This page documents production updates to Google Security Operations. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
August 12, 2026
[Spotlight Feature] Analyze feed activity with Cloud Logging
This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.
This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:
- Investigate telemetry: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
- Debug feeds: Use the Debug with logs option on the Feed management page to open Logs Explorer pre-filtered for a specific feed.
- Filter routed logs: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.
For more information, see Analyze feed activity with Cloud Logging.
July 29, 2026
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- Airlock Digital Application Allowlisting (
AIRLOCK_DIGITAL) - AIX system (
AIX_SYSTEM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Akamai SIEM Connector (
AKAMAI_SIEM_CONNECTOR) - Apache (
APACHE) - Arcsight CEF (
ARCSIGHT_CEF) - Armis Alerts (
ARMIS_ALERTS) - Aruba Switch (
ARUBA_SWITCH) - Atlassian Cloud Admin Audit (
ATLASSIAN_AUDIT) - Linux Auditing System (AuditD) (
AUDITD) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS Control Tower (
AWS_CONTROL_TOWER) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Key Vault logging (
AZURE_KEYVAULT_AUDIT) - Microsoft Azure Resource (
AZURE_RESOURCE_LOGS) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - BeyondTrust (
BOMGAR) - Cato Networks (
CATO_NETWORKS) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Harmony (
CHECKPOINT_HARMONY) - Chrome Management (
CHROME_MANAGEMENT) - ChromeOS XDR (
CHROMEOS_XDR) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT) - Cisco ISE (
CISCO_ISE) - Cisco Router (
CISCO_ROUTER) - Cisco Switch (
CISCO_SWITCH) - Cisco UCM (
CISCO_UCM) - Claroty Xdome (
CLAROTY_XDOME) - Claude Compliance Logs (
CLAUDE_COMPLIANCE_LOGS) - HP Aruba (ClearPass) (
CLEARPASS) - Cloudflare (
CLOUDFLARE) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - CrowdStrike Falcon (
CS_EDR) - Darktrace (
DARKTRACE) - EfficientIP DDI (
EFFICIENTIP_DDI) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - Fastly CDN (
FASTLY_CDN) - FireEye eMPS (
FIREEYE_EMPS) - FireEye HX (
FIREEYE_HX) - FireEye NX (
FIREEYE_NX) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet FortiClient (
FORTINET_FORTICLIENT) - Fortinet Switch (
FORTINET_SWITCH) - GCP Cloud Audit (
GCP_CLOUDAUDIT) - Security Command Center External Exposure (
GCP_SECURITYCENTER_EXTERNAL_EXPOSURE) - Gitlab (
GITLAB) - Google Threat Intelligence IOC (
GTI_IOC) - AWS GuardDuty (
GUARDDUTY) - Huawei Switches (
HUAWEI_SWITCH) - IBM Security Access Manager (
IBM_SAM) - Microsoft IIS (
IIS) - Illumio Core (
ILLUMIO_CORE) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox (
INFOBLOX) - Infoblox DHCP (
INFOBLOX_DHCP) - Jamf pro context (
JAMF_PRO_CONTEXT) - Mobile Endpoint Security (
LOOKOUT_MOBILE_ENDPOINT_SECURITY) - Apple macOS (
MACOS) - McAfee IPS (
MCAFEE_IPS) - Micro Focus iManager (
MICROFOCUS_IMANAGER) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft SQL Server (
MICROSOFT_SQL) - Mimecast URL Logs (
MIMECAST_URL_LOGS) - MISP Threat Intelligence (
MISP_IOC) - NetApp ONTAP (
NETAPP_ONTAP) - Netskope V2 (
NETSKOPE_ALERT_V2) - Unix system (
NIX_SYSTEM) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Onapsis (
ONAPSIS) - OpenVPN (
OPEN_VPN) - Oracle Fusion (
ORACLE_FUSION) - Ping Identity (
PING) - Proofpoint Sendmail Sentrion (
PROOFPOINT_SENDMAIL_SENTRION) - SailPoint IAM (
SAILPOINT_IAM) - Salesforce (
SALESFORCE) - Sendmail (
SENDMAIL) - Sentinelone Alerts (
