Purchase and activate Agentic SOC

更新时间:
复制 MD 格式

Agentic SOC is a built-in threat detection and response module in Security Center. It provides unified log analysis, automated incident response, and out-of-the-box threat detection rules. This topic describes how to choose a billing method and activate the service.

Purchase planning

Choose a billing method

You can flexibly combine billing methods for log ingestion traffic and log storage capacity based on your needs. For example, use subscription for log ingestion traffic and pay-as-you-go for Log Management.

Billing method

Best for

Billing items

Subscription

Predictable resource usage cycles. Stable business scenarios. Long-term resource needs.

Log Ingestion Traffic: Tiered pricing, minimum 100 GB/day, step size 100 GB/day. Log Storage Capacity: Minimum 1,000 GB, step size 1,000 GB. Intelligent Usage Analysis: Must match Log Ingestion Traffic. Number of Managed Instances: Minimum 10 instances/month, step size 10 instances/month.

Pay-as-you-go

Unpredictable resource usage cycles. Highly variable traffic.

Log Ingestion Traffic: Tiered cumulative billing based on actual daily ingestion, minimum 1 GB. Intelligent Usage Analysis: Billed by actual analysis usage (GB). Number of Managed Instances: Billed by actual Agent instance invocations. Log Management: Billed by daily cumulative storage, minimum 1 TB.

Choose a service

Agentic SOC provides two service tiers. Compare the following sections to determine which tier meets your requirements.

  • Agentic SOC (Basic): Rule-based threat detection and response with preset playbooks and lightweight AI models.

  • Security Operations Agent: An advanced tier built on Agentic SOC. Uses a Multi-Agent architecture powered by large-scale AI models for autonomous incident investigation, threat detection, and response coordination.

Intelligence level differences

Dimension

Agentic SOC (Basic)

Security Operations Agent

Positioning

Tool-assisted with limited intelligence

Digital security expert, 24/7 digital workforce

Driving method

Rule-based and feature-driven with lightweight/edge models

Semantic awareness and dynamic reasoning with large-scale models

Core logic

Preset, static, linear playbooks with partial lightweight model capabilities

Goal-driven autonomous closed loop with Multi-Agent architecture on top of Agentic SOC

Extensibility

Limited by human FTE

Highly automated with compute-scalable capacity

AI Agent differences

For more information about Agents, see Security operations agents.

Dimension

Agentic SOC (Basic)

Security Operations Agent

Security AI Assistant: product consultation, alert explanation, and incident summary

Supported

Supported

Incident Investigation Agent: malicious web traffic tracing and analysis

Not supported

Supported

Threat Detection Agent: incident generation, deep investigation, traceability analysis, and impact assessment

Not supported

Supported

Response Coordination Agent: incident response and entity assessment

Not supported

Supported

Security Report Agent: alert analysis reports, security operations reports, and incident investigation reports

Incident investigation reports not supported.

Supported

Billing differences

Dimension

Agentic SOC (Basic)

Security Operations Agent

Billing items

Billed by Log Ingestion Traffic and Log Storage Capacity independently. Purchase each based on your needs.

In addition to Agentic SOC billing items, also requires Intelligent Usage Analysis and Number of Managed Instances.

Purchase steps

Subscription

  1. Log on to the Security Center console.

  2. On the Agentic SOC page, click Activate Subscription. On the Quick Purchase tab, Billing Method defaults to Subscription.

  3. Click Create Service-linked Role to complete cloud service access authorization. Skip this step if you have already created the role.

    After authorization, Security Center automatically creates the service-linked role AliyunServiceRoleForSasCloudSiem so that Agentic SOC can access resources in your other cloud services. For more information, see Service-linked roles for Security Center.

  4. Select the service to purchase: Agentic SOC or Security Operations Agent. For the differences between these two services, see Choose a service.

