Google Security Operations release notes

This page documents production updates to Google Security Operations. You can periodically check this page for announcements related to new or updated features, known issues, and deprecated functionality.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 18, 2026

Feature

Resizable side panels in the Investigation Management experience

You can now dynamically resize the Case preview and Alert and detection preview side panels in the revamped Investigation Management experience in Google SecOps. You can adjust the panel width using your mouse or keyboard shortcuts to view detailed telemetry, parsed UDM records, and raw logs without navigating away from your main case queue.

To explore the complete triage workflow, see Investigation and case management overview.

September 15, 2026

Feature

Grok filter match_all option in parser syntax

The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match.

For more information, see Parser syntax reference.

September 14, 2026

Feature

[Spotlight Feature] GoogleSQL query support in Search

This feature is in public preview. You can now use GoogleSQL in Search to query your security data in Google SecOps, offering a flexible and powerful industry-standard alternative to YARA-L 2.0. GoogleSQL is optimized for broad data exploration, statistical aggregation, and deep-dive ad hoc investigations. You can query telemetry tables including but not limited to UDM events, entity graphs, detection rules, and case management data—using either standard declarative SQL or the linear, sequential Piped SQL syntax.

For more information, see Get started with GoogleSQL.

Deprecated

MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed

The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.

September 11, 2026

Deprecated

Deprecation of write permissions from the chronicle.readonly OAuth scope

Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

September 06, 2026

Feature

[Spotlight Feature] Case playbooks

This feature is in preview. Google SecOps now supports case playbooks. You can run playbooks or execute manual actions across an entire case container rather than individual alerts, consolidating response tasks and reducing redundant operations during investigations.

For more information, see Case playbooks overview.

Feature

[Spotlight Feature] Reaction triggers

This feature is in preview. Google SecOps now supports reaction triggers. As post-ingestion triggers, they allow playbooks to automatically fire in response to real-time case or alert updates during active investigations, such as changes to the case assignee, case tags, alert priority, or newly added entities.

For more information, see Use reaction triggers in playbooks.

September 03, 2026

Feature

Self-service Bindplane Enterprise license download

This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane Enterprise (Google Edition) license key directly from the platform console under SIEM Settings > Collection Agents.

For more information, see Bindplane Enterprise (Google Edition).

August 31, 2026

Feature

[Spotlight Feature] Customizable schedules for multi-event rules general availability

The customizable schedules for multi-event rules feature is now in General Availability (GA).

Customizable schedules give security teams granular control and transparency over how multi-event rules execute in Google SecOps, and provide the following capabilities:

  • Configure settlement delays: Set first-run delay offsets (from 1 minute up to 48 hours) to account for log ingestion latency and reduce false negatives.
  • Leverage automated true-up runs: Automatically re-evaluate time windows at 4 hours (and optionally 30 hours for full context enrichment) to capture late-arriving logs.
  • Migrate legacy rules: Upgrade existing custom multi-event rules to customizable schedules directly from the Rules Dashboard.

To manage rule schedules with custom IAM roles, make sure your roles include chronicle.rules.modifyRules and chronicle.ruleDeployments.update. Predefined IAM roles include these permissions automatically.

For more information, see Configure customized schedules for rules and Understand rule run scheduling.

August 27, 2026

Announcement

Scheduled maintenance

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 30. During this window, your system will experience a brief period of downtime. You don't need to take any action.

August 26, 2026

Feature

[Spotlight Feature] Mandiant Frontline Threats rule packs

Curated Detections has been enhanced with additional Mandiant Frontline Threats detections for Linux, MacOS, and Google Cloud. The following rule packs have been added to the Content Hub:

August 24, 2026

Feature

Unroll Processor for Data Processing Pipelines

Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing arrays or slices of events into multiple individual log events prior to parsing and ingestion.

Key details:

  • Event Breaking Capability: Automatically expands log arrays into discrete log events.
  • Pre-parsing Requirement: The Unroll processor requires structured data inputs. Raw string payloads must first be parsed using a Transform processor (e.g., set(body, ParseJSON(body))) positioned prior to the Unroll processor in the pipeline execution sequence.

For details on configuring data processing pipelines and processors, see Set up and manage data processing pipelines.