SENTINELONE_ALERT) - ServiceNow Audit (
SERVICENOW_AUDIT) - ServiceNow CMDB (
SERVICENOW_CMDB) - ServiceNow Security (
SERVICENOW_SECURITY) - SonicWall (
SONIC_FIREWALL) - STIX Threat Intelligence (
STIX) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Thinkst Canary (
THINKST_CANARY) - ThreatConnect IOC V3 (
THREATCONNECT_IOC_V3) - ThreatLocker Platform (
THREATLOCKER) - Varonis (
VARONIS) - VMware ESXi (
VMWARE_ESX) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - wiz.io (
WIZ_IO) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zoom Operation Logs (
ZOOM_OPERATION_LOGS)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Adobe Experience Platform (
ADOBE_EXPERIENCE_PLATFORM) - AudioCodes Session Border Controller (
AUDIOCODES_SBC) - Azure Application Gateway for Containers (
AZURE_GATEWAY_CONTAINERS) - Azure Logic Apps (
AZURE_LOGIC_APPS) - Azure NAT Gateway Flow (
AZURE_NATGW_FLOW) - Broadcom DX NetOps Spectrum (
BROADCOM_DX_NETOPS_SPECTRUM) - Carto Activity (
CARTO_ACTIVITY) - Claude Code Observability (
CLAUDE_CODE_OBSERVABILITY) - Cyble Attack Surface Management (
CYBLE_ASM) - Cyble Brand Intelligence & Protection (
CYBLE_BIP) - Darkweb IQ (
DARKWEB_IQ) - Ellio Threat Intelligence (
ELLIO_THREAT_INTEL) - Exeon NDR (
EXEON_NDR) - Gravitee (
GRAVITEE) - Kaspersky anti targeted attack (
KASPERSKY_ANTI_TARGETED_ATTACK) - Microsoft Copilot Interaction (
MICROSOFT_COPILOT_INTERACTION) - OSTTRA MarkitWire (
OSTTRA_MARKITWIRE) - Proofpoint Adaptive Email Security (
PROOFPOINT_ADAPTIVE_EMAIL_SECURITY) - Secomea GateManager (
SECOMEA_GATEMANAGER) - Trend Micro Vision One Risk Event (
TRENDMICRO_VISION_ONE_RISK_EVENT) - TXOne EdgeIPS (
TXONE_EDGEIPS) - Vectra Respond UX (
VECTRA_RUX) - Zoho CRM (
ZOHO_CRM)
View prebuilt parser version content
You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.
July 20, 2026
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
Google Security Operations is deprecating its legacy SIEM APIs—Backstory API (including Customer Management API) and Ingestion API—in favor of the modern Chronicle API.
Key dates
- October 26, 2026: New Google SecOps instances provisioned from this date will no longer support legacy API calls.
- July 20, 2027: All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down.
This change applies only to custom scripts, integrations, SOAR connectors, or ingestion feeds calling legacy Backstory API or Ingestion API endpoints. Any changes impacting the Google SecOps UI are already addressed and don't call for your action.
Next steps
Audit API usage to identify any affected components that currently call legacy Backstory API or Ingestion API endpoints, and replace them with Chronicle API endpoints.
Validate and test that your updated components work properly.
For more information, see Migrate from legacy API to Chronicle API.
July 15, 2026
Advanced Filtering in Dashboards
This feature is in public preview.
Advanced Filtering in dashboards is now available in Google SecOps. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime.
Key aspects of Advanced Filtering include:
- Token Variable Definition: When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores (
^[a-zA-Z0-9_]+$) and must be unique within the dashboard. - Filter Value Generation: Token values can be generated dynamically from YARA-L query results or entered manually as a static list.
- Customizable Wrappers: You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions.
- Multi-Select Support: The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example,
|) for combining values in queries.
For more information, see Advanced filtering.
