Google SecOps
100 updates from Google Cloud.
Expanded read-only permissions for Chronicle API Restricted Data Access Viewer
Expanded read-only permissions for Chronicle API Restricted Data Access Viewer Google SecOps has updated the predefined Chronicle API Restricted Data Access Viewer…
Google Cloud organization ID enrichment for direct ingestion
Google Cloud organization ID enrichment for direct ingestion Google SecOps now automatically enriches logs ingested through <a…
Resizable side panels in the Investigation Management experience
Resizable side panels in the Investigation Management experience You can now dynamically resize the Case preview and Alert and detection preview side panels in the revamped Investigation Management…
Grok filter match_all option in parser syntax
Grok filter match_all option in parser syntax The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all…
[Spotlight Feature] GoogleSQL query support in Search
[Spotlight Feature] GoogleSQL query support in Search This feature is in public preview. You can now use GoogleSQL in Search to query your security data in Google SecOps, offering a flexible and…
Deprecation of write permissions from the chronicle.readonly OAuth scope
Deprecation of write permissions from the chronicle.readonly OAuth scope Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it…
[Spotlight Feature] Case playbooks
[Spotlight Feature] Case playbooks This feature is in preview. Google SecOps now supports case playbooks. You can run playbooks or execute manual actions across an entire case container rather…
[Spotlight Feature] Reaction triggers
[Spotlight Feature] Reaction triggers This feature is in preview. Google SecOps now supports reaction triggers. As post-ingestion triggers, they allow playbooks to automatically fire in response to…
Self-service Bindplane Enterprise license download
Self-service Bindplane Enterprise license download This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus…
Scheduled maintenance
Scheduled maintenance SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 30. During this window, your system will…
[Spotlight Feature] Mandiant Frontline Threats rule packs
[Spotlight Feature] Mandiant Frontline Threats rule packs <a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections">Curated Detections</a> has been enhanced with additional…
Unroll Processor for Data Processing Pipelines
Unroll Processor for Data Processing Pipelines Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing…
[Spotlight Feature] Operations in Emerging Threats Center
[Spotlight Feature] Operations in Emerging Threats Center Google SecOps now supports Operations in the Emerging Threats Center feed to provide rapid visibility into threat activity details involving…
[Spotlight Feature] Relative time filtering in Google SecOps
[Spotlight Feature] Relative time filtering in Google SecOps This feature is in public preview. Google SecOps has updated how relative time filters calculate data ranges. You can now choose from…
Side-by-side view on the Alerts & Detections tab in Cases
Side-by-side view on the Alerts & Detections tab in Cases This feature is in public preview. The Alerts & Detections tab in the revamped Investigation Management experience now supports…
[Spotlight Feature] Event simulation for detection coverage evaluation
[Spotlight Feature] Event simulation for detection coverage evaluation This feature is in public preview. You can now programmatically deliver realistic threat sequences into the live ingestion…
[Spotlight Feature] Monitor your data latency with the Health Hub
[Spotlight Feature] Monitor your data latency with the Health Hub This feature is in public preview. The Health Hub now includes two new tables to track the ingestion latency at both the source…
Scheduled Maintenance
Scheduled Maintenance SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 16. During this window, your system will…
[Spotlight Feature] Analyze feed activity with Cloud Logging
[Spotlight Feature] Analyze feed activity with Cloud Logging This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project…
Self-service Bindplane Enterprise license download
Self-service Bindplane Enterprise license download This feature is currently in Preview. Google SecOps Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane…
[Spotlight Feature] Analyze feed activity with Cloud Logging
[Spotlight Feature] Analyze feed activity with Cloud Logging This feature is in public preview. You can now monitor, debug, and troubleshoot Google SecOps ingestion pipelines and feeds using Cloud…
Updated rich-text editor
Updated rich-text editor Upgraded the rich-text editor across Google SecOps, including the Cases Wall, Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget. Key changes…
[Spotlight Feature] Threat Hunt Agent
[Spotlight Feature] Threat Hunt Agent The Threat Hunt Agent is now available in Public Preview for Google SecOps Enterprise Plus customers. Powered by Gemini and grounded in Google Threat…
Scheduled Maintenance
Scheduled Maintenance SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on August 2. During this window, environments will experience a…
View prebuilt parser version content
View prebuilt parser version content You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated…
[Spotlight Feature] Data RBAC for first-party (1P) cases and alerts
[Spotlight Feature] Data RBAC for first-party (1P) cases and alerts Availability This feature is now available in public preview for all regions. Google SecOps now supports data role-based access…
[Spotlight Feature] Investigation and case management experience
[Spotlight Feature] Investigation and case management experience This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking…
Customizable schedules for multi-event rules
