When logs are scattered across cloud services, third-party tools, and self-managed applications, unified threat detection becomes difficult. Agentic SOC provides a central Integration Center to collect, standardize, and analyze log data from any source — so you can apply consistent detection rules across your entire environment and respond to threats efficiently.
How it works
Agentic SOC uses a modular configuration system to automate log ingestion and standardization. Four components work together to form the pipeline:
Data Source: The storage location for raw logs — typically a Project and Logstore in Simple Log Service (SLS).
NoteAgentic SOC supports three data source types: Agentic SOC Dedicated Collection Channel, User Log Service, and Security Center Log Service. See Data source type comparison for details.
Standardized Rule:
A set of SPL-based parsing instructions that extract key fields (such as source IP and destination port) from raw logs and convert them into Agentic SOC's unified structured format.
ImportantSupports ingesting extended fields with the Keep Original setting. Note that this increases ingestion traffic volume, resulting in higher costs.
Each Standardized Rule is associated with a Dataset — a predefined model of standard fields that determines what fields are available for log analysis. See Datasets.
Standardization Method: The technical pattern for processing logs after standardization. The supported methods are Real-time Consumption and Scan Query.For more information,See Dataset .
Access Policy: The core configuration that ties together the Data Source, Standardization Method, and Standardized Rule. It specifies how logs are read, parsed, and processed — and drives automatic log ingestion.
Integrate Alibaba Cloud products
This applies to Alibaba Cloud products that deliver logs to your SLS Logstores, such as Web Application Firewall (WAF), Cloud Firewall (CFW), and ActionTrail.
Integration flowchart
Step 1: Enable product log delivery
Enable the log audit feature for the target product and deliver its logs to SLS.
Alert logs from Alibaba Cloud security products in the central Logstore are automatically delivered to Agentic SOC — you don't need to enable the product's log service for these. Examples include WAF alert logs and CFW alert logs.
Go to the cloud product console (such as WAF or CFW) and find Log Management or Simple Log Service. For reference links, see References for integrating Alibaba Cloud product logs into SLS.
Follow the product documentation to enable log delivery. This typically creates a Project and one or more Logstores in SLS automatically.
NoteLog on to the Simple Log Service console to view the Project and Logstore created by the product. For example, WAF logs use a project named
wafnew-logstore.
Step 2: Enable built-in access policies
Enable manually
Configure the data source. Agentic SOC includes preconfigured data sources for major Alibaba Cloud products. Verify that these configurations match your Logstore information.
Find the cloud product.
Log on to the Security Center console > Agentic SOC > Management > Integration Settings. In the upper-left corner, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
On the Service Integration tab, set Ingestion Settings to Alibaba Cloud, select the product (such as Web Application Firewall), and click Ingestion Settings in the Actions column.
Check the data source status.
Click the name of the data source associated with the product. The page redirects to the Data Source tab.
Check the connection status:
Normal: Agentic SOC can access the Logstore. Proceed to the next step.
Abnormal: The configuration is incorrect. Click Edit in the Actions column and verify:
Instance information: Confirm the Region, Project, and Logstore match what was created in Step 1.
Source log service: Confirm the SLS Logstore is active — the Project is not disabled and new logs are being written.
Not connected: The data source is not configured. Click Edit in the Actions column, then click Create Instance and select the Region ID, Project and Logstore created in Step 1.
Enable the built-in access policy.
Return to the Service Integration tab and go to Access Settings for the product.
Modify the standardization method (optional). For some product policies, you can change the Standardization Method between Real-time Consumption and Scan Query. See Standardized fields and datasets.
ImportantIf the data source type is Security Center Log Service or the log type is an alert log, the method is fixed to Real-time Consumption and cannot be changed.
If the dataset (StoreView) associated with Standardization Category or Structure already has five Scan Query policies attached, select Real-time Consumption for the current policy. Otherwise, the policy cannot be enabled.

Log standardization test
If you changed the standardization method, run a test before enabling the policy.
WarningThe Logstore for the data source must contain data. The test cannot run on an empty Logstore.
Log sample selection: The system automatically fetches log samples from the last 7 days by default. You can also manually select a time range.
SPL syntax: The syntax from the current policy's standardization rule is synchronized by default. To modify the syntax, go to the Standardized rules and datasets tab and edit the rule.
After obtaining log samples, click Parse and Test.
After the test passes, click Complete.
NoteIf the test fails, see What do I do if the log standardization test fails or data cannot be parsed?
