ServicesGoogle CloudGoogle SecOps SIEM

Google SecOps SIEM

68 updates from Google Cloud.

Get Google SecOps SIEM updates weekly
Google SecOps SIEMfeature

View prebuilt parser version content

View prebuilt parser version content You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is…

Google SecOps SIEMfeature

Advanced Filtering in Dashboards

Advanced Filtering in Dashboards This feature is in Public Preview. Advanced Filtering in dashboards is now available in Google SecOps. This feature enhances dashboard capabilities by enabling…

Google SecOps SIEMannouncement

Improved documentation portal navigation

Improved documentation portal navigation Finding help is now easier! We've updated the navigation of our documentation portal to be primarily user-centric. Sections have been reorganized and renamed…

Google SecOps SIEMfeature

Ask Gemini Cloud Assist in Feed Management

Ask Gemini Cloud Assist in Feed Management Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation, setup, and general…

Google SecOps SIEMchange

Ingestion metrics reporting correction

Ingestion metrics reporting correction Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were…

Google SecOps SIEMchange

Auto-collapse setting for the query editor

Auto-collapse setting for the query editor You can now configure the query editor to automatically collapse after you run a search, maximizing the screen space available for viewing your search…

Google SecOps SIEMannouncement

New Documentation changelogs

New Documentation changelogs Google SecOps is now releasing a monthly changelog to capture major documentation updates. For more information, refer to <a…

Google SecOps SIEMannouncement

Asynchronous Search APIs for large datasets

Asynchronous Search APIs for large datasets Google SecOps now supports asynchronous Search APIs that let you perform long-running queries without blocking your applications. This is ideal for…

Google SecOps SIEMfeature

UDM fields now show the sources of enrichment

UDM fields now show the sources of enrichment The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its…

Google SecOps SIEMfeature

Upgraded Chronicle API

Upgraded Chronicle API We've upgraded the following <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> resources from v1 beta to v1. This upgrade signals API…

Google SecOps SIEMfeature

Standard parser support policy

Standard parser support policy Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The…

Google SecOps SIEMannouncement

New parser documentation now available

New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…

Google SecOps SIEMchange

Time range selection for searches

Time range selection for searches Google SecOps has now added relative and absolute time range options to define the required time period for retrieving search results. • Relative time range: Set a…

Google SecOps SIEMannouncement

New parser documentation now available

New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…

Google SecOps SIEMannouncement

Emerging Threats Center general availability

Emerging Threats Center general availability The Emerging Threats Center is now in General Availability (GA) and includes the following new features and enhancements: • Expanded campaign filtering:…

Google SecOps SIEMchange

Search query editor enhancements

Search query editor enhancements Google SecOps has enhanced the search query editor to provide intelligent auto-suggestions and improved error handling. • Auto-suggestions: The query editor now…

Google SecOps SIEMfeature

Health Hub

Health Hub This feature is currently in Preview. The Health Hub is the central location in Google Security Operations for you to monitor the status and health of all configured data sources. The…

Google SecOps SIEMchange

Updates to search query limits and error messaging

Updates to search query limits and error messaging Google SecOps has updated search query limits for programmatic and web interface access: • Increased Queries Per Hour (QPH) limits of up to 2,000…

Google SecOps SIEMdeprecated

v1 Cloud Storage Feed Types (GCS, S3, SQS, Azure)

v1 Cloud Storage Feed Types (GCS, S3, SQS, Azure) The v1 feed types for GOOGLE_CLOUD_STORAGE, AMAZON_S3, AMAZON_SQS, and AZURE_BLOBSTORE are deprecated and will be discontinued on March 15, 2027.…

Google SecOps SIEMfeature

Multi-stage queries in YARA-L

Multi-stage queries in YARA-L The Multi-stage queries feature is now GA. This feature lets you feed the output of one query stage into the input of another, providing more granular data…

Google SecOps SIEMannouncement

New parser documentation now available

New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…

Google SecOps SIEMannouncement

Manage parser versions

Manage parser versions The <a href="https://docs.cloud.google.com/chronicle/docs/release-notes#October_07_2025">Manage parser versions</a> feature is in Public Preview for all customers.

Google SecOps SIEMfeature

Set up and manage data processing pipelines

Set up and manage data processing pipelines This feature is currently in Preview. You can now use the Data Processing pipelines to filter, transform, and redact Google SecOps data before ingestion.…

Google SecOps SIEMannouncement

Manage parser versions

Manage parser versions The <a href="https://docs.cloud.google.com/chronicle/docs/release-notes#October_07_2025">Manage parser versions</a> feature is now in General Availability. For more…

Google SecOps SIEMfeature

New Unified rules interface

New Unified rules interface This feature is currently in Preview. Google SecOps has launched a unified rules interface that brings custom and curated rule management into a single, cohesive…

Google SecOps SIEMfeature

RBAC for ingestion metrics

RBAC for ingestion metrics Administrators can now use RBAC for ingestion metrics to restrict visibility of system health data, such as ingestion volume, errors, and throughput, based on a user's…

Google SecOps SIEMfeature

New: cross joins in multi-stage queries

New: cross joins in multi-stage queries You can now use cross joins in YARA-L 2.0 multi-stage queries let you compare individual UDM event data against aggregated statistics calculated in previous…

Google SecOps SIEMannouncement

New parser documentation now available

New parser documentation now available New parser documentation is available to help you ingest and normalize logs from the following sources: • <a…

Google SecOps SIEMfeature

New capabilities in Feeds page

New capabilities in Feeds page The following options have been added to the Feeds page: • Search • Filtering (using feed attributes) • Pagination • Last Refreshed Time • Feed Metadata Export to CSV

Google SecOps SIEMfeature

Advanced Joins in Search

Advanced Joins in Search Google SecOps now supports expanded capabilities for correlating data across multiple sources. These join operations are also supported in multistage queries. Joins without…