Purchase and activate Agentic SOC
Agentic SOC is the built-in threat detection and response module in Security Center. It provides unified log analysis, automated incident response, out-of-the-box threat detection rules, and other security capabilities. This topic describes how to select a billing mode and activate the service.
Purchase options
Agentic SOC (New) uses Agentic AI as its core engine, deeply integrating Alibaba Cloud's native security data and infrastructure. It leverages the Agent's autonomous perception-reasoning-execution capabilities to autonomously triage security incidents and help achieve rapid incident response. Agentic SOC (Legacy) and Security Operations Agent (Legacy) are legacy services sold before July 30, 2026, billed primarily based on log ingestion traffic. The two legacy versions cannot be switched between each other -- you can only close the current legacy version or upgrade to the new Agentic SOC. Upgrades are irreversible.
To use the full feature set of Agentic SOC, you must purchase Agentic SOC (Log Storage Capacity) to store ingested logs in the log library of the Logs module. For detailed billing information about log storage capacity, see Agentic SOC (Log Storage Capacity).
The new version of Agentic SOC supports three billing modes: post-paid, pre-paid, and burstable protection (pre-paid to pay-as-you-go). Post-paid bills based on actual usage of intelligent operations volume (Credits), managed instances, and log ingestion volume. Pre-paid allows you to purchase intelligent operations packages and managed instance packages on a monthly or annual subscription.
Edition |
Billing mode |
Applicable scenarios |
Billing item description |
Agentic SOC |
Post-paid (Pay-as-you-go) |
|
|
Pre-paid (Annual/Monthly) |
|
You can configure intelligent operations packages and managed instance packages in the same order. Monthly and annual billing are supported; annual pricing is calculated as monthly price multiplied by 12. You can optionally enable burstable protection, under which usage beyond the pre-paid entitlements is billed according to post-paid rules. |
|
Agentic SOC Legacy |
Agentic SOC (Legacy) |
|
Includes 2 billing items: Log Ingestion Traffic and Agentic SOC (Log Storage Capacity). Upgrading to the new version is irreversible. For detailed billing information about log storage capacity, see Agentic SOC (Log Storage Capacity). |
Security Operations Agent (Legacy) |
Activated before July 30, 2026, and not yet switched to the new version during the current order validity period. |
Includes 4 billing items: Log Ingestion Traffic, Agentic SOC (Log Storage Capacity), Intelligent Usage Analysis, and Number of Managed Instances. Upgrading to the new version is irreversible. For detailed billing information about log storage capacity, see Agentic SOC (Log Storage Capacity). |
Users who activated Agentic SOC (Legacy) or Security Operations Agent (Legacy) before July 30, 2026 can continue using the original billing model during the current order validity period, or upgrade to the new pre-paid version. Upgrades are irreversible. For detailed information about billing model upgrades and legacy version migration steps, see Notice: Agentic SOC billing model upgrade.
Purchase steps
The following sections describe the purchase steps for each billing mode, in the same order as the billing modes listed in Purchase options. New users should refer to Post-paid (Pay-as-you-go), Pre-paid (Annual/Monthly) based on their selection. Agentic SOC (Legacy) applies only to existing users who activated before July 30, 2026 and have not yet switched to the new version during the current order validity period. Complete pricing and billing rules for each billing mode are described in the corresponding subsection only.
To use the full feature set of Agentic SOC, you must purchase Agentic SOC (Log Storage Capacity) to store ingested logs in the log library of the Logs module. For detailed billing information about log storage capacity, see Agentic SOC (Log Storage Capacity).
Post-paid (Pay-as-you-go)
If you have already purchased log ingestion traffic through an annual/monthly subscription, you cannot activate Agentic SOC pay-as-you-go. The new-version billing rules in this section apply to users who purchase on or after July 30, 2026, or who have switched from the legacy version. Users who remain within an active legacy subscription and have not switched should continue to refer to the legacy billing rules.
Post-paid requires no upfront payment. The system meters actual usage and generates bills. After activation, billing is based on intelligent operations volume (Credits), managed instances, and log ingestion volume separately.
-
Log on to the Security Center console, In the left-side navigation pane, choose .
-
On the Agentic SOC page, click Enable Pay-as-you-go to go to the pay-as-you-go purchase page.