Feature

[Spotlight Feature] Operations in Emerging Threats Center

Google SecOps now supports Operations in the Emerging Threats Center feed to provide rapid visibility into threat activity details involving the targeting of a single organization. Operations complement global Campaigns by providing granular threat intelligence derived from frontline investigations, such as Managed Threat Defense (MTD) engagements. For more information, see Operations in Emerging Threats.

Key capabilities include:

  • Focused threat insights: Zero in on localized adversary activity and personalized attack vectors specific to individual missions.
  • Holistic threat mapping: View Operations alongside global Campaigns to see the full scope of adversary tactics, techniques, and procedures (TTPs).

August 21, 2026

Feature

[Spotlight Feature] Relative time filtering in Google SecOps

This feature is in public preview. Google SecOps has updated how relative time filters calculate data ranges. You can now choose from three distinct, mathematically precise operators: Past, Previous, and Current. This change eliminates ambiguity between rolling windows and calendar-aligned periods, ensuring consistent behavior across all time units (like seconds, minutes, hours, days, weeks, months, years) and aligning SecOps dashboards with Search and other Google tools (such as Looker).

For more information, see the Relative time range section of the Understand search guide.

August 20, 2026

Feature

Side-by-side view on the Alerts & Detections tab in Cases

This feature is in public preview. The Alerts & Detections tab in the revamped Investigation Management experience now supports a Side-by-side view layout.

You can switch between the default List view and the Side-by-side view to inspect an alert or detection's detailed metadata, status, priority, creation date, and Gemini investigation insights in an adjacent side pane without navigating away from the main list.

For more information, see Investigation and case management overview.

August 18, 2026

Feature

[Spotlight Feature] Evaluate threat coverage and generate rules with the Detection Engineering Agent

This feature is in public preview. You can now evaluate and strengthen your Google SecOps security posture against emerging threats using the Detection Engineering Agent. This AI-powered assistant helps you extract threat intelligence and automatically draft YARA-L detection rules, drastically improves time-to-value for custom security automation and accelerating risk mitigation. The agent is accessible using Model Context Protocol (MCP) tools operated by compatible AI clients (such as Google Antigravity or Claude Code). For more information, see Evaluate threat coverage with the Detection Engineering Agent.

Feature

[Spotlight Feature] Event simulation for detection coverage evaluation

This feature is in public preview. You can now programmatically deliver realistic threat sequences into the live ingestion pipeline using event simulation. Event simulation provides a full-funnel detection coverage evaluation framework embedded directly within Google SecOps, enabling detection engineering and SOC teams to verify the entire detection lifecycle—from UDM normalization to multi-event correlation and alerting—while preserving production SOC workflows.

As a core capability of the Detection Engineering Agent (DEA) architecture, event simulation connects Google SecOps MCP tools with AI assistance (such as Gemini) to automate threat intel processing, synthetic telemetry generation, and YARA-L 2.0 rule coverage evaluation.

For more information, see Use event simulation for detection coverage evaluation.

August 14, 2026

Feature

[Spotlight Feature] Monitor your data latency with the Health Hub

This feature is in public preview. The Health Hub now includes two new tables to track the ingestion latency at both the source level and the log-type level. In addition, you can select a specific source or log type to open the Data Health Deep Dive page and view detailed information about ingestion latency. For more information, see Monitor health of data sources.

Key capabilities include:

  • Improve end-to-end visibility and reduce mean time to debug (MTTD): Google SecOps calculates latency at both the source level and the log type level to improve end-to-end visibility and help reduce the mean time to debug (MTTD) for delayed logs.
  • Monitor ingestion latency by source: View the ingestion latency for each individual data source.
  • Monitor ingestion latency by log type: View the ingestion latency for each individual log type.
  • View detailed information about ingestion latency: Select a specific source or log type to open the Data Health Deep Dive page and view detailed information about ingestion latency.

August 13, 2026

Announcement

Scheduled Maintenance

SOAR database and infrastructure maintenance is scheduled to take place during the standard maintenance window on Sunday, August 16. During this window, your system will experience a brief period of downtime. No customer action is required.

August 12, 2026

Feature

[Spotlight Feature] Analyze feed activity with Cloud Logging

This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in the Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.