Enable the policy.
Turn on the switch in the Enabling Status column.
ImportantIf you enabled the recommended access policy when purchasing Agentic SOC, built-in policies for Security Center, WAF, Cloud Firewall, and ActionTrail are already enabled. See Enable access policies for subscription and Enable log access policies for pay-as-you-go.
Enable in batches (recommended)
Batch integration automatically enables access policies and discovers data sources across multiple products at once.
Access the Security Center console - Agentic SOC - Management - Access Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.
Configure batch integration.
Click Access Settings and complete the configuration:
Access Settings:
Increment Access: Keeps all enabled access policies and adds only the data sources and policies from the current configuration.
Full Access: Overwrites and replaces all existing access settings. Policies not selected in the current configuration are disabled.
WarningFull Access is an overwrite operation. It may disable running policies and interrupt data integration. Proceed with caution.
Accessible Account: Select the current account and its member accounts.
Alibaba Cloud Services: Select the cloud products and their corresponding data sources.
NoteTo quickly enable data analytics, click Use Recommended Policy. The system selects the data sources with the most analytical value for each product based on best practices.
Auto-Add New Data Sources: When enabled, new Logstores are automatically included in the data source's collection scope — no manual updates needed.
Confirm and start data integration.
Click OK. The system automatically:
Integrates all Logstores: Ingests all enabled Logstores associated with the selected products and accounts in SLS.
Activates access policies: Enables the access policies that correspond to the selected data sources.
ImportantNew access policies may take some time to deploy and initialize. Wait for the process to complete before verifying results.
Confirm the enabled status.
Return to the access list, select the product, and click Ingestion Settings in the Actions column.
NoteFor member accounts, go to Multi-account Access Settings, then click Multi-account Access in the Actions column for the target data source.
Check the access state in the access policy list. If the state is abnormal, check the data source status. See Check the data source status..
Step 3: Add a new access policy (optional)
Some products support custom access policies.
In the access policy list, click Create Access Policy.
NoteIf Create Access Policy is not displayed, the product does not support this feature.
On the Create Access Policy page, select the Data Source,Standardized Rule, and Standardization Method. If no suitable options exist, create a new data source and a custom standardization rule.
ImportantOnly data sources from the current account are supported. Data sources from member accounts cannot be used here.
Complete the Test Log Standardization and enable the policy.
Integrate third-party logs
Agentic SOC supports logs from third-party clouds (Fortinet, Chaitin, Microsoft, Sangfor, Tencent Cloud, Huawei Cloud, Hillstone Networks, Knownsec, and Microsoft Cloud) and custom product applications.
Integrate logs from third-party cloud products
Third-party cloud products with logs not in SLS
For Tencent Cloud and Huawei Cloud WAF and CFW products, Agentic SOC provides a built-in data import feature.
Supported products:
Cloud provider | Product | Log type |
Tencent Cloud | Web Application Firewall (WAF) | Attack log, access log |
Cloud Firewall (CFW) | Alert log | |
HUAWEI CLOUD | Web Application Firewall (WAF) | Attack log, access log |
Cloud Firewall (CFW) | Alert log |
Integration flowchart
Procedure
Create a data source. Create a dedicated Agentic SOC data source to receive the third-party cloud log data. Skip this step if you already have one.
Go to Security Center console > Agentic SOC > Management > Integration Settings. In the upper-left corner, select the region for the assets you want to protect: Chinese Mainland or Outside Chinese Mainland.
On the Data Source tab, create a data source. See Create a data source: Logs not in SLS.
Source Data Source Type: Select User Log Service or Agentic SOC Dedicated Collection Channel. See Data source type comparison.
Add Instances: We recommend that you create a new Logstore to isolate the data.
Import data. Follow Import Huawei Cloud log data or Import Tencent Cloud log data to import the third-party cloud data into the data source created in Step 1.
Configure an access policy.
On the Service Integration tab, set Ingestion Settings to the third-party vendor (such as Huawei Cloud).
Click Ingestion Settings for the target product, then click Create Access Policy.
Configure the data source:
Data Source Name: Select the data source created in Step 1.
Standardized Rule: Select the built-in standardization rules for Huawei Cloud or Tencent Cloud.
NoteYou can also create custom standardization rules.
Standardization Method: Only Real-time Consumption is supported. Scan Query is not available for this scenario.
On the Log Parsing page, click Parse and Test.
WarningThe Logstore corresponding to the data source must contain data. Otherwise, the test cannot proceed.
