Google SecOps SIEM
76 updates from Google Cloud.
Google Cloud organization ID enrichment for direct ingestion
Google Cloud organization ID enrichment for direct ingestion Google SecOps now automatically enriches logs ingested through <a…
Grok filter match_all option in parser syntax
Grok filter match_all option in parser syntax The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all…
Deprecation of write permissions from the chronicle.readonly OAuth scope
Deprecation of write permissions from the chronicle.readonly OAuth scope Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it…
Self-service Bindplane Enterprise license download
Self-service Bindplane Enterprise license download This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus…
[Spotlight Feature] Mandiant Frontline Threats rule packs
[Spotlight Feature] Mandiant Frontline Threats rule packs <a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections">Curated Detections</a> has been enhanced with additional…
Unroll Processor for Data Processing Pipelines
Unroll Processor for Data Processing Pipelines Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing…
[Spotlight Feature] Analyze feed activity with Cloud Logging
[Spotlight Feature] Analyze feed activity with Cloud Logging This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project…
[Spotlight Feature] Analyze feed activity with Cloud Logging
[Spotlight Feature] Analyze feed activity with Cloud Logging This feature is in public preview. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using…
Self-service Bindplane Enterprise license download
Self-service Bindplane Enterprise license download This feature is currently in Preview. Google SecOps Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane…
View prebuilt parser version content
View prebuilt parser version content You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated…
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs Google Security Operations is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecating</a> its…
Advanced Filtering in Dashboards
Advanced Filtering in Dashboards This feature is in Public Preview. Advanced Filtering in dashboards is now available in Google SecOps. This feature enhances dashboard capabilities by enabling…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated…
Improved documentation portal navigation
Improved documentation portal navigation Finding help is now easier! We've updated the navigation of our documentation portal to be primarily user-centric. Sections have been reorganized and renamed…
Ask Gemini Cloud Assist in Feed Management
Ask Gemini Cloud Assist in Feed Management Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation, setup, and general…
Ingestion metrics reporting correction
Ingestion metrics reporting correction Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were…
Auto-collapse setting for the query editor
Auto-collapse setting for the query editor You can now configure the query editor to automatically collapse after you run a search, maximizing the screen space available for viewing your search…
New Documentation changelogs
New Documentation changelogs Google SecOps is now releasing a monthly changelog to capture major documentation updates. For more information, refer to <a…
[Spotlight Feature] Ask Gemini Cloud Assist in Feed Management
[Spotlight Feature] Ask Gemini Cloud Assist in Feed Management Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation,…
Non-prioritized IoC Matching rules Category
Non-prioritized IoC Matching rules Category Google SecOps has introduced a new detection category, Non-prioritized IoC Matching rules, as part of the <a…
Asynchronous Search APIs for large datasets
Asynchronous Search APIs for large datasets Google SecOps now supports asynchronous Search APIs that let you perform long-running queries without blocking your applications. This is ideal for…
[Spotlight Feature] Investigate detections in Google SecOps Search
[Spotlight Feature] Investigate detections in Google SecOps Search Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or…
UDM fields now show whether data is enriched or not
UDM fields now show whether data is enriched or not The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to…
UDM fields now show the sources of enrichment
UDM fields now show the sources of enrichment The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region. The following…
Upgraded Chronicle API
Upgraded Chronicle API We've upgraded the following <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> resources from v1 beta to v1. This upgrade signals API…
Standard parser support policy
Standard parser support policy Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The…
Enhanced Data Export API general availability and improvements
Enhanced Data Export API general availability and improvements The Data Export API is now GA and introduces significant security and capability improvements. This feature facilitates the bulk export…
The legacy Data Export API is deprecated in favor of the enhanced Data Export API, which provides a more secure and...
The legacy Data Export API is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecated</a> in favor of the <a…
The fetchavailablelogtypes API endpoint is deprecated in favor of the list endpoint.
The <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1alpha/projects.locations.instances.dataExports/fetchavailablelogtypes">fetchavailablelogtypes</a> API endpoint is <a…
The updateDataExport endpoint in the enhanced Data Export API is deprecated.
The updateDataExport endpoint in the enhanced Data Export API is <a href="https://docs.cloud.google.com/chronicle/docs/deprecations">deprecated</a>. The reduction in job queue times using the <a…
New parser documentation now available
New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…
Time range selection for searches
Time range selection for searches Google SecOps has now added relative and absolute time range options to define the required time period for retrieving search results. • Relative time range: Set a…
Google SecOps has updated the list of list of supported default parsers.