This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:

  • Investigate telemetry: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
  • Debug feeds: Use the Debug with logs option on the Feed management page to open Logs Explorer pre-filtered for a specific feed.
  • Filter routed logs: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.

For more information, see Analyze feed activity with Cloud Logging.

August 09, 2026

Feature

Updated rich-text editor

Upgraded the rich-text editor across Google SecOps, including the Cases Wall, Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget.

Key changes include:

  • Simplified typography: Choose font sizes using semantic options (Small, Normal, Large, Huge). Legacy font sizes on existing text are preserved.
  • Streamlined tables: You can insert or remove entire tables. Formatting inside table cells is no longer supported.
  • Toolbar cleanup: Removed the Cut, Copy, and Paste buttons from the toolbar. Standard OS keyboard shortcuts remain supported.
  • Visual alignment: Improved visual consistency between editor content during editing and after submission.

August 03, 2026

Feature

[Spotlight Feature] Threat Hunt Agent

The Threat Hunt Agent is now available in Public Preview for Google SecOps Enterprise Plus customers. Powered by Gemini and grounded in Google Threat Intelligence (GTI), Mandiant frontline expertise, and the MITRE ATT&CK® framework, the Threat Hunt Agent autonomously automates proactive threat hunting across your historical security telemetry. For more information, see Threat Hunt Agent.

Key capabilities include:

  • Autonomous hunt planning: Generates structured hunting plans tailored to specific threat actors, campaigns, malware families, software toolkits, or MITRE ATT&CK techniques.
  • Automated case creation and determinations: Synthesizes findings into summaries, assigns a verdict (Substantial Evidence, Evidence Found, or Threat Not Found), and automatically creates a dedicated case in Case Management.
  • Automated query translation and execution: Converts investigative hypotheses into YARA-L 2.0 search queries and executes against historical security telemetry.
  • AI-driven evidence extraction: Filters out routine background noise to isolate high-fidelity forensic evidence (hostnames, user accounts, and command lines).
Announcement

The deadline for Stage 2 of the SOAR migration to Google Cloud has been extended from September 30th to November 30th, 2026. For more information, refer to the SOAR migration guide.