Parser extensions for code snippets now support Append/Replace for Repeated Fields
You can now use append and replace functionality for repeated fields when creating code snippet extensions. Previously, this was only available for no-code extensions. This enhancement provides more granular control over how data is handled in repeated UDM fields, allowing you to either add new values or entirely replace existing ones.
For more information, see Repeated fields selector.
July 01, 2026
[Spotlight Feature] Security Tokens
Security Tokens are now available for metering agentic consumption within Google SecOps. Tokens are consumed by generally available security agents only. These agents are invoked automatically or manually using the web interface, CLI, chat, or Model Context Protocol (MCP). Assistive features, such as standard chat panels and automated summaries, along with preview agents, won't consume Security Tokens.
Security Tokens will start rolling out across all regions starting July 1. For more information, see Google SecOps Agentic SOC Security Tokens pricing and billing.
June 30, 2026
Increased multiple event limits
Multiple event rule limits have been increased to 200 for Enterprise customers and 400 for Enterprise+ customers.
For more information, see Package comparison
Unified rules interface
The new rules interface is now available in public preview.
The Google SecOps unified rules interface brings custom and curated rule management into a single, cohesive workflow. This optimizes detection engineering with a redesigned dashboard, an advanced rule editor, and expanded API capabilities to streamline rule deployment and troubleshooting.
You can still revert to the legacy experience. At the top right of the screen, click Switch to the legacy experience.
For more information about the Unified rules interface, see Manage unified rules.
June 28, 2026
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- AIX system (
AIX_SYSTEM) - Amazon API Gateway (
AWS_API_GATEWAY) - Apache (
APACHE) - Appian Cloud (
APPIAN_CLOUD) - Aruba Switch (
ARUBA_SWITCH) - Atlassian Bitbucket (
ATLASSIAN_BITBUCKET) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS GuardDuty (
GUARDDUTY) - AWS Network Firewall (
AWS_NETWORK_FIREWALL) - AWS RDS (
AWS_RDS) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS VPC Flow (
AWS_VPC_FLOW) - AWS VPC Flow (CSV) (
AWS_VPC_FLOW_CSV) - AWS WAF (
AWS_WAF) - Azure AD (
AZURE_AD) - Barracuda WAF (
BARRACUDA_WAF) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Cato Networks (
CATO_NETWORKS) - Check Point Harmony (
CHECKPOINT_HARMONY) - Chrome Management (
CHROME_MANAGEMENT) - CircleCI (
CIRCLECI) - Cisco ACS (
CISCO_ACS) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco Router (
CISCO_ROUTER) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Cisco Umbrella Cloud Firewall (
UMBRELLA_FIREWALL) - Cisco Umbrella Web Proxy (
UMBRELLA_WEBPROXY) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco WLC/WCS (
CISCO_WIRELESS) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Xdome (
CLAROTY_XDOME) - Cloudflare (
CLOUDFLARE) - Corelight (
CORELIGHT) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CyberArk PTA Privileged Threat Analytics (
CYBERARK_PTA) - Cynet 360 AutoXDR (
CYNET_360_AUTOXDR) - Dell Switch (
DELL_SWITCH) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - FireEye ETP (
FIREEYE_ETP) - FireEye NX (
FIREEYE_NX) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - FortiMail Email Security (
FORTINET_FORTIMAIL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GitHub (
GITHUB) - Google Cloud Audit (
GCP_CLOUDAUDIT) - Google Cloud DNS (
GCP_DNS) - HAProxy (
HAPROXY) - IBM Tape Storages (
IBM_LTO) - Imperva CEF (
IMPERVA_CEF) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox DNS (