NoteThe current pay-as-you-go purchase page only provides a single Agentic SOC (new version) service entry; new users can simply activate it. If you currently have Agentic SOC (Legacy) or Security Operations Agent (Legacy), this page only supports closing the legacy version you currently hold -- it does not allow switching between the two legacy versions. To continue using the new-version capabilities, upgrade to the new Agentic SOC. For legacy version upgrade/downgrade and switching steps, see Legacy version (Agentic SOC / Security Operations Agent) operations (renewal only).
-
After activating Agentic SOC pay-as-you-go, the system meters intelligent operations volume, managed instances, and log ingestion volume separately based on actual usage and pushes pay-as-you-go bills.
Billing item
Billing rule
Intelligent operations volume
Billed in near real time based on Credits actually consumed, at CNY 0.015/Credit.
Managed instances
Billed based on the number of target instances that actually receive a response action during security operations, at CNY 15/seat/month, counted by calendar month.
Log ingestion volume
Credits accumulate by calendar day. Every 24,000 Credits consumed converts to a 1 GB/day log ingestion volume entitlement. Before the daily log ingestion charge is pushed, the entitlement converted that day is applied first. The portion beyond the entitlement is billed using tiered cumulative pricing.
The daily tiered cumulative price for log ingestion volume beyond the entitlement is as follows:
Log ingestion volume range
Price
Cost formula (Y is the daily ingestion volume in GB)
1~10 (GB/day)
CNY 15/GB
15 x Y (CNY)
11~50 (GB/day)
CNY 10/GB
15 x 10 + 10 x (Y - 10) (CNY)
51~100 (GB/day)
CNY 9/GB
15 x 10 + 10 x 40 + 9 x (Y - 50) (CNY)
>100 (GB/day)
CNY 8/GB
15 x 10 + 10 x 40 + 9 x 50 + 8 x (Y - 100) (CNY)
Tiered charges accumulate separately by range. For example, if the daily usage beyond the entitlement is 60 GB, the charge is
10 GB x CNY 15/GB + 40 GB x CNY 10/GB + 10 GB x CNY 9/GB.Actual fees are subject to the purchase page, metering results, and Billing Center bills.
-
Based on your business needs, choose whether to enable One-click Onboarding without Configuration.
-
If you select One-click Onboarding without Configuration, after activating Agentic SOC, the system automatically ingests certain data sources from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account. For more information, see Recommended log onboarding policy.
ImportantAfter enabling the recommended log onboarding policy, the system automatically ingests the specified log types into Agentic SOC. Security Center will generate a bill the next day based on the actual log ingestion volume.
-
If you do not enable One-click Onboarding without Configuration, you can customize which product logs to ingest based on your actual needs. For more information, see Product logs.
-
-
Read and agree to the relevant agreements, and then click Activate and Authorize.
NoteAfter this operation is completed, Security Center automatically creates the service-linked role AliyunServiceRoleForSasCloudSiem so that Agentic SOC can use this role to access resources in your other cloud services. For more information, see Service-linked roles for Security Center.
Pre-paid (Annual/Monthly)
Pre-paid is suitable for scenarios where usage is relatively predictable and you want to lock in your budget in advance. You can configure intelligent operations packages and managed instance packages in the same order. Monthly and annual billing are supported; annual pricing is calculated as monthly price multiplied by 12.
Pre-paid package |
Monthly price |
Annual price |
Entitlement description |
Intelligent operations package |
CNY 12,000/month |
CNY 144,000/year |
Each package provides 600,000 Credits and a 50 GB/day log ingestion volume entitlement. |
Managed instance package |
CNY 100/month |
CNY 1,200/year |
Each package provides 10 managed instance seats, equivalent to CNY 10/seat/month. |
Pre-paid entitlements are applied first against the corresponding usage within the validity period. When multiple intelligent operations packages are purchased, Credits and log ingestion volume entitlements stack by package count. For example, purchasing 2 intelligent operations packages provides 1,200,000 Credits and a 100 GB/day log ingestion volume entitlement.
Users with an active pre-paid subscription can upgrade or downgrade through the console. After downgrading, the package quantity cannot be lower than the minimum number of packages required by current actual usage. The specific adjustable quantities and the amount due or refund are subject to the operation page and Billing Center display.
Purchase steps:
Log on to the Security Center console, In the left-side navigation pane, choose .
On the Agentic SOC page, click Subscribe (Annual/Monthly). On the Quick Purchase tab, switch Billing Method to Pre-paid (Annual/Monthly).
Click Create Service-linked Role to complete the cloud service access authorization. Skip this step if you have already created the role.