After the test passes, click Complete, then enable the policy.
Third-party logs already in SLS
If logs from products such as Fortinet, Chaitin, or Sangfor are already collected into an SLS Logstore (via Logtail or Syslog-ng), follow this flow. For data collection methods, see Data collection overview.
Configure the data source.
Find the integration product.
Go to Security Center console > Agentic SOC > Management > Integration Settings. In the upper-left corner, select the region where the assets you want to protect are located: Chinese Mainland or Outside Chinese Mainland.
On the Service Integration tab, set Ingestion Settings to the third-party vendor (such as Huawei Cloud).
Update the data source.
Click the name of the data source associated with the product. You are redirected to the Data Source tab. Click Edit in the Actions column.
Click Create Instance and select the Region ID, Project, and Logstore where the third-party logs are stored.
NoteLog on to the Simple Log Service console to find the Logstore information.
Enable the built-in access policy.
Return to the Service Integration tab and go to Access Settings for the product.
Click Edit in the Actions column for the built-in access policy. On the Log Parsing page, click Parse and Test. See Log standardization test .
After the test passes, click Complete, then enable the policy.
Integrate logs from custom product applications
Custom product applications
Use this flow to integrate logs from your own applications or products not covered by built-in integrations.
Before you begin, confirm the following:
Whether your logs are already collected in SLS. If not, decide whether to use Agentic SOC Dedicated Collection Channel (Agentic SOC creates and manages the Logstore) or User Log Service (you create the Logstore yourself).
You will need to write a custom SPL-based standardization rule for your log format.
Integration flowchart
Add a product.
Access the Security Center console - Agentic SOC - Management - Access Settings. In the upper-left corner of the page, select the region where the assets to be protected are located: Chinese Mainland or Outside Chinese Mainland.
On the Service Integration tab, in the Multi-cloud Service Access area, click Add Service and enter the Service Provider and Service Name.
Add a data source. On the Data Source tab, click Add Data Source. See Data source.
If logs are already in SLS: Set Source Data Source Type to User Log Service and select the corresponding Logstore.
NoteLog on to the Simple Log Service console to find the Logstore information.
If logs are not yet in SLS:
Agentic SOC Dedicated Collection Channel: Agentic SOC creates a dedicated Project (
aliyun-cloudsiem-channel-AlibabaCloudUID-cn-RegionID) and Logstore in SLS automatically.User Log Service: Go to the Simple Log Service console and create the Logstore first.
After configuring the data source, refer to Data Collection Overview or contact the SLS helpdesk to collect product logs and send them to the corresponding SLS Logstore.
Add a standardization rule.
On the Standardized Rule tab, click Create Custom Rule. See Create a custom standardization rule.
Set the vendor and product to match what you added in Step 1.
Add and enable an access policy.
Return to the Service Integration tab, find the product added in Step 1, and click Ingestion Settings in the Actions column.
On the Ingestion Settings page, click Create Access Policy and configure:
Data Source: Select the data source configured in Step 2.
Standardized Rule: Select the rule configured in Step 3.
Standardization Method: Real-time Consumption or Scan Query.
ImportantIf the data source type is Agentic SOC Dedicated Collection Channel, select Real-time Consumption.
On the Log Parsing page, click Parse and Test. See Log standardization test.
WarningThe data source's Logstore must contain data. The test cannot run on an empty Logstore.
After the test passes, click Complete, then enable the policy.
Analyze integrated data
After integrating product logs, configure threat detection rules to analyze logs, generate alerts, and respond to cloud security risks. See Configure threat detection rules.
Limitations
Scan Query policy limit: A dataset (associated with a standardized rule) supports a maximum of five access policies in Scan Query mode.
Multi-account integration:
Logs from member accounts can only be ingested using Real-time Consumption. Scan Query is not supported. See Multi-account management.
Custom access policies cannot be added for data sources from member accounts.
Standardization method restrictions: If the data source type is Agentic SOC Dedicated Collection Channel or the log type is an alert log, only Real-time Consumption is supported.
Billing
Log integration fees depend on the data source type.
See billing details for Agentic SOC subscription, Agentic SOC pay-as-you-go, and SLS billing.