Google SecOps has updated the list of list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are updated…
New parser documentation now available
New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…
Emerging Threats Center general availability
Emerging Threats Center general availability The Emerging Threats Center is now in General Availability (GA) and includes the following new features and enhancements: • Expanded campaign filtering:…
Search query editor enhancements
Search query editor enhancements Google SecOps has enhanced the search query editor to provide intelligent auto-suggestions and improved error handling. • Auto-suggestions: The query editor now…
Health Hub
Health Hub This feature is currently in Preview. The Health Hub is the central location in Google Security Operations for you to monitor the status and health of all configured data sources. The…
v1 Cloud Storage Feed Types (GCS, S3, SQS, Azure)
v1 Cloud Storage Feed Types (GCS, S3, SQS, Azure) The v1 feed types for GOOGLE_CLOUD_STORAGE, AMAZON_S3, AMAZON_SQS, and AZURE_BLOBSTORE are deprecated and will be discontinued on March 15, 2027.…
Updates to search query limits and error messaging
Updates to search query limits and error messaging Google SecOps has updated search query limits for programmatic and web interface access: • Increased Queries Per Hour (QPH) limits of up to 2,000…
Google Security Operations has updated the list of supported default parsers.
Google Security Operations has updated the list of <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/parser-list/supported-default-parsers">supported default parsers</a>. Parsers are…
Multi-stage queries in YARA-L
Multi-stage queries in YARA-L The Multi-stage queries feature is now GA. This feature lets you feed the output of one query stage into the input of another, providing more granular data…
Credential validation for third-party API connectors
Credential validation for third-party API connectors Credential validation is now available for all 49 third-party API connectors. When you create a feed using a third-party API connector, Google…
New parser documentation now available
New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…
Bindplane features for Google SecOps general availability
Bindplane features for Google SecOps general availability The following <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/use-bindplane-agent">Bindplane</a> features that relate to…
Manage parser versions
Manage parser versions The <a href="https://docs.cloud.google.com/chronicle/docs/release-notes#October_07_2025">Manage parser versions</a> feature is in Public Preview for all customers.
Set up and manage data processing pipelines
Set up and manage data processing pipelines This feature is currently in Preview. You can now use the Data Processing pipelines to filter, transform, and redact Google SecOps data before ingestion.…
Google SecOps has updated the list of supported default parsers.
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region. For more…
Manage parser versions
Manage parser versions The <a href="https://docs.cloud.google.com/chronicle/docs/release-notes#October_07_2025">Manage parser versions</a> feature is now in General Availability. For more…
New Unified rules interface
New Unified rules interface This feature is currently in Preview. Google SecOps has launched a unified rules interface that brings custom and curated rule management into a single, cohesive…
Release 6.3.78 is being rolled out to the first phase of regions as listed here.
Release 6.3.78 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>. This…
Release 6.3.77 is now available for all regions.
<a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#February_22_2026">Release 6.3.77</a> is now available for all regions.
Added support for Google Cloud VPC Service Controls
Added support for Google Cloud VPC Service Controls This feature is currently in Preview. <a href="https://docs.cloud.google.com/chronicle/docs/secops/vpcsc-for-secops">VPC Service Controls</a>…
RBAC for ingestion metrics
RBAC for ingestion metrics Administrators can now use RBAC for ingestion metrics to restrict visibility of system health data, such as ingestion volume, errors, and throughput, based on a user's…
New: cross joins in multi-stage queries
New: cross joins in multi-stage queries You can now use cross joins in YARA-L 2.0 multi-stage queries let you compare individual UDM event data against aggregated statistics calculated in previous…
New parser documentation now available
New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…
Release 6.3.77 is being rolled out to the first phase of regions as listed here.
Release 6.3.77 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>. This…
Release 6.3.76 is now available for all regions.
<a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#February_15_2026">Release 6.3.76</a> is now available for all regions.
New capabilities in Feeds page
New capabilities in Feeds page The following options have been added to the Feeds page: • Search • Filtering (using feed attributes) • Pagination • Last Refreshed Time • Feed Metadata Export to CSV
Control of MCP use with organization policies is deprecated.
Control of MCP use with organization policies is deprecated. After March 17, 2026, organization policies that use the gcp.managed.allowedMCPServices constraint won't work, and you can control MCP use…
Release 6.3.76 is being rolled out to the first phase of regions as listed here.
Release 6.3.76 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>. This…
Release 6.3.75 is now available for all regions.
<a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#February_08_2026">Release 6.3.75</a> is now available for all regions.
Advanced Joins in Search
Advanced Joins in Search Google SecOps now supports expanded capabilities for correlating data across multiple sources. These join operations are also supported in multistage queries. Joins without…
Enhanced rule observability: New metadata, visual indicators, and dashboards
Enhanced rule observability: New metadata, visual indicators, and dashboards Google Security Operations has introduced updates to how detection and alert data is processed and visualized. These…