Customizable schedules for multi-event rules <a href="https://docs.cloud.google.com/chronicle/docs/detection/set-customized-schedule">Customizable schedules for multi-event rules</a> are available…
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs Google Security Operations is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecating</a> its…
[Spotlight Feature] Advanced Filtering in Dashboards
[Spotlight Feature] Advanced Filtering in Dashboards Advanced Filtering in dashboards is now available in Preview. This feature enhances dashboard capabilities by enabling security analysts to use…
SOAR migration to Google Cloud validation status
SOAR migration to Google Cloud validation status You can now check if the SOAR migration was successful by going to the SOAR Settings > License Management page. After successful completion of…
Publisher Agent Version 2.7.0
Publisher Agent Version 2.7.0 Publisher Agent Version 2.7.0 is now available for all regions. This release includes the following updates for the remote agent: • High Availability support: Adds…
Data RBAC for first-party (1P) cases and alerts in public preview
Data RBAC for first-party (1P) cases and alerts in public preview Availability: This feature is available only in the following regions: europe-central2, asia-northeast1, asia-south1,…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated…
Improved documentation portal navigation
Improved documentation portal navigation Finding help is now easier! We've updated the navigation of our documentation portal to be primarily user-centric. Sections have been reorganized and renamed…
Ingestion metrics reporting correction
Ingestion metrics reporting correction Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were…
[Spotlight Feature] Ask Gemini Cloud Assist in Feed Management
[Spotlight Feature] Ask Gemini Cloud Assist in Feed Management Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface. Use the new Ask Gemini Cloud Assist…
Breaking: Critical Notice: Upcoming reservation of siemAlertId field
Critical Notice: Upcoming reservation of siemAlertId field Effective July 5, 2026, the siemAlertId field will be strictly reserved for internal Chronicle SIEM alert IDs. Starting July 5, the system…
Scheduled Maintenance
Scheduled Maintenance CloudSQL will undergo a scheduled minor upgrade this Sunday, June 21, 2026.
Auto-collapse setting for the query editor
Auto-collapse setting for the query editor You can now configure the query editor to automatically collapse after you run a search, maximizing the screen space available for viewing your search…
New Documentation changelogs
New Documentation changelogs Google SecOps is now releasing a monthly changelog to capture major documentation updates. For more information, refer to <a…
Non-prioritized IoC Matching rules Category
Non-prioritized IoC Matching rules Category Google SecOps has introduced a new detection category, Non-prioritized IoC Matching rules, as part of the <a…
Asynchronous Search APIs for large datasets
Asynchronous Search APIs for large datasets Google SecOps now supports asynchronous Search APIs that let you perform long-running queries without blocking your applications. This is ideal for…
[Spotlight Feature] Search for cases using SIEM Search
[Spotlight Feature] Search for cases using SIEM Search Google SecOps SIEM Search now provides robust capabilities for analyzing cases and case history alongside existing Unified Data Model (UDM)…
[Spotlight Feature] Investigate detections in Google SecOps Search
[Spotlight Feature] Investigate detections in Google SecOps Search Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or…
UDM fields now show whether data is enriched or not
UDM fields now show whether data is enriched or not The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to…
UDM fields now show the sources of enrichment
UDM fields now show the sources of enrichment The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its…
The Manage access to preview features feature has been rolled back.
The <a href="https://docs.cloud.google.com/chronicle/docs/secops/release-notes#May_28_2026">Manage access to preview features feature</a> has been rolled back.
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region. The following…
[Spotlight Feature] Unified and Upgraded Chronicle API
[Spotlight Feature] Unified and Upgraded Chronicle API <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> has been unified with API resources from <a…
[Spotlight Feature] Manage access to preview features
[Spotlight Feature] Manage access to preview features Google Sec0ps tenant administrators can enable or disable access to public preview features. Previously, all public preview features needed to…
Standard parser support policy
Standard parser support policy Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The…
Time range selection for searches
Time range selection for searches Google SecOps has now added relative and absolute time range options to define the required time period for retrieving search results. • Relative time range: Set a…
[Spotlight Feature] Create and manage calculated fields
[Spotlight Feature] Create and manage calculated fields The Calculated Fields feature is now available in Preview. With Calculated Fields, you can dynamically derive new data points within Google…
The updateDataExport endpoint in the enhanced Data Export API is deprecated.
The updateDataExport endpoint in the enhanced Data Export API is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecated</a>. The reduction in job queue times using the <a…
The fetchavailablelogtypes API endpoint is deprecated in favor of the list endpoint.
The <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1alpha/projects.locations.instances.dataExports/fetchavailablelogtypes">fetchavailablelogtypes</a> API endpoint is <a…
The legacy Data Export API is deprecated in favor of the enhanced Data Export API, which provides a more secure and...
