This document outlines a step-by-step guide to generate an API key for Chronicle SOAR using a service account and assign the API key with the appropriate permissions.◼︎
Step 1: Create a Service Account for AiStrike
-
Log in to your Chronicle SOAR instance as an Administrator.
-
Navigate to: Settings → Users & Roles → Service Accounts
-
Click + Create Service Account
-
Fill in the required details:
-
Name:
aistrike_service_account -
Description: Service account to allow AiStrike platform access to SOAR data
-
-
Click Create
-
Assign the required permission group:
-
In the Permission Group dropdown, select: Collaborator
-
Click Save
-
Step 2: Generate API Key for AiStrike
-
Go to: Settings → Users & Roles → API Keys
-
Click + Generate API Key
-
Fill in the fields:
-
Name:
aistrike_api_key -
Service Account: Select
aistrike_service_account -
Expiration: Set per your security policy (e.g., 1 year). You may select No expiration if you handle key rotation manually.
-
-
Click Create Key
-
Once generated, copy and securely store the API key. It will only be visible once.
Create a collaborator user (SOAR standalone customers only)
To create a collaborator user, follow these steps:
-
Go to Settings > Organization > User Management.
-
Click Add.
-
In the Add User dialog, select the following:
-
In the License Type field, select the Collaborator.
-
In the Permission Group list, choose Collaborator or any new group that you created for collaborator users.
-
In SOC Roles, add Administrator. If admin is not possible, then Tier3.
-
-
Click Add.
Required Details for Integration with AiStrike
Please provide the following information to the AiStrike team or configure it in the AiStrike platform:
|
Field |
Value / Description |
|---|---|
|
Base URL |
|
|
API Key |
<paste the aistrike_api_key here> |
|
Service Account Name |
|
|
Permission Group |
Collaborator |
|
API Key Expiry |
<as per your policy> |
Once complete, send the integration details securely to AiStrike and connect with your Success Team for any guidance or next steps.