Data source type | Agentic SOC billing | SLS billing | Notes |
Agentic SOC Dedicated Collection Channel | Log ingestion fees + log storage and write fees (consumes Log Ingestion Traffic) | Internet traffic fees (not storage or writes) | Agentic SOC creates and manages SLS resources, so Logstore storage and write fees are billed by Agentic SOC. |
User Log Service | Log ingestion (consumes Log Ingestion Traffic) | All costs: storage, writes, and data transfer | SLS manages all log resources and bills all associated fees. |
Security Center Log Service | Consumes Log Ingestion Traffic | None | Internal Security Center logs. No SLS fees apply. |
References
Standardization method comparison
Dimension | Real-time Consumption | Scan Query |
How it works | Write-time standardization: Agentic SOC consumes logs from the data source, standardizes them, and stores them in the Agentic SOC log space. | Schema-on-read: Reads logs directly from the data source without storing replicas. |
Core advantages | High query performance and fast analysis. | Lightweight deployment and lower cost. |
Log storage and fees | If you purchase Log Storage Capacity, standardized logs are automatically delivered to Log Management in Agentic SOC. This delivery consumes your Agentic SOC Log Storage Capacity and cannot be disabled. | No replicas stored. Raw log storage is billed by the source (SLS). |
Applicable data source types | Security Center Log Service, User Log Service, Agentic SOC Dedicated Collection Channel | User Log Service only (excluding alert logs) |
Performance and quota | No limit on the number of access policies. | Max five Scan Query policies per dataset; full indexes not available; query performance degrades as scanned data volume grows; |
Multi-account access | Supported | Not supported |
Scenario restrictions | Required if the data source is the Agentic SOC Dedicated Collection Channel or the log type is an alert log. | None |
Data source type comparison
Dimension | User Log Service | Agentic SOC Dedicated Collection Channel | Security Center Log Service |
Log storage and management | You manage your own SLS projects and Logstores. | Agentic SOC automatically creates and manages dedicated SLS projects and Logstores. | Security Center internal logs; not stored in your SLS. |
Supported standardization methods | Real-time Consumption, Scan Query (excluding alert logs) | Real-time Consumption | Real-time Consumption |
Use cases | Ingest logs delivered to SLS from Alibaba Cloud products (WAF, CFW, etc.) or collected to SLS from third-party products using Logtail. | Collect logs from third-party clouds (Tencent Cloud, Huawei Cloud) not already in SLS; collect custom application logs without an existing delivery method. | Analyze internal Security Center logs. |
References for integrating Alibaba Cloud product logs into SLS
Web Application Firewall: WAF 3.0 logs
Cloud Firewall: Cloud Firewall logs
Bastionhost: Archive audit logs to Simple Log Service
ActionTrail: Platform operation logs
Anti-DDoS: Get started with full log analysis
CDN: Best practices for delivering CDN real-time logs to SLS
API Gateway: API Gateway access logs
Container Service for Kubernetes: Log management
PolarDB: Log analysis
ApsaraDB for MongoDB: MongoDB logs
RDS: RDS SQL Audit Log, Deliver RDS MySQL logs to Simple Log Service
Server Load Balancer: ALB access logs, CLB access logs, Layer-7 access logs for CLB, Layer-4 monitoring metrics for CLB
Object Storage Service: OSS access log
File Storage NAS: Log analysis based on SLS
CloudConfig: Configuration Audit Log
Log Service (SLS) Log Collection Reference
Logstash: Use Logstash to upload logs
OSS: Import OSS data
Log4j: Collect Log4j logs
Alibaba Cloud Log Collection Agent: LoongCollector (formerly Logtail)
Collection Selection Guide: Data collection
FAQ
Why does the data source show "Abnormal" or "Not connected"?
Check the
AliyunServiceRoleForSasservice-linked role first — it must have at leastAliyunLogReadOnlyAccesson the SLS Logstore. This is the most common cause.If permissions are correct, go to the data source edit page in Agentic SOC and verify the Region, Project, and Logstore names (watch for typos and extra spaces).
Finally, log on to the SLS console and confirm the Project is not disabled and new data is being written.
Why does the access policy fail to enable?
Each dataset (StoreView) supports a maximum of five access policies in Scan Query mode. If you've hit this limit, switch the policy's standardization method to Real-time Consumption. See Access policy fails to be enabled.
What do I do if the log standardization test fails or data cannot be parsed?
First, confirm the SLS Logstore contains recent data (preferably written within the last hour) — the test cannot run on an empty Logstore.
If the Logstore has data but the test still fails, check whether the SPL statement in your standardization rule correctly parses the raw log format. Debug the SPL statement on the query and analysis page in the SLS console.