July 29, 2026

Change

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • Airlock Digital Application Allowlisting (AIRLOCK_DIGITAL)
  • AIX system (AIX_SYSTEM)
  • Akamai DataStream 2 (AKAMAI_DATASTREAM_2)
  • Akamai SIEM Connector (AKAMAI_SIEM_CONNECTOR)
  • Apache (APACHE)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Armis Alerts (ARMIS_ALERTS)
  • Aruba Switch (ARUBA_SWITCH)
  • Atlassian Cloud Admin Audit (ATLASSIAN_AUDIT)
  • Linux Auditing System (AuditD) (AUDITD)
  • Avaya Aura Experience Portal (AVAYA_AURA)
  • AWS Cloudtrail (AWS_CLOUDTRAIL)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS Control Tower (AWS_CONTROL_TOWER)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Azure AD (AZURE_AD)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Azure Application Gateway (AZURE_GATEWAY)
  • Azure Key Vault logging (AZURE_KEYVAULT_AUDIT)
  • Microsoft Azure Resource (AZURE_RESOURCE_LOGS)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • BeyondTrust (BOMGAR)
  • Cato Networks (CATO_NETWORKS)
  • Check Point (CHECKPOINT_FIREWALL)
  • Check Point Harmony (CHECKPOINT_HARMONY)
  • Chrome Management (CHROME_MANAGEMENT)
  • ChromeOS XDR (CHROMEOS_XDR)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco FireSIGHT Management Center (CISCO_FIRESIGHT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco UCM (CISCO_UCM)
  • Claroty Xdome (CLAROTY_XDOME)
  • Claude Compliance Logs (CLAUDE_COMPLIANCE_LOGS)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Cloudflare (CLOUDFLARE)
  • Palo Alto Cortex XDR Alerts (CORTEX_XDR)
  • CrowdStrike Falcon (CS_EDR)
  • Darktrace (DARKTRACE)
  • EfficientIP DDI (EFFICIENTIP_DDI)
  • F5 ASM (F5_ASM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • Fastly CDN (FASTLY_CDN)
  • FireEye eMPS (FIREEYE_EMPS)
  • FireEye HX (FIREEYE_HX)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint Proxy (FORCEPOINT_WEBPROXY)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet FortiClient (FORTINET_FORTICLIENT)
  • Fortinet Switch (FORTINET_SWITCH)
  • GCP Cloud Audit (GCP_CLOUDAUDIT)
  • Security Command Center External Exposure (GCP_SECURITYCENTER_EXTERNAL_EXPOSURE)
  • Gitlab (GITLAB)
  • Google Threat Intelligence IOC (GTI_IOC)
  • AWS GuardDuty (GUARDDUTY)
  • Huawei Switches (HUAWEI_SWITCH)
  • IBM Security Access Manager (IBM_SAM)
  • Microsoft IIS (IIS)
  • Illumio Core (ILLUMIO_CORE)
  • Imperva SecureSphere Management (IMPERVA_SECURESPHERE)
  • Infoblox (INFOBLOX)
  • Infoblox DHCP (INFOBLOX_DHCP)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • Mobile Endpoint Security (LOOKOUT_MOBILE_ENDPOINT_SECURITY)
  • Apple macOS (MACOS)
  • McAfee IPS (MCAFEE_IPS)
  • Micro Focus iManager (MICROFOCUS_IMANAGER)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Defender for Office 365 (MICROSOFT_DEFENDER_MAIL)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft Sentinel (MICROSOFT_SENTINEL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mimecast URL Logs (MIMECAST_URL_LOGS)
  • MISP Threat Intelligence (MISP_IOC)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Unix system (NIX_SYSTEM)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Onapsis (ONAPSIS)
  • OpenVPN (OPEN_VPN)
  • Oracle Fusion (ORACLE_FUSION)
  • Ping Identity (PING)
  • Proofpoint Sendmail Sentrion (PROOFPOINT_SENDMAIL_SENTRION)
  • SailPoint IAM (SAILPOINT_IAM)
  • Salesforce (SALESFORCE)
  • Sendmail (SENDMAIL)
  • Sentinelone Alerts (SENTINELONE_ALERT)
  • ServiceNow Audit (SERVICENOW_AUDIT)
  • ServiceNow CMDB (SERVICENOW_CMDB)
  • ServiceNow Security (SERVICENOW_SECURITY)
  • SonicWall (SONIC_FIREWALL)
  • STIX Threat Intelligence (STIX)
  • Tanium Threat Response (TANIUM_THREAT_RESPONSE)
  • Thinkst Canary (THINKST_CANARY)
  • ThreatConnect IOC V3 (THREATCONNECT_IOC_V3)
  • ThreatLocker Platform (THREATLOCKER)
  • Varonis (VARONIS)
  • VMware ESXi (VMWARE_ESX)
  • Windows DNS (WINDOWS_DNS)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • wiz.io (WIZ_IO)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Zoom Operation Logs (ZOOM_OPERATION_LOGS)

The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.

  • Adobe Experience Platform (ADOBE_EXPERIENCE_PLATFORM)
  • AudioCodes Session Border Controller (AUDIOCODES_SBC)
  • Azure Application Gateway for Containers (AZURE_GATEWAY_CONTAINERS)
  • Azure Logic Apps (AZURE_LOGIC_APPS)
  • Azure NAT Gateway Flow (AZURE_NATGW_FLOW)
  • Broadcom DX NetOps Spectrum (BROADCOM_DX_NETOPS_SPECTRUM)
  • Carto Activity (CARTO_ACTIVITY)
  • Claude Code Observability (CLAUDE_CODE_OBSERVABILITY)
  • Cyble Attack Surface Management (CYBLE_ASM)
  • Cyble Brand Intelligence & Protection (CYBLE_BIP)
  • Darkweb IQ (DARKWEB_IQ)
  • Ellio Threat Intelligence (ELLIO_THREAT_INTEL)
  • Exeon NDR (EXEON_NDR)
  • Gravitee (GRAVITEE)
  • Kaspersky anti targeted attack (KASPERSKY_ANTI_TARGETED_ATTACK)
  • Microsoft Copilot Interaction (MICROSOFT_COPILOT_INTERACTION)
  • OSTTRA MarkitWire (OSTTRA_MARKITWIRE)
  • Proofpoint Adaptive Email Security (PROOFPOINT_ADAPTIVE_EMAIL_SECURITY)
  • Secomea GateManager (SECOMEA_GATEMANAGER)
  • Trend Micro Vision One Risk Event (TRENDMICRO_VISION_ONE_RISK_EVENT)
  • TXOne EdgeIPS (TXONE_EDGEIPS)
  • Vectra Respond UX (VECTRA_RUX)
  • Zoho CRM (ZOHO_CRM)
Feature

View prebuilt parser version content

You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.