  5. Set the purchase quantity based on your selected service.

    • Agentic SOC: Billed by Log Ingestion Traffic and Log Storage Capacity independently. Purchase each based on your needs.

    • Security Operations Agent: In addition to Agentic SOC billing items, also requires Intelligent Usage Analysis and Number of Managed Instances.

Log ingestion traffic

  • Definition: The daily volume of logs ingested into Agentic SOC for analysis, measured in GB/day.

  • Sizing guidance: Estimate your required log ingestion traffic using one of these methods:

    • Based on existing Simple Log Service (SLS) capacity:

      Log ingestion traffic (GB/day) = Log storage capacity / TTL

      • Log storage capacity is the storage used by the log sources you plan to ingest into Agentic SOC.

      • TTL is the log retention period.

    • Based on Events Per Second (EPS):

      Log ingestion traffic (GB/day) = EPS × 86400 × SIZE / (1024 × 1024)

      • EPS is the number of raw log events ingested per second.

      • SIZE is the average log entry size, typically 3 KB to 7 KB.

  • Pricing: Tiered pricing. Minimum purchase: 100 GB/day. Step size: 100 GB/day. Pricing tiers (X = daily ingestion traffic):

    X = 100 GB: CNY 3 per GB per day. 200 GB <= X < 9,999,999,999 GB: CNY 2.8 per GB per day.

Log storage capacity

  • Definition: The amount of log storage Agentic SOC uses to retain logs.

  • Sizing guidance: Allocate 120 GB per server, or use three times the storage capacity currently used by Security Center log analysis. For more information, see Log management.

  • Pricing: Minimum 1,000 GB. Step size: 1,000 GB. Price: CNY 500 per 1,000 GB per month.

Intelligent analysis flow

  • Definition: Required only when you purchase Security Operations Agent. Measures the AI analysis quota consumed by alert triage, incident investigation, traceability, attribution, and security report generation.

  • Sizing guidance: Does not support auto-filling. Must match your Log Ingestion Traffic purchase amount.

  • Pricing:

    • Minimum purchase: 100 GB/day. Auto-fill is not supported. Must match Log Ingestion Traffic.

    • Price: CNY 66.7 per 100 GB per day.

      Note

      Usage resets to zero at midnight every day. If exceeded, the system automatically throttles.

Onboarded assets

  • Definition: The count of instances managed by Security Operations Agent for cross-instance security operations and automated response.

  • Sizing guidance: Each invoked instance is counted. Instances include ECS, WAF, ALB, cross-cloud products, and on-premises security products.

  • Pricing:

    • Minimum purchase: 10 instances/month, step size: 10 instances/month.

    • CNY 10 per instance per month.

      Note

      Each instance is counted only once. Duplicates are automatically removed.

  1. Choose whether to enable Access Policy.

    • If you select the access policy, Agentic SOC automatically ingests logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account after activation. For more information, see Recommended log ingestion policy.

    • If you do not select the access policy, no predefined ingestion settings are applied. After purchase, manually select log sources based on your needs. For instructions, see Product logs.

  2. Review the Security Center Related Agreements, then click Order Now.

Pay-as-you-go

Important

If you have already purchased log ingestion traffic using subscription, you cannot activate Agentic SOC on pay-as-you-go.

  1. Log on to the Security Center console.

  2. On the Agentic SOC page, click Activate Pay-as-you-go and select the services to activate.

  3. Review the billing rule descriptions. Billing varies by activated service.

    • Billing method:

      • Agentic SOC: Billed by daily log ingestion traffic (GB) using tiered cumulative pricing. Daily cost is the sum of each tier.

        Important

        The minimum billing unit is 1 GB. Usage less than 1 GB is billed as 1 GB.

      • Security Operations Agent: In addition to tiered cumulative billing by daily log ingestion traffic (GB), the following billing items apply:

        • Intelligent Analysis Flow: Billed by the analysis usage (GB) consumed by the AI security agent for alert triage, incident investigation, traceability, attribution, and security report generation.

