Skip to main content
Technology areas
close
AI and ML
Application development
Application hosting
Compute
Data analytics and pipelines
Databases
Distributed, hybrid, and multicloud
Industry solutions
Migration
Networking
Observability and monitoring
Security
Storage
Cross-product tools
close
Access and resources management
Costs and usage management
Infrastructure as code
SDK, languages, frameworks, and tools
/
Console
English
Deutsch
Español
Español – América Latina
Français
Indonesia
Italiano
Português
Português – Brasil
עברית
中文 – 简体
中文 – 繁體
日本語
한국어
Sign in
Google Security Operations
Start free
Overview
Guides
Use cases
Reference
Support
Resources
Technology areas
More
Overview
Guides
Use cases
Reference
Support
Resources
Cross-product tools
More
Console
Discover
Introduction
Google SecOps overview
Google Unified Security overview
Recommended Google Unified Security products
Understand the Google SecOps platform
Google SecOps lifecycle
Collect data
Data ingestion overview
UDM overview
Detect threats
Applied Threat Intelligence overview
Get started with YARA-L
Investigate alerts
Investigation and case management overview
Investigate alerts and entity context
Respond to alerts
Playbook automation overview
Embed AI agents in playbooks
Respond to alerts and cases
Manage and monitor
Content Hub overview
Ingestion metrics overview
Dashboards overview
Gemini in Google SecOps
Overview
Access in-product help with Gemini
Licensing
Google SecOps packages overview
Google SecOps Security Tokens overview
Get started
Access a Google SecOps instance
Log in to Google SecOps
Navigate the Google SecOps platform
Configure user preferences
Administer
Set up an instance
Deploy an instance
Understand your billing
Configure a Google Cloud project
Link an instance to Google Cloud
Configure authentication
Configure Google Cloud identity
Configure third-party identity
Change authentication
Configure feature access
Configure data access
Data RBAC overview
Configure data RBAC
Manage RBAC impact
Overview
Control access to dashboards
Control access to data tables
Control access to 1P cases and alerts
Control access to reference lists
Configure legacy RBAC
Configure SOAR access
Overview
Manage permission groups
Overview
Understand user groups
Create a managed user
Create a collaborator user
Create a view-only user
Manage SOC roles
Manage environments
Overview
Manage environment groups
Configure custom environment groups
Enable access
Enable SOAR access
Map users with Cloud identity
Map users with third-party identity
Apply multiple control access parameters
Enable federated access
View all users
Delete a user account
Configure compliance
Configure CMEK
Configure VPC service controls
Configure MCP
Configure instance settings
Manage operational settings
Define a landing page
Rebrand your platform
Set time zone
Configure email settings
Manage preview features
Manage data retention
Configure SIEM data retention
Configure SOAR data retention
Monitor and audit platform activity
Manage audit logs
Monitor user activities
Manage administrative assets
Create custom lists
Create email HTML templates
Create email templates
Add variables to email templates
Create user requests
Manage properties metadata
Retrieve raw Python logs
Manage case settings
Manage case stages
Configure case naming conventions
Create custom fields for cases
Manage custom case closure fields
Configure the close case dialog
Configure the default case view
Manage alert settings
Configure alert grouping
Configure alert overflow
Configure the default alert view
Exclude entities from alerts
Manage case and alert tags
Configure networks and multi-tenancy
Manage networks
Define domains for MSSPs
Manage environment load balancing
Upgrade and migrate
Migrate SOAR to Google Cloud
Overview
Pre-migration validation guide
Manage MSSP migration
Migrate SOAR permissions to IAM
Map SOAR permissions to IAM
Migrate to Chronicle API
SOAR API mapping table
Migrate remote agent authentication infrastructure
Frequently asked questions
Migrate SIEM to Google Cloud
SIEM migration overview
Migrate to a Google Cloud project
Migrate to Google Cloud authentication
Migrate from legacy RBAC to feature RBAC
Migrate from legacy SIEM APIs to Chronicle API
Overview
SIEM API endpoint mapping
Migrate an instance to a BYOP project
Migrate from legacy features
Migrate CBN alerts to YARA-L alerts
Migrate from CrowdStrike Detects API to Alerts API
Deprovision
Build and integrate
Deploy centralized content
Content Hub overview
Run use cases from the Content Hub
Power ups and utilities
Connectors
Email utilities
Enrichment
File utilities
Functions
GitSync
Image utilities
TemplateEngine
Insights
Lists
Tools
Develop custom capabilities
Use the IDE
Get started
Develop your first custom integration
Develop your first custom action
Develop your first email connector
Develop your first use case
Build and design custom components
Build custom integrations
Create custom actions
Write automated jobs
Build and configure connectors
Build connector logic
Configure custom connectors
Test custom connectors
Map and model alerts
Publish custom integrations
Advanced data modeling
Develop custom transformers
Configure calculated fields for cases
Manage response integrations
Configure response integrations
Roll back response integrations
Upgrade the Python version
Manage integration dependencies
Support multiple instances
Test response integrations
Manage secrets with secret managers
Manage remote agents
Get started
Overview
Review deployment requirements
Review data flow and protocols
Deploy remote agents
Deploy with Docker
Deploy with Podman
Deploy on Debian
Deploy on RHEL
Deploy on CentOS
Configure high availability
Redeploy connectors
Configure and validate connectivity
Configure the Installer and Docker
Configure remote execution
Test the connection flow
Manage and upgrade remote agents
Remote agent scaling strategy
Monitor and manage remote agents
Perform a standard upgrade
Major upgrade with Docker
Major upgrade with Podman
Major upgrade with RHEL
Major upgrade with CentOS
Redeploy remote agents
Troubleshoot remote agents
Collaborate and share
Contribute community response integrations
Become a technology partner
Ingest
Prepare for data ingestion
Overview
Ingestion methods and data types
Ingest and parse log data
Parsers overview
Data feeds overview
Data enrichment and aliasing overview
Collect data
Work with the feeds UI
Create an Azure event hub feed
Ingest data with API connectors
Ingest data with the Ingestion API
Ingest Google Cloud logs
Collect data using webhooks
Set up a SOAR webhook
Set up a SIEM webhook
Deploy the Bindplane agent for collection
Collect data using SOAR connectors
Ingest data using SOAR connectors
Map custom date and time in Elasticsearch
Define environments in SOAR connectors
Collect data using legacy forwarders
Install and configure the forwarder
Configure forwarders in the platform
Manage forwarder configurations manually
Install Windows forwarder executable
Ingest logs with Cloud Run functions
Configure partner-hosted integrations
Configure log types and parsers
Default parsers and log types overview
List of default parser configuration guides
Request prebuilt and create custom log types
Support policy for standard parsers
Premium parsers
Apigee logs
AWS CloudTrail logs
AWS EC2 Hosts logs
AWS EC2 Instance logs
Chrome management logs
Cisco ASA firewall logs
Cloud SQL context Logs
Resource Manager context logs
CrowdStrike Falcon logs
Duo Activity logs
Fluentd logs
Fortinet Firewall logs
Google Cloud Abuse Events logs
Google Cloud Audit Logs
Google Cloud BigQuery context logs
Google Cloud DNS logs
Google Cloud Firewall logs
Google Cloud IAM context logs
Google Cloud Kubernetes context logs
Google Cloud Load Balancing logs
Google Cloud NAT logs