July 28, 2026

Feature

[Spotlight Feature] Data RBAC for first-party (1P) cases and alerts

Availability This feature is now available in public preview for all regions.

Google SecOps now supports data role-based access control (Data RBAC) for first-party (1P) SOAR cases and alerts. This feature automatically applies SIEM data access scopes to alerts and cases ingested using the Chronicle connector, ensuring analysts only see data they are authorized to access.

For more information, see the Release Note entry for July 6th.

July 26, 2026

Feature

Customizable schedules for multi-event rules

Customizable schedules for multi-event rules are available in public preview. You can customize rule execution schedules on the Rule schedule tab to specify a first-run delay offset that accounts for data ingestion latency. The system also performs automated background true-up runs to catch late-arriving logs and process metadata enrichment without requiring manual system interventions. This gives you precise control over detection evaluation timing, reduces false negatives without missing detections, and promotes alert accuracy.

To view or modify rule schedules using custom Identity and Access Management (IAM) roles, update your IAM permissions to include the following:

  • chronicle.ruleDeployments.update to update individual rule schedules using the API.
  • chronicle.rules.modifyRules to modify rule schedules using the web interface or in batch using the API.

If you use predefined IAM roles, such as Chronicle API Admin (roles/chronicle.admin) or Chronicle API Editor (roles/chronicle.editor), these permissions are included automatically.

Feature

[Spotlight Feature] Investigation and case management experience

This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking raw UDM events and detections alongside alerts to accommodate new investigation types (such as retrohunt and threat hunt) and higher investigation volumes in cases. You can navigate your case queue using customizable table views, side-drawer previews, and integrated UDM Search workflows. For more information, see Investigation and case management overview.

This preview is currently supported only for single-SIEM deployments (instances where a single Google SecOps SIEM instance ingests data into SOAR) and does not support federated or MSSP environments.

Additional enhancements include:

  • Attach SIEM search results to cases: Manually attach individual UDM events or detections directly from SIEM search results to new or existing cases as core evidence (supporting up to 500 detections and 5,000 UDM events per case). For details, see Attach SIEM search results to cases.
  • Interactive Events Viewer: Dive directly into technical evidence from an interactive side panel. Inspect parsed UDM records, review original raw logs, pin key evidence to your case, and build detection exclusions in real time. For details, see Use the Events Viewer.
  • Configure new default views: Before enabling the updated Cases experience, set up your default views under SOAR Settings > Case Data > Views. Make sure to manually copy over advanced widget configurations (such as Safe HTML Rendering or custom conditions) from the Default Alert View and Default Case View to the New Default Alert View and New Default Case View to preserve your preferred setups.

July 20, 2026

Deprecated

[Spotlight Feature] Deprecation of Google SecOps legacy SIEM APIs

Google SecOps is deprecating its legacy SIEM APIs—Backstory API (including Customer Management API) and Ingestion API—in favor of the modern Chronicle API.

Key dates

  • October 26, 2026: New Google SecOps instances provisioned from this date will no longer support legacy API calls.
  • July 20, 2027: All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down.

This change applies only to custom scripts, integrations, SOAR connectors, or ingestion feeds calling legacy Backstory API or Ingestion API endpoints. Any changes impacting the Google SecOps UI are already addressed and don't call for your action.

Next steps

  • Audit API usage to identify any affected components that currently call legacy Backstory API or Ingestion API endpoints, and replace them with Chronicle API endpoints.

  • Validate and test that your updated components work properly.

For more information, see Migrate from legacy API to Chronicle API.

July 15, 2026

Feature

[Spotlight Feature] Advanced Filtering in Dashboards

Advanced Filtering in dashboards is now available in Preview. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime.