The legacy Data Export API is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecated</a> in favor of the <a…
New parser documentation now available
New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…
Time range selection for searches
Time range selection for searches Google SecOps has now added relative and absolute time range options to define the required time period for retrieving search results. • Relative time range: Set a…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated…
Enhanced "Time to respond" options for multi-choice questions
Enhanced "Time to respond" options for multi-choice questions Google SecOps now provides more granular control over playbook execution when the "time to respond" for a MultiChoiceQuestion step is…
VPC Service Controls for Google SecOps general availability
VPC Service Controls for Google SecOps general availability VPC Service Controls is now GA. This feature helps to create perimeters and protect resources and services data from accidental or…
New parser documentation now available
New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…
Unified and upgraded Chronicle API
Unified and upgraded Chronicle API <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest?rep_location=africa-south1">Chronicle API</a> has been unified with API resources from <a…
Emerging Threats Center general availability
Emerging Threats Center general availability The Emerging Threats Center is now in General Availability (GA) and includes the following new features and enhancements: • Expanded campaign filtering:…
Search query editor enhancements
Search query editor enhancements Google SecOps has enhanced the search query editor to provide intelligent auto-suggestions and improved error handling. • Auto-suggestions: The query editor now…
Health Hub
Health Hub This feature is currently in Preview. The Health Hub is the central location in Google Security Operations for you to monitor the status and health of all configured data sources. The…
Updates to search query limits and error messaging
Updates to search query limits and error messaging Google SecOps has updated search query limits for programmatic and web interface access: • Increased Queries Per Hour (QPH) limits of up to 2,000…
v1 Cloud Storage Feed Types (GCS, S3, SQS, Azure)
v1 Cloud Storage Feed Types (GCS, S3, SQS, Azure) The v1 feed types for GOOGLE_CLOUD_STORAGE, AMAZON_S3, AMAZON_SQS, and AZURE_BLOBSTORE are deprecated and will be discontinued on March 15, 2027.…
Playbook Condition and Multi-Choice Question Flows
Playbook Condition and Multi-Choice Question Flows The maximum number of branches supported in Playbook Conditions and Multiple Choice Questions has been increased from 6 to 20. This allows for more…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated…
Chrome Enterprise Premium Integration general availability
Chrome Enterprise Premium Integration general availability The Chrome Enterprise Premium integration is now GA. This release includes the following new features and updates: • New <a…
Multi-stage queries in YARA-L
Multi-stage queries in YARA-L The Multi-stage queries feature is now GA. This feature lets you feed the output of one query stage into the input of another, providing more granular data…
Credential validation for third-party API connectors
Credential validation for third-party API connectors Credential validation is now available for all 49 third-party API connectors. When you create a feed using a third-party API connector, Google…
New parser documentation now available
New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…
Agentic Automation
Agentic Automation This feature is in Public Preview. You can now use Agentic Automation to embed AI Agents directly into your workflows. This feature lets you integrate AI-driven capabilities into…
View Triage and Investigation Agent (TIN) results in the Case Summary
View Triage and Investigation Agent (TIN) results in the Case Summary This feature is currently in Preview and is part of a gradual rollout. You can now view TIN results and verdict summaries…
Bindplane features for Google SecOps general availability
Bindplane features for Google SecOps general availability The following <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/use-bindplane-agent">Bindplane</a> features that relate to…
Manage parser versions
Manage parser versions The <a href="https://docs.cloud.google.com/chronicle/docs/secops/release-notes#October_07_2025">Manage parser versions</a> feature is in Public Preview for all customers.
Set up and manage data processing pipelines
Set up and manage data processing pipelines This feature is currently in Preview. You can now use the Data Processing pipelines to filter, transform, and redact Google SecOps data before ingestion.…
Google Agentic SOC Trial
Google Agentic SOC Trial There will be a no-cost trial for the Google SecOps Triage Investigative Agent (TIN) from April 1, 2026 to June 30, 2026. TIN is an agentic AI feature for Google SecOps…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region. For more…
Manage parser versions
Manage parser versions The <a href="https://docs.cloud.google.com/chronicle/docs/secops/release-notes#October_07_2025">Manage parser versions</a> feature is now in General Availability. For more…
New Unified rules interface
New Unified rules interface This feature is currently in Preview. Google Secops has launched a unified rules interface that brings custom and curated rule management into a single, cohesive…
Added support for Google Cloud VPC Service Controls
Added support for Google Cloud VPC Service Controls This feature is currently in Preview. <a href="https://docs.cloud.google.com/chronicle/docs/secops/vpcsc-for-secops">VPC Service Controls</a>…