INFOBLOX_DNS) - Island Browser logs (
ISLAND_BROWSER) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS) - Kemp Load Balancer (
KEMP_LOADBALANCER) - Kubernetes Node (
KUBERNETES_NODE) - ManageEngine ADAudit Plus (
ADAUDIT_PLUS) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Microsoft SQL Server (
MICROSOFT_SQL) - MISP Threat Intelligence (
MISP_IOC) - NetApp ONTAP (
NETAPP_ONTAP) - NetIQ eDirectory (
NETIQ_EDIRECTORY) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - NGINX (
NGINX) - Noname API Security (
NONAME_API_SECURITY) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Oracle (
ORACLE_DB) - Oracle Cloud Infrastructure VCN Flow Logs (
OCI_FLOW) - Oracle NetSuite (
ORACLE_NETSUITE) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Access (
PAN_CASB) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Ping Identity (
PING) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - RSA (
RSA_AUTH_MANAGER) - Salesforce (
SALESFORCE) - Security Command Center Error (
GCP_SECURITYCENTER_ERROR) - Security Command Center Misconfiguration (
GCP_SECURITYCENTER_MISCONFIGURATION) - Security Command Center Observation (
GCP_SECURITYCENTER_OBSERVATION) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
GCP_SECURITYCENTER_THREAT) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Security Command Center Unspecified (
GCP_SECURITYCENTER_UNSPECIFIED) - Security Command Center Vulnerability (
GCP_SECURITYCENTER_VULNERABILITY) - Sendmail (
SENDMAIL) - Sentinelone Activity (
SENTINELONE_ACTIVITY) - ServiceNow CMDB (
SERVICENOW_CMDB) - Sophos Firewall (Next Gen) (
SOPHOS_FIREWALL) - Squid Web Proxy (
SQUID_WEBPROXY) - Symantec EDR (
SYMANTEC_EDR) - Symantec Endpoint Protection (
SEP) - Sysdig (
SYSDIG) - Thinkst Canary (
THINKST_CANARY) - Trellix EDRF Trace Data and Telemetry (
TRELLIX_EDRF) - Trend Micro Vision One Detections (
TRENDMICRO_VISION_ONE_DETECTIONS) - Trend Micro Vision One Workbench (
TRENDMICRO_VISION_ONE_WORKBENCH) - Unix system (
NIX_SYSTEM) - Varonis (
VARONIS) - Veeam (
VEEAM) - VMware vCenter (
VMWARE_VCENTER) - VMWare VSphere (
VMWARE_VSPHERE) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Windows Sysmon (
WINDOWS_SYSMON) - wiz.io (
WIZ_IO) - Workday User Activity (
WORKDAY_USER_ACTIVITY) - Zeek JSON (
BRO_JSON) - Zscaler (
ZSCALER_WEBPROXY) - ZScaler NGFW (
ZSCALER_FIREWALL)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Cisco Secure Access Enrollment (
CISCO_SECURE_ACCESS_ENROLLMENT) - Cisco Secure Access Network (
CISCO_SECURE_ACCESS_NETWORK) - CyberArk Certificate Manager SaaS (
CYBERARK_CERTIFICATE_MANAGER_SAAS) - Gemini Enterprise Agent Platform (
GEMINI_ENTERPRISE_AGENT_PLATFORM) - Schneider Electric GeoScada OT (
GEOSCADA_OT) - Model Context Protocol Dev (
MCPDEV) - Model Context Protocol Modify (
MCPMODIFY) - Model Context Protocol View (
MCPVIEW) - NetApp Ransomware Resilience (
NETAPP_RANSOMWARE_RESILIENCE) - Netskope Log Streaming (
NETSKOPE_LOG_STREAMING) - Pylon Audit Logs (
PYLON_LOGS) - Reco AI CSPM (
RECO_CSPM) - Salt Security API Protection Platform (
SALT_SECURITY) - SentinelOne Application (
SENTINELONE_APPLICATION) - Wiz Vulnerabilities (
WIZ_VULNERABILITIES)
June 26, 2026
Improved documentation portal navigation
Finding help is now easier! We've updated the navigation of our documentation portal to be primarily user-centric. Sections have been reorganized and renamed to align with your workflows, providing a logical path through the documentation.
We've also added:
- A Support tab for technical support, changelogs, and release notes
- A Use cases tab for persona-driven CUJs and workflows
June 23, 2026
Ask Gemini Cloud Assist in Feed Management
Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation, setup, and general troubleshooting questions.