Key aspects of Advanced Filtering include:

  • Token Variable Definition: When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores (^[a-zA-Z0-9_]+$) and must be unique within the dashboard.
  • Filter Value Generation: Token values can be generated dynamically from YARA-L query results or entered manually as a static list.
  • Customizable Wrappers: You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions.
  • Multi-Select Support: The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example, |) for combining values in queries.

For more information, see Advanced filtering.

Feature

Parser extensions for code snippets now support Append/Replace for Repeated Fields

You can now use append and replace functionality for repeated fields when creating code snippet extensions. Previously, this was only available for no-code extensions. This enhancement provides more granular control over how data is handled in repeated UDM fields, allowing you to either add new values or entirely replace existing ones.

For more information, see Repeated fields selector.

July 13, 2026

Feature

SOAR migration to Google Cloud validation status

You can now check if the SOAR migration was successful by going to the SOAR Settings > License Management page. After successful completion of Stage 1, it will say Google.com after the system version number. After successful completion of Stage 2 of SOAR permissions to IAM roles, it will say both Google.com and CloudIAM Enabled after the system version number.

For more information on the migration, see the SOAR migration guide

July 12, 2026

Feature

Publisher Agent Version 2.7.0

Publisher Agent Version 2.7.0 is now available for all regions.

This release includes the following updates for the remote agent:

  • High Availability support: Adds applicative support for Publisher high availability.
  • File transfer support: You can now upload and download files using playbooks and the SDK on agents that have been migrated to the GCOM infrastructure.

July 06, 2026

Feature

Data RBAC for first-party (1P) cases and alerts in public preview

Availability: This feature is available only in the following regions: europe-central2, asia-northeast1, asia-south1, australia-southeast1, northamerica-northeast2, europe-west3, europe-west6, southamerica-east1, asia-southeast1, me-central1, me-central2, me-west1, europe-west2, europe-west9, europe-west12, asia-southeast2, africa-south1, asia-east1, and asia-northeast3.

Google SecOps now supports data role-based access control (Data RBAC) for first-party (1P) cases and alerts in SOAR. This feature automatically applies SIEM data access scopes to alerts and cases ingested using the Chronicle connector, ensuring analysts only see data they are authorized to access.

Key highlights

  • SIEM-scope-to-SOAR inheritance: Ingested 1P SIEM alerts carry their assigned data access scopes, which are automatically inherited by their parent SOAR cases.
  • Dual access enforcement: To view a case or alert, users must have access to both the assigned SOAR environment and all associated data access scopes. Global users maintain full visibility.
  • Scope-to-environment mapping: Administrators can map SIEM data access scopes to SOAR environments (SOAR settings > Environments) to manage alert routing and grouping. Alerts without mapped scopes are routed to a fallback environment.
  • Enhanced UI visibility and filtering: Assigned data access scopes are visible next to the environment in the Case header and the List cases table, allowing for easy filtering.
  • Manual case and grouping logic: When creating cases manually, analysts can only select from the intersection of their permitted data access scopes and environment mappings.

Prerequisites and enablement

  • Requires a unified Google SecOps instance with the Chronicle connector using the modern Chronicle API.
  • Administrators can enable this feature under SIEM settings > Data access by selecting Enforce data access in SOAR (or Enforce data access if SIEM data access is not yet active).

For more information, see Control access to 1P cases and alerts.

July 01, 2026

Announcement

[Spotlight Feature] Security Tokens

Security Tokens are now available for metering agentic consumption within Google SecOps. Tokens are consumed by generally available security agents only. These agents are invoked automatically or manually using the web interface, CLI, chat, or Model Context Protocol (MCP). Assistive features, such as standard chat panels and automated summaries, along with preview agents, won't consume Security Tokens.

Security Tokens will start rolling out across all regions starting July 1. For more information, see Google SecOps Agentic SOC Security Tokens pricing and billing.

Feature

[Spotlight Feature] Enhanced security and compliance for the Advanced BigQuery Export feature

The Advanced BigQuery Export feature is in Preview and is available for Google SecOps Enterprise Plus customers only.

Here's what's new: We're excited to announce significant performance and coverage enhancements to Advanced BigQuery Export for Google SecOps Enterprise Plus customers.