-
Configure the pre-paid packages:
Intelligent operations package: Set the purchase quantity. Each package includes 600,000 Credits and a 50 GB/day log ingestion volume entitlement. Monthly and annual billing are supported.
Managed instance package: Set the purchase quantity. Each package includes 10 managed instance seats. Monthly and annual billing are supported.
Based on your business needs, choose whether to enable burstable protection. When enabled, usage beyond the pre-paid entitlements is billed according to post-paid rules and service is not interrupted. When disabled, new overage consumption is blocked once entitlements are exhausted.
-
Based on your business needs, choose whether to enable Access Policy.
If you select the onboarding policy, after activation the system automatically ingests certain log sources from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account.
If you do not select the onboarding policy, no predefined onboarding is performed. After purchase, you can customize which product logs to ingest based on your actual needs.
Read the Security Center Product Agreements carefully, confirm the order information, and then click Order Now to complete the purchase.
After activating the Agentic SOC pre-paid subscription, the console Overview page will display the Agentic SOC Subscription Service card, showing current pre-paid entitlement usage, the burstable protection toggle, and upgrade/downgrade entry points.
Actual fees, purchasable quantities, and amounts due or refundable are subject to the purchase page, metering results, and Billing Center bills.
Legacy version (Agentic SOC / Security Operations Agent) operations (renewal only)
The following instructions apply to users who activated Agentic SOC (Legacy) or Security Operations Agent (Legacy) subscription before July 30, 2026, and have not yet switched to the new billing model during the current order validity period. The two legacy versions cannot be switched between each other -- you can only close the current legacy version or upgrade to the new Agentic SOC. New users should refer to the Post-paid (Pay-as-you-go) or Pre-paid (Annual/Monthly) subsections.
Log on to the Security Center console, In the left-side navigation pane, choose .
On the Agentic SOC page, click Subscribe (Annual/Monthly). On the Quick Purchase tab, keep Billing Method at the default option Subscription.
-
Click Create Service-linked Role to complete the cloud service access authorization. Skip this step if you have already created the role.
NoteAfter this authorization operation is completed, Security Center automatically creates the service-linked role AliyunServiceRoleForSasCloudSiem so that Agentic SOC can use this role to access resources in your other cloud services. For more information, see Service-linked roles for Security Center.
Your current legacy version only supports renewal or closure -- switching to the other legacy version is not supported. To upgrade to the new Agentic SOC, see the upgrade instructions in Notice: Agentic SOC billing model upgrade.
-
Based on your current legacy service, configure the renewal quantity. Billing item descriptions are as follows:
Log Ingestion Traffic
Definition: Select the daily log volume to be ingested into Agentic SOC for analysis, in GB/day.
-
Estimated purchase volume: You can estimate the required log ingestion volume using the following methods:
Estimate based on the provisioned log storage capacity:
Log ingestion volume (GB/day) = Log storage capacity / TTL
Log storage capacity is the storage space used by the log sources to be connected to Agentic SOC.
TTL is the log retention period.
Estimate based on the events per second (EPS):
Log ingestion volume (GB/day) = EPS * 86400s * SIZE / (1024 * 1024)
EPS stands for Events Per Second, which refers to the number of raw logs ingested into Agentic SOC in a day.
SIZE is the size of each log entry, typically ranging from 3 to 7 KB.
-
Billing: Tiered pricing is applied. The minimum purchase is 100 GB/day, with increments of 100 GB/day. The specific pricing is as follows (X is the daily ingestion volume):
X=100 GB: CNY 3/GB/day.
200 GB<=X<9,999,999,999 GB: CNY 2.8/GB/day.
Agentic SOC (Log Storage Capacity)
Definition: Select the log storage capacity for Agentic SOC.
Estimated purchase volume: We recommend 120 GB of log storage capacity per server, or 3 times the log analysis storage capacity in Security Center. For more information, see Log management.
Billing: The minimum purchase is 1,000 GB, with increments of 1,000 GB. The price is CNY 500/1,000 GB/month.
Capacity entitlement: The log storage capacity purchased on the buy page and the capacity displayed and used on the Logs page are the same entitlement, not two separate capacities.
Access path: If you have not purchased Agentic SOC, view log storage capacity usage through Detection and Response > Logs. After purchasing Agentic SOC, the entry changes to Agentic SOC > Logs, with the capacity entitlement and usage remaining unchanged.
Intelligent Usage Analysis
Definition: This item is required only when purchasing Security Operations Agent. It represents the analysis credits consumed for alert triage, event investigation, tracing, attribution, and security report generation.