        • Onboarded Assets: Billed by the number of Agent instance invocations. Products such as ECS, WAF, ALB, cross-cloud products, and on-premises security vendor products are all counted as instances.

          Important

          Each instance is counted only once. Duplicates are automatically removed.

    • Billing cycle: Billed by calendar day.

    • Price:

      • Log Ingestion Traffic: Tiered pricing by daily log ingestion traffic (GB).

        Daily log ingestion traffic range

        Price

        Cost formula (Y = daily traffic in GB)

        1–10 (GB/day)

        CNY 15/GB

        15 × Y (CNY)

        11–50 (GB/day)

        CNY 10/GB

        15×10 + 10×(Y−10) (CNY)

        51–100 (GB/day)

        CNY 9/GB

        15×10 + 10×40 + 9×(Y−50) (CNY)

        >100 (GB/day)

        CNY 8/GB

        15×10 + 10×40 + 9×50 + 8×(Y−100) (CNY)

      • Intelligent Analysis Flow: CNY 1/GB/day.

      • Onboarded Assets: CNY 15 per instance per month.

  4. Choose whether to enable One-click Ingestion.

    • If you select One-click Ingestion, Agentic SOC automatically ingests logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account after activation. For more information, see Recommended log ingestion policy.

      After you enable the recommended log ingestion policy, the system automatically ingests the specified log types into Agentic SOC. Security Center generates a bill the next day based on your actual log ingestion volume.

    • If you do not enable One-click Ingestion, manually select log sources based on your needs. For instructions, see Product logs.

  5. Click Activate and Authorize.

    After this operation, Security Center automatically creates the service-linked role AliyunServiceRoleForSasCloudSiem so that Agentic SOC can access resources in your other cloud services. For more information, see Service-linked roles for Security Center.

Features available after activation

The features you can access depend on your billing method and which dimensions you purchased.

Subscription

Feature

CTDR 1.0

CTDR 2.0 (Agentic SOC)

Log ingestion only

Log ingestion + storage

Log ingestion only

Log storage only

Log ingestion + storage

Dashboard

Not supported

Supported

Not supported

Not supported

Not supported

Event Handling

Supported

Supported

Supported

Not supported

Supported

Alerts

Supported

Supported

Supported. Custom Alert Analysis requires pay-as-you-go feature for full support.

Not supported

Supported

Incident Response

Supported

Supported

Supported

Not supported

Supported

Response Rules

Supported

Supported

Supported

Not supported

Supported

Log Management

Not supported

Supported

Security Center logs: Supported. Standardized logs: Only supports logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported.

Security Center Logs: Supported. Standardized Log: Not supported.

Supported

Detection Rules

Predefined: Supported; Custom: Not supported

Supported

Predefined: Supported. Custom: Only supports detection of logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported.

Not supported

Supported

Integration Settings / Service Integration

Supported

Supported

Supported

Not supported

Supported

Pay-as-you-go

Feature

CTDR 1.0

CTDR 2.0 (Agentic SOC)

Dashboard

Not supported

Not supported

Event Handling

Supported

Supported

Alerts

Supported

Supported

Incident Response

Supported

Supported

Response Rules

Supported

Supported

Log Management

Not supported

Security Center logs: Supported. Standardized logs: Only supports logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported.

Detection Rules

Predefined: Supported; Custom: Not supported

Predefined: Supported. Custom: Only supports detection of logs with standardization method "Scan Query". If pay-as-you-go feature is also activated, all services are supported.

Integration Settings / Service Integration

Supported

Supported

Product ingestion

After activating Agentic SOC, ingest product logs to enable cross-resource alerting and unified log analysis. For instructions, see Product logs.

Unsubscribe

To disable Agentic SOC:

  • Subscription: Go to the order downgrade page. On the Order Downgrade tab, in the Agentic SOC section, set Purchase or Not to No. For instructions, see Upgrades and downgrades.