  • Expanded dataset support: In addition to UDM events, rule detections, and IoC matches, we now support the export of Entity Graph and Ingestion Metrics.
  • Enhanced security & compliance: The offering natively supports VPC Service Controls (VPC-SC), Customer-Managed Encryption Keys (CMEK), and Data Residency (DRZ). Furthermore, customer-facing audit logs (Access Transparency) are delivered directly to your Cloud Logging workspace using the Federated Resource Identification Service.
  • Data integrity and deduplication: The system now uses Fine-Grained DML merges to update records in place behind the scenes. This ensures that you receive clean, deduplicated data without needing to write complex SQL routines.
  • Seamless MSSP support (hub and spoke): Managed Security Service Providers (MSSPs) can now efficiently manage analytics across multiple customer tenants. This is achieved by programmatically subscribing to customers' linked datasets from a single centralized "Hub" project.
  • Enum mapping tables: Advanced BigQuery Export now includes entity_enum_value_to_name_mapping and udm_enum_value_to_name_mapping tables. These allow you to easily join against your events to translate numerical enum values into human-readable strings.

Key reminders

  • Public preview & feature activation: This feature is currently in Public Preview, is enabled only upon request, and may require initial configuration in your organization's Google SecOps instance. Contact your Google SecOps representative to confirm feature enablement.
  • Enterprise Plus only: This feature is exclusive to the Enterprise Plus tier.
  • Zero-maintenance: Your security data remains in a Google-managed project, appearing as a read-only linked dataset directly in your own Google Cloud project. This lets you query the data locally without the overhead of managing the pipeline or paying for storage.
  • Migration and dual operation: To support a smooth transition without disruption during the Public Preview, your data will be exported to the new BigQuery tenant project in addition to your existing Google-managed BigQuery project. You'll be notified before the old export pipeline is disabled for your account.

June 30, 2026

Announcement

Increased multiple event limits

Multiple event rule limits have been increased to 200 for Enterprise customers and 400 for Enterprise+ customers.

For more information, see Package comparison

Announcement

[Spotlight Feature] Unified rules interface

The new rules interface is now available in public preview. The Google SecOps unified rules interface brings custom and curated rule management into a single, cohesive workflow. This optimizes detection engineering with a redesigned dashboard, an advanced rule editor, and expanded API capabilities to streamline rule deployment and troubleshooting.

You can still revert to the legacy experience. At the top right of the screen, click Switch to the legacy experience.

For more information about the Unified rules interface, see Manage unified rules.

