
|
Alerts |
Supported |
Supported |
Supported. Custom Alert Analysis requires pay-as-you-go feature for full support. |
Not supported |
Supported |
|
Incident Response |
Supported |
Supported |
Supported |
Not supported |
Supported |
|
Response Rules |
Supported |
Supported |
Supported |
Not supported |
Supported |
|
Log Management |
Not supported |
Supported |
Security Center logs: Supported. Standardized logs: Only supports logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported. |
Security Center Logs: Supported. Standardized Log: Not supported. |
Supported |
|
Detection Rules |
Predefined: Supported; Custom: Not supported |
Supported |
Predefined: Supported. Custom: Only supports detection of logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported. |
Not supported |
Supported |
|
Integration Settings / Service Integration |
Supported |
Supported |
Supported |
Not supported |
Supported |
Pay-as-you-go
|
Feature |
CTDR 1.0 |
CTDR 2.0 (Agentic SOC) |
|
Dashboard |
Not supported |
Not supported |
|
Event Handling |
Supported |
Supported |
|
Alerts |
Supported |
Supported |
|
Incident Response |
Supported |
Supported |
|
Response Rules |
Supported |
Supported |
|
Log Management |
Not supported |
Security Center logs: Supported. Standardized logs: Only supports logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported. |
|
Detection Rules |
Predefined: Supported; Custom: Not supported |
Predefined: Supported. Custom: Only supports detection of logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported. |
|
Integration Settings / Service Integration |
Supported |
Supported |
Product ingestion
After activating Agentic SOC, ingest product logs to enable cross-resource alerting and unified log analysis. For instructions, see Product logs.
Unsubscribe
To disable Agentic SOC:
-
Subscription: Go to the order downgrade page. On the Order Downgrade tab, in the Agentic SOC section, set Purchase or Not to No. For instructions, see Upgrades and downgrades.
The exact refund amount is shown on the downgrade page. For details about refund disbursement, see Refund destinations.
-
Pay-as-you-go: On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the switch for Agentic SOC or Log Management.
-
No new charges accrue after you disable the service. Except for user-delivered logs, all data and configurations—including security alerts, security events, and ingestion settings—are deleted after 15 days.
-
After you turn off the Log Management switch, log delivery stops and the corresponding Logstore is deleted. Deleted log data cannot be recovered. Proceed with caution.
Appendix
Other purchase entry points
You can also purchase Agentic SOC on the Security Center purchase page or on the console Overview page. For Security Center edition selection and other service purchases, see Purchase and Unsubscribe from Security Center.
Subscription
On the Security Center purchase page, in the edition selection area select Value-added Services Only. In the Agentic SOC configuration area, set the purchase option to Agentic SOC. Configure Log Ingestion Traffic (minimum and step size: 100 GB/day) and Log Storage Capacity. Confirm the Service-linked Role status is Created, and select Enable Agentic SOC recommended product log ingestion policy.
Pay-as-you-go
-
Security Center purchase page
On the Security Center purchase page, set Billing Method to Pay-as-you-go (billed daily). In the Agentic SOC area, select Agentic SOC or Security Operations Agent. Confirm the Service-linked Role status is Created, and select the Access Policy option "Enable Agentic SOC recommended product log ingestion policy. After enabling, billing is based on actual usage."
-
Overview page
In the Pay-as-you-go Services area, find the Agentic SOC service item and enable its switch.
Recommended log ingestion policy
After you enable the recommended log ingestion policy, Agentic SOC automatically ingests logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account—no manual configuration required.
If your Security Center edition is Free Edition or Value-added Services Only, ActionTrail event logs are not ingested.
|
# |
Alibaba Cloud product |
Data source name |
Standardization rule name |
Standardization method |
Standardization category/structure |
Security capabilities |
|
1 |
Security Center |
DNS request logs |
Host DNS request log standardization rule |
Scan query |
Host logs - Process DNS request logs |
Predefined analysis rules, predefined playbooks |
|
2 |
Baseline logs |
Baseline log standardization rule |
Scan query |
Security logs - Host baseline logs |
Incident investigation and traceability, predefined playbooks |
|
|
3 |
Login flow logs |
Login flow log standardization rule |
Scan query |
Login logs - Host login logs |
Custom analysis rules, incident investigation and traceability, predefined playbooks |
|
|
4 |
Network connectivity logs |
Network connectivity log standardization rule |
Scan query |
Host logs - Process network outbound logs |
Predefined analysis rules, predefined playbooks |
|
|
5 |
Process startup logs |
Process startup log standardization rule |
Scan query |
Host logs - Process startup logs |
Predefined analysis rules, custom analysis rules, incident investigation and traceability, predefined playbooks |
|
|
6 |
Security alert logs |
Security alert log standardization rule |
Real-time consumption |
Security logs - Other alert logs |
Predefined playbooks |
|
|
7 |
Vulnerability logs |
Vulnerability log standardization rule |
Scan query |
Security logs - Vulnerability logs |
Incident investigation and traceability, predefined playbooks |
|
|
8 |
Web Application Firewall |
WAF alert logs |
WAF alert log standardization rule |
Real-time consumption |
Security logs - WAF alert logs |
Predefined analysis rules, custom analysis rules, predefined playbooks |
|
9 |
WAF full/block/block-and-observe logs |
WAF full/block/block-and-observe log standardization rule |
Real-time consumption |
Network logs - HTTP logs |
Predefined analysis rules, custom analysis rules, incident investigation and traceability, predefined playbooks |
|
|
10 |
Cloud Firewall |
Cloud Firewall alert logs |
Cloud Firewall alert log standardization rule |
Real-time consumption |
Security logs - Firewall alert logs |
Predefined analysis rules, custom analysis rules, predefined playbooks |
|
11 |
ActionTrail |
ActionTrail event logs |
ActionTrail event log standardization rule |
Real-time consumption |
Audit logs - Cloud platform operation audit logs |
Custom analysis rules, incident investigation and traceability |
Related documentation
-
To learn about Security Center editions and value-added service purchases, see Purchase and Unsubscribe from Security Center.
-
To understand Agentic SOC architecture, see Agentic SOC version comparison.
-
After activating Agentic SOC, ingest product logs. See Agentic SOC product ingestion.