    The exact refund amount is shown on the downgrade page. For details about refund disbursement, see Refund destinations.

  • Pay-as-you-go: On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the switch for Agentic SOC or Log Management.

Important
  • No new charges accrue after you disable the service. Except for user-delivered logs, all data and configurations—including security alerts, security events, and ingestion settings—are deleted after 15 days.

  • After you turn off the Log Management switch, log delivery stops and the corresponding Logstore is deleted. Deleted log data cannot be recovered. Proceed with caution.

Appendix

Other purchase entry points

You can also purchase Agentic SOC on the Security Center purchase page or on the console Overview page. For Security Center edition selection and other service purchases, see Purchase and Unsubscribe from Security Center.

Subscription

On the Security Center purchase page, in the edition selection area select Value-added Services Only. In the Agentic SOC configuration area, set the purchase option to Agentic SOC. Configure Log Ingestion Traffic (minimum and step size: 100 GB/day) and Log Storage Capacity. Confirm the Service-linked Role status is Created, and select Enable Agentic SOC recommended product log ingestion policy.

Pay-as-you-go

  • Security Center purchase page

    On the Security Center purchase page, set Billing Method to Pay-as-you-go (billed daily). In the Agentic SOC area, select Agentic SOC or Security Operations Agent. Confirm the Service-linked Role status is Created, and select the Access Policy option "Enable Agentic SOC recommended product log ingestion policy. After enabling, billing is based on actual usage."

  • Overview page

    In the Pay-as-you-go Services area, find the Agentic SOC service item and enable its switch.

Recommended log ingestion policy

After you enable the recommended log ingestion policy, Agentic SOC automatically ingests logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account—no manual configuration required.

Note

If your Security Center edition is Free Edition or Value-added Services Only, ActionTrail event logs are not ingested.

#

Alibaba Cloud product

Data source name

Standardization rule name

Standardization method

Standardization category/structure

Security capabilities

1

Security Center

DNS request logs

Host DNS request log standardization rule

Scan query

Host logs - Process DNS request logs

Predefined analysis rules, predefined playbooks

2

Baseline logs

Baseline log standardization rule

Scan query

Security logs - Host baseline logs

Incident investigation and traceability, predefined playbooks

3

Login flow logs

Login flow log standardization rule

Scan query

Login logs - Host login logs

Custom analysis rules, incident investigation and traceability, predefined playbooks

4

Network connectivity logs

Network connectivity log standardization rule

Scan query

Host logs - Process network outbound logs

Predefined analysis rules, predefined playbooks

5

Process startup logs

Process startup log standardization rule

Scan query

Host logs - Process startup logs

Predefined analysis rules, custom analysis rules, incident investigation and traceability, predefined playbooks

6

Security alert logs

Security alert log standardization rule

Real-time consumption

Security logs - Other alert logs

Predefined playbooks

7

Vulnerability logs

Vulnerability log standardization rule

Scan query

Security logs - Vulnerability logs

Incident investigation and traceability, predefined playbooks

8

Web Application Firewall

WAF alert logs

WAF alert log standardization rule

Real-time consumption

Security logs - WAF alert logs

Predefined analysis rules, custom analysis rules, predefined playbooks

9

WAF full/block/block-and-observe logs

WAF full/block/block-and-observe log standardization rule

Real-time consumption

Network logs - HTTP logs

Predefined analysis rules, custom analysis rules, incident investigation and traceability, predefined playbooks

10

Cloud Firewall

Cloud Firewall alert logs

Cloud Firewall alert log standardization rule

Real-time consumption

Security logs - Firewall alert logs

Predefined analysis rules, custom analysis rules, predefined playbooks

11

ActionTrail

ActionTrail event logs

ActionTrail event log standardization rule

Real-time consumption

Audit logs - Cloud platform operation audit logs

Custom analysis rules, incident investigation and traceability

Related documentation