A new Ask Gemini Cloud Assist button is now available in the Feed Management interface. You can click this button to open the Gemini Cloud Assist panel and ask questions to get guidance on:
- Configuring and managing data feeds.
- Understanding ingestion pre-requisites and setup steps for different log sources.
- Resolving common setup issues.
Note: Gemini Cloud Assist provides recommendations and answers to your questions, but does not perform configuration changes on your behalf. You must apply any recommended changes manually to your feeds.
For more information, see Feed management overview.
Ingestion metrics reporting correction
Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were under-reported.
Because of this correction, you might notice a one-time apparent spike in your ingestion metrics when the update is enabled for your region (between June 29 and July 10, 2026). The actual log volume ingested remains unchanged.
Historical metrics recorded before this update will not be modified or backfilled. This correction does not affect customer billing.
If you have questions or need assistance, contact Google Security Operations support.
June 17, 2026
Auto-collapse setting for the query editor
You can now configure the query editor to automatically collapse after you run a search, maximizing the screen space available for viewing your search results. By default, the query editor remains expanded.
For more information, see Configure query editor behavior.
June 16, 2026
New Documentation changelogs
Google SecOps is now releasing a monthly changelog to capture major documentation updates.
For more information, refer to Documentation changelog.
June 13, 2026
Non-prioritized IoC Matching rules Category
Google SecOps has introduced a new detection category, Non-prioritized IoC Matching rules, as part of the Curated Detections feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.
This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.
For more information, refer to Non-prioritized IoC Matching rules category overview.
June 12, 2026
[Spotlight Feature] Investigate detections in Google SecOps Search
Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the Alerts and Detections tab, providing a more holistic workflow for threat investigation.
For more details, see Investigate detections in Search.
Asynchronous Search APIs for large datasets
Google SecOps now supports asynchronous Search APIs that let you perform long-running queries without blocking your applications. This is ideal for searches that return a large volume of results.
- Non-blocking queries: Initiate searches and receive an operation ID to track progress, so your application remains responsive.
- Handle large result sets: Retrieve up to 1 million results from data sources including Unified Data Model (UDM) events, data tables, and Entity Context Graph (ECG).
- Paginated results: View results efficiently in manageable pages.
For more information, see Asynchronous Search APIs and Result limits for data sources.
June 09, 2026
UDM fields now show the sources of enrichment
The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its data source: U for unenriched fields and E for enriched fields. Enriched fields contain additional metadata values that indicate the source of the enriched data.
For more information, see: Viewing events.
May 31, 2026
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- 1Password Audit Events (
ONEPASSWORD_AUDIT_EVENTS) - AIX system (
AIX_SYSTEM) - Apache (
APACHE) - Aruba EdgeConnect SD-WAN (
ARUBA_EDGECONNECT_SDWAN) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS CloudFront (
AWS_CLOUDFRONT) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS GuardDuty (
GUARDDUTY) - AWS Security Hub (
AWS_SECURITY_HUB) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure AD Sign-In (
AZURE_AD_SIGNIN) - Azure SQL (
AZURE_SQL) - Azure Storage Audit (