Estimated purchase volume: The quantity cannot be auto-filled. It must match the Log Ingestion Traffic setting.
Billing:
The minimum purchase is 100 GB/day. The quantity cannot be auto-filled and must match the Log Ingestion Traffic setting.
Price: CNY 66.7/100 GB/day.
Number of Managed Instances
Definition: The number of instances managed by Security Operations Agent for cross-instance security operations and automated response.
Estimated purchase volume: Every invoked instance is counted. This includes ECS, WAF, ALB, multi-cloud services, and on-premises security vendor products.
Billing:
The minimum purchase is 10 instances/month, with increments of 10 instances/month.
CNY 10/instance/month.
NoteEach instance is counted only once with automatic deduplication.
-
Based on your business needs, choose whether to enable Access Policy.
If you select the onboarding policy, after activating Agentic SOC the system automatically ingests certain log sources from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account. For more information, see Recommended log onboarding policy.
If you do not select the onboarding policy, no predefined onboarding is performed. After purchase, you can customize which product logs to ingest based on your actual needs. For more information, see Product logs.
Read the Security Center Product Agreements carefully, and then click Order Now.
Agentic SOC (Log Storage Capacity)
To use the full feature set of Agentic SOC, you must purchase log storage capacity to store ingested logs in the log library of the Logs module. The following describes the log storage capacity in detail.
Definition: Select the log storage capacity for Agentic SOC.
Estimated purchase volume: We recommend 120 GB of log storage capacity per server, or 3 times the log analysis storage capacity in Security Center. For more information, see Log management.
-
Billing: Log storage capacity supports both pre-paid (annual/monthly) and post-paid (pay-as-you-go) billing modes.
Annual/Monthly: Charged based on the purchased log storage capacity and subscription duration. CNY 500/1,000 GB/month. The minimum purchase is 1,000 GB, with increments of 1,000 GB.
-
Pay-as-you-go: After activating pay-as-you-go for log management, the system calculates the daily cumulative storage volume (GB) for each calendar day and charges CNY 50/1,000 GB per calendar day.
ImportantThe minimum billing unit for pay-as-you-go log management is 1,000 GB. Any usage less than 1,000 GB is billed as 1,000 GB. For example, if the daily usage is 1,900 GB, you are charged for 2,000 GB.
Capacity entitlement: The log storage capacity purchased on the buy page and the capacity displayed and used on the Logs page are the same entitlement, not two separate capacities.
Access path: If you have not purchased Agentic SOC, view log storage capacity usage through Detection and Response > Logs. After purchasing Agentic SOC, the entry changes to Agentic SOC > Logs, with the capacity entitlement and usage remaining unchanged.
Product onboarding
After activating Agentic SOC, onboard product logs to enable unified monitoring and analysis of cross-resource alerts and log data. This improves alert analysis and handling efficiency. For more information, see Product logs.
Unsubscription
If you no longer need Agentic SOC, you can disable the service.
-
For annual/monthly subscriptions: On the Overview page Subscription region, click On the order upgrade/downgrade page, on the Order Downgrade tab in the Agentic SOC area, set Purchase or Not to No. For more information, see Upgrades and downgrades.
NoteThe specific refund amount is subject to the amount displayed on the downgrade page. For information about refund fund flows, see Refund destinations.
ImportantAfter unsubscription, data and configurations other than user-delivered logs -- such as security alerts, security incidents, and onboarding configurations -- will be cleared after 15 days.
-
For pay-as-you-go: On the Overview page in the Security Center console, in the Enable Pay-as-You-Go Service area, turn off the Agentic SOC or Log Management toggle.
ImportantNo new charges are incurred after disabling. Data and configurations other than user-delivered logs -- such as security alerts, security incidents, and onboarding configurations -- will be cleared after midnight on the day after unsubscription (T+1).
After the Log Management toggle is turned off, log delivery is automatically disabled and the corresponding Logstore is deleted. Deleted log data cannot be recovered. Proceed with caution.
Appendix
Other purchase entry points
You can also purchase or activate Agentic SOC on the Security Center buy page or the console Overview page. For information about Security Center edition selection and other service purchase options, see Purchase Security Center.
