All Products
Search
Document Center

Security Center:Data ingestion overview

Last Updated:Mar 31, 2026

Agentic SOC collects logs from connected products using Alibaba Cloud Simple Log Service (SLS) and normalizes them with standardization rules based on SLS SPL syntax. Normalization maps logs from different sources into a unified schema, enabling cross-source correlation and consistent detection rule evaluation. For non-standard fields, use the extended field ingestion feature and select preserve as-is to retain all original log fields. After normalization, Agentic SOC applies detection rules to the ingested logs to identify threats, reconstruct complete attack chains, and generate detailed security events that streamline alert analysis and response.

Log ingestion architecture

image

Ingestion solution overview

Connect to Alibaba Cloud

image

Integrate with third-party clouds

image

Integrate custom applications

image

Supported products and logs

Agentic SOC natively supports logs from Alibaba Cloud, Huawei Cloud, Tencent Cloud, Fortinet, Chaitin, and Sangfor, as well as custom products.

Note: For details about the default ingestion policies, data sources, and standardization rules provided by Agentic SOC, go to the console.
VendorProductLog types
Alibaba CloudSecurity CenterNetwork defense alert logs, cloud platform configuration check logs, baseline logs, security alert logs, vulnerability logs, Runtime Application Self-Protection (RASP) alert logs, and cloud security posture management logs; account snapshot logs, network snapshot logs, and process snapshot logs; host logon failure logs, DNS request logs, logon trail logs, process startup logs, network connection logs, and brute-force attack logs
Web Application Firewall (WAF)WAF full logs, blocked logs, blocked and observed logs, anti-crawler full logs, API security event alert logs, API risk logs, and WAF alert logs
Cloud FirewallCloud Firewall alert logs, Cloud Firewall traffic logs, NDR HTTP logs, NDR DNS logs, and NDR event alert logs
Anti-DDoSAnti-DDoS Pro and Anti-DDoS Premium full logs
BastionhostBastionhost logs
CDNCDN flow logs
Edge Security Acceleration (ESA)DCDN user access logs and DCDN WAF blocked logs
API GatewayAPI Gateway logs
Container Service for Kubernetes (ACK)Kubernetes audit logs
PolarDBPolarDB-X 1.0 SQL audit logs and PolarDB-X 2.0 SQL audit logs
ApsaraDB for MongoDBMongoDB audit logs
ApsaraDB RDSRDS SQL audit logs
Virtual Private Cloud (VPC)VPC flow logs
Elastic IP Address (EIP)Elastic IP Address logs
Server Load Balancer (SLB)ALB access logs and CLB access logs
Object Storage Service (OSS)OSS access logs
ActionTrailActionTrail event logs
CloudConfigConfiguration audit logs
File Storage NASNAS NFS operational logs
AI GuardrailsAlibaba Cloud AI Security Guardrail logs
Tencent CloudWeb Application FirewallTencent Cloud Web Application Firewall alert logs
Cloud FirewallTencent Cloud Firewall alert logs
Huawei CloudWeb Application FirewallHuawei Cloud Web Application Firewall alert logs
Cloud FirewallHuawei Cloud Firewall alert logs
AzureWindows Defender for EndpointEndpoint alert logs
Azure Active DirectoryAudit logs and logon logs
ActivityAudit logs
SQL DatabaseSQL Server audit logs
AWSCloudTrailCloudTrail logs
RedshiftRedshift audit logs
GuardDutyGuardDuty finding alert logs
PostgreSQL on Amazon RDSPostgreSQL event logs
VolcengineSecurity CenterHIDS alert logs
FortinetFortinet FirewallFortinet Firewall alert logs, Fortinet Firewall flow logs, and Fortinet audit logs
ChaitinChaitin WAFChaitin WAF alert logs and Chaitin WAF flow logs
MicrosoftEndpoint event logsWindows security event logs
SangforSangfor Endpoint Secure aES (EDR)Endpoint detection and response alert logs
Hillstone NetworksHillstone Networks FirewallHillstone Networks Firewall alert logs
TophantTophant Full-Traffic Security Computing and Analysis PlatformTophant Full-Traffic Security Computing and Analysis Platform product alert logs
SkyGuardDLPDLP alert logs
AzureAzure Active DirectoryAzure Active Directory audit logs and Azure Active Directory logon audit logs
ThreatbookOneSECOneSEC alert logs
CiscoCisco Firepower FirewallFirewall alert logs
Palo AltoNext-Generation FirewallFirewall alert logs
Cortex XDRPalo Alto Cortex alert logs and endpoint alert logs
PanoramaPanorama product logs
Ege CloudPolarisLayer 4 internal network access logs and data audit logs
Custom vendorCustom productFirewall alert logs, firewall traffic logs, Web Application Firewall (WAF) alert logs, and WAF traffic logs