June 28, 2026

Change

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • AIX system (AIX_SYSTEM)
  • Amazon API Gateway (AWS_API_GATEWAY)
  • Apache (APACHE)
  • Appian Cloud (APPIAN_CLOUD)
  • Aruba Switch (ARUBA_SWITCH)
  • Atlassian Bitbucket (ATLASSIAN_BITBUCKET)
  • Avaya Aura Experience Portal (AVAYA_AURA)
  • AWS CloudWatch (AWS_CLOUDWATCH)
  • AWS GuardDuty (GUARDDUTY)
  • AWS Network Firewall (AWS_NETWORK_FIREWALL)
  • AWS RDS (AWS_RDS)
  • AWS Security Hub (AWS_SECURITY_HUB)
  • AWS VPC Flow (AWS_VPC_FLOW)
  • AWS VPC Flow (CSV) (AWS_VPC_FLOW_CSV)
  • AWS WAF (AWS_WAF)
  • Azure AD (AZURE_AD)
  • Barracuda WAF (BARRACUDA_WAF)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • Cato Networks (CATO_NETWORKS)
  • Check Point Harmony (CHECKPOINT_HARMONY)
  • Chrome Management (CHROME_MANAGEMENT)
  • CircleCI (CIRCLECI)
  • Cisco ACS (CISCO_ACS)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco IronPort (CISCO_IRONPORT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Meraki (CISCO_MERAKI)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Secure Access (CISCO_SECURE_ACCESS)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco Umbrella Audit (CISCO_UMBRELLA_AUDIT)
  • Cisco Umbrella Cloud Firewall (UMBRELLA_FIREWALL)
  • Cisco Umbrella Web Proxy (UMBRELLA_WEBPROXY)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco WLC/WCS (CISCO_WIRELESS)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Claroty Xdome (CLAROTY_XDOME)
  • Cloudflare (CLOUDFLARE)
  • Corelight (CORELIGHT)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Falcon (CS_EDR)
  • CyberArk PTA Privileged Threat Analytics (CYBERARK_PTA)
  • Cynet 360 AutoXDR (CYNET_360_AUTOXDR)
  • Dell Switch (DELL_SWITCH)
  • Elastic Windows Event Log Beats (ELASTIC_WINLOGBEAT)
  • F5 ASM (F5_ASM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • FireEye ETP (FIREEYE_ETP)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint Proxy (FORCEPOINT_WEBPROXY)
  • FortiGate (FORTINET_FIREWALL)
  • FortiMail Email Security (FORTINET_FORTIMAIL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet Web Application Firewall (FORTINET_FORTIWEB)
  • GitHub (GITHUB)
  • Google Cloud Audit (GCP_CLOUDAUDIT)
  • Google Cloud DNS (GCP_DNS)
  • HAProxy (HAPROXY)
  • IBM Tape Storages (IBM_LTO)
  • Imperva CEF (IMPERVA_CEF)
  • Imperva SecureSphere Management (IMPERVA_SECURESPHERE)
  • Infoblox DNS (INFOBLOX_DNS)
  • Island Browser logs (ISLAND_BROWSER)
  • JumpCloud Directory Insights (JUMPCLOUD_DIRECTORY_INSIGHTS)
  • Kemp Load Balancer (KEMP_LOADBALANCER)
  • Kubernetes Node (KUBERNETES_NODE)
  • ManageEngine ADAudit Plus (ADAUDIT_PLUS)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Defender for Office 365 (MICROSOFT_DEFENDER_MAIL)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft IIS (IIS)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • MISP Threat Intelligence (MISP_IOC)
  • NetApp ONTAP (NETAPP_ONTAP)
  • NetIQ eDirectory (NETIQ_EDIRECTORY)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • NGINX (NGINX)
  • Noname API Security (NONAME_API_SECURITY)
  • Office 365 (OFFICE_365)
  • Okta (OKTA)
  • Oracle (ORACLE_DB)
  • Oracle Cloud Infrastructure VCN Flow Logs (OCI_FLOW)
  • Oracle NetSuite (ORACLE_NETSUITE)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Palo Alto Panorama (PAN_PANORAMA)
  • Palo Alto Prisma Access (PAN_CASB)
  • Palo Alto Prisma Cloud Alert payload (PAN_PRISMA_CA)
  • Ping Identity (PING)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • RSA (RSA_AUTH_MANAGER)
  • Salesforce (SALESFORCE)
  • Security Command Center Error (GCP_SECURITYCENTER_ERROR)
  • Security Command Center Misconfiguration (GCP_SECURITYCENTER_MISCONFIGURATION)
  • Security Command Center Observation (GCP_SECURITYCENTER_OBSERVATION)
  • Security Command Center Posture Violation (GCP_SECURITYCENTER_POSTURE_VIOLATION)
  • Security Command Center Threat (GCP_SECURITYCENTER_THREAT)
  • Security Command Center Toxic Combination (GCP_SECURITYCENTER_TOXIC_COMBINATION)
  • Security Command Center Unspecified (GCP_SECURITYCENTER_UNSPECIFIED)
  • Security Command Center Vulnerability (GCP_SECURITYCENTER_VULNERABILITY)
  • Sendmail (SENDMAIL)
  • Sentinelone Activity (SENTINELONE_ACTIVITY)
  • ServiceNow CMDB (SERVICENOW_CMDB)
  • Sophos Firewall (Next Gen) (SOPHOS_FIREWALL)
  • Squid Web Proxy (SQUID_WEBPROXY)
  • Symantec EDR (SYMANTEC_EDR)
  • Symantec Endpoint Protection (SEP)
  • Sysdig (SYSDIG)
  • Thinkst Canary (THINKST_CANARY)
  • Trellix EDRF Trace Data and Telemetry (TRELLIX_EDRF)
  • Trend Micro Vision One Detections (TRENDMICRO_VISION_ONE_DETECTIONS)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • Unix system (