Post-paid (Pay-as-you-go)
-
Security Center buy page
On the Security Center buy page, set Purchase Method to Pay-as-you-go. The billing cycle is daily. The current pay-as-you-go purchase page only provides a single Agentic SOC (new version) service entry; new users can simply activate it. If you currently have Agentic SOC (Legacy) or Security Operations Agent (Legacy), this page only supports closing the legacy version you currently hold -- it does not allow switching between the two legacy versions. The new-version billing is based on a combination of intelligent operations volume, managed instances, and log ingestion volume. For specific pricing and tiered rules, see the Post-paid (Pay-as-you-go) section of this topic. Confirm that the Associated Role status shows created, and select "Enable the recommended product log onboarding policy for Agentic SOC. After enabling, metering is based on actual usage" under Onboarding Policy.
-
Overview page
In the Pay-as-you-go Services area on the console Overview page, find the Agentic SOC service entry and turn on its toggle.
Pre-paid (Annual/Monthly)
-
Security Center buy page (new-version pre-paid)
On the Security Center buy page, set Purchase Method to Pre-paid (Annual/Monthly), configure the intelligent operations package and managed instance package quantities and the billing cycle (monthly or annual). For specific pricing and entitlements, see the Pre-paid (Annual/Monthly) section of this topic.
-
Security Center buy page (legacy version annual/monthly)
This option applies only to users who activated the legacy version before July 30, 2026 and have not yet switched to the new version during the current order validity period. On the Security Center buy page, select Purchase Value-added Services Only in the edition selection area. In the Agentic SOC configuration area, set the purchase option to Agentic SOC, configure Log Ingestion Traffic and Log Storage Capacity, confirm that the Associated Role status shows created, and select Enable the recommended product log onboarding policy for Agentic SOC. For specific pricing, minimum purchase quantities, and purchase increments, see the Legacy version (Agentic SOC / Security Operations Agent) operations (renewal only) section of this topic.
Recommended log onboarding policy
After enabling the recommended log onboarding policy, no manual configuration is required. Agentic SOC automatically ingests logs from Security Center, Web Application Firewall, Cloud Firewall, and ActionTrail under your current Alibaba Cloud account. The ingested data sources and supported security capabilities are listed in the following table.
If your Security Center edition is Free or Purchase Value-added Services Only, the system does not ingest ActionTrail event logs.
|
No. |
Alibaba Cloud service |
Data source name |
Normalization rule name |
Normalization method |
Normalization category/structure |
Supported security capabilities |
|
1 |
Security Center |
DNS request logs |
Host DNS request log normalization rule |
Scan query |
Host logs - Process DNS request logs |
|
|
2 |
Baseline logs |
Baseline log normalization rule |
Scan query |
Security logs - Host baseline logs |
|
|
|
3 |
Login history logs |
Login history log normalization rule |
Scan query |
Login logs - Host login logs |
|
|
|
4 |
Network connection logs |
Network connection log normalization rule |
Scan query |
Host logs - Process network outbound logs |
|
|
|
5 |
Process startup logs |
Process startup log normalization rule |
Scan query |
Host logs - Process startup logs |
|
|
|
6 |
Security alert logs |
Security alert log normalization rule |
Real-time consumption |
Security logs - Other alert logs |
Predefined playbooks |
|
|
7 |
Vulnerability logs |
Vulnerability log normalization rule |
Scan query |
Security logs - Vulnerability logs |
|
|
|
8 |
Web Application Firewall |
WAF alert logs |
WAF alert log normalization rule |
Real-time consumption |
Security logs - WAF alert logs |
|
|
9 |
WAF full/block/block-and-observe logs |
WAF full/block/block-and-observe log normalization rule |
Real-time consumption |
Network logs - HTTP logs |
|
|
|
10 |
Cloud Firewall |
Cloud Firewall alert logs |
Cloud Firewall alert log normalization rule |
Real-time consumption |
Security logs - Firewall alert logs |
|
|
11 |
ActionTrail |
ActionTrail event logs |
ActionTrail event log normalization rule |
Real-time consumption |
Audit logs - Cloud platform operation audit logs |
|
References
-
For information about Security Center editions and value-added service purchase options, see Purchase Security Center.
-
For information about the Agentic SOC architecture, see Agentic SOC edition comparison.
-
After activating the Agentic SOC service, you need to onboard product logs. For more information, see Agentic SOC 2.0 product onboarding.
-
For the complete billing rules of the new-version Agentic SOC pay-as-you-go billing mode, see Pay-as-you-go.
-
For the hybrid billing mechanism that switches to pay-as-you-go after pre-paid entitlements are exhausted, see Security Center hybrid billing model.