AiStrike Documentation

Google SecOps / Chronicle

This document outlines a step-by-step guide to generate an API key for Chronicle SOAR using a service account and assign the API key with the appropriate permissions.◼︎

Step 1: Create a Service Account for AiStrike

  1. Log in to your Chronicle SOAR instance as an Administrator.

  2. Navigate to: Settings → Users & Roles → Service Accounts

  3. Click + Create Service Account

  4. Fill in the required details:

    • Name: aistrike_service_account

    • Description: Service account to allow AiStrike platform access to SOAR data

  5. Click Create

  6. Assign the required permission group:

    • In the Permission Group dropdown, select: Collaborator

    • Click Save

Step 2: Generate API Key for AiStrike

  1. Go to: Settings → Users & Roles → API Keys

  2. Click + Generate API Key

  3. Fill in the fields:

    • Name: aistrike_api_key

    • Service Account: Select aistrike_service_account

    • Expiration: Set per your security policy (e.g., 1 year). You may select No expiration if you handle key rotation manually.

  4. Click Create Key

  5. Once generated, copy and securely store the API key. It will only be visible once.

Create a collaborator user (SOAR standalone customers only)

To create a collaborator user, follow these steps:

  1. Go to Settings > Organization > User Management.

  2. Click Add.

  3. In the Add User dialog, select the following:

    • In the License Type field, select the Collaborator.

    • In the Permission Group list, choose Collaborator or any new group that you created for collaborator users.

    • In SOC Roles, add Administrator. If admin is not possible, then Tier3.

  4. Click Add.

Required Details for Integration with AiStrike

Please provide the following information to the AiStrike team or configure it in the AiStrike platform:

Field

Value / Description

Base URL

https://<your-tenant>.chronicle.security

API Key

<paste the aistrike_api_key here>

Service Account Name

aistrike_service_account

Permission Group

Collaborator

API Key Expiry

<as per your policy>

Once complete, send the integration details securely to AiStrike and connect with your Success Team for any guidance or next steps.