AZURE_STORAGE_AUDIT) - Barracuda WAF (
BARRACUDA_WAF) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Chrome Management (
CHROME_MANAGEMENT) - Cisco ACS (
CISCO_ACS) - Cisco ISE (
CISCO_ISE) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Secure Workload (
CISCO_SECURE_WORKLOAD) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Xdome (
CLAROTY_XDOME) - Claude Compliance Logs (
CLAUDE_COMPLIANCE_LOGS) - Cloudflare (
CLOUDFLARE) - Cloudflare Warp (
CLOUDFLARE_WARP) - Corelight (
CORELIGHT) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CyberArk (
CYBERARK) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Duo Administrator Logs (
DUO_ADMIN) - EfficientIP DDI (
EFFICIENTIP_DDI) - Elastic Audit Beats (
ELASTIC_AUDITBEAT) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT) - F5 ASM (
F5_ASM) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - GitHub (
GITHUB) - Google Cloud Asset Inventory (
GCP_CLOUD_ASSET_INVENTORY) - Google Cloud Audit (
GCP_CLOUDAUDIT) - Google Compute Context (
GCP_COMPUTE_CONTEXT) - Google Threat Intelligence IOC (
GTI_IOC) - GTB Technologies DLP (
GTB_DLP) - HP Aruba (ClearPass) (
CLEARPASS) - IBM Websphere Application Server (
IBM_WEBSPHERE_APP_SERVER) - IBM z/OS (
IBM_ZOS) - Imperva (
IMPERVA_WAF) - Imperva CEF (
IMPERVA_CEF) - Imperva DRA (
IMPERVA_DRA) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Island Browser logs (
ISLAND_BROWSER) - Juniper (
JUNIPER_FIREWALL) - Juniper Mist (
JUNIPER_MIST) - Kubernetes Node (
KUBERNETES_NODE) - LastPass Password Management (
LASTPASS) - Linux Auditing System (AuditD) (
AUDITD) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft IIS (
IIS) - Mobileiron (
MOBILEIRON) - Mongo Database (
MONGO_DB) - MySQL (
MYSQL) - Netapp Storagegrid (
NETAPP_STORAGEGRID) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - NGFW Enterprise (
GCP_NGFW_ENTERPRISE) - Office 365 (
OFFICE_365) - Office 365 Message Trace (
OFFICE_365_MESSAGETRACE) - Okta Scaleft (
OKTA_SCALEFT) - Oracle (
ORACLE_DB) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT) - Orca Cloud Security Platform (
ORCA) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Red Hat Directory Server LDAP (
REDHAT_DIRECTORY_SERVER) - Red Hat OpenShift (
REDHAT_OPENSHIFT) - Salesforce (
SALESFORCE) - Sangfor Next Generation Firewall (
SANGFOR_NGAF) - Security Command Center Error (
GCP_SECURITYCENTER_ERROR) - Security Command Center Misconfiguration (
GCP_SECURITYCENTER_MISCONFIGURATION) - Security Command Center Observation (
GCP_SECURITYCENTER_OBSERVATION) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
GCP_SECURITYCENTER_THREAT) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Security Command Center Unspecified (
GCP_SECURITYCENTER_UNSPECIFIED) - Security Command Center Vulnerability (
GCP_SECURITYCENTER_VULNERABILITY) - SentinelOne Singularity Cloud Funnel (
SENTINELONE_CF) - ServiceNow Security (
SERVICENOW_SECURITY) - Sourcefire (
SOURCEFIRE_IDS) - Suricata EVE (
SURICATA_EVE) - Symantec Endpoint Protection (
SEP) - Sysdig (
SYSDIG) - Trend Micro Deep Security (
TRENDMICRO_DEEP_SECURITY) - Trend Micro Vision One Observerd Attack Techniques (
TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES) - Ubiquiti UniFi Switch (
UBIQUITI_SWITCH) - Unix system (
NIX_SYSTEM) - Upwind (
UPWIND) - VMware ESXi (
VMWARE_ESX) - VMWare VSphere (
VMWARE_VSPHERE) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Wiz.io (
WIZ_IO) - Workday User Activity (
WORKDAY_USER_ACTIVITY) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zscaler (
ZSCALER_WEBPROXY) - Zscaler CASB (
ZSCALER_CASB) - Zscaler DLP (
ZSCALER_DLP) - Zscaler Private Access (
ZSCALER_ZPA)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Azure Software Vulnerabilities (
AZURE_SOFTWARE_VULNERABILITIES) - Caller Verify (
CALLER_VERIFY) - CertSecure Log (
CERTSECURE_LOG) - Cisco MultiCloud Defense Firewall (
CISCO_MULTICLOUD_DEFENSE_FIREWALL) - Cursor (
CURSOR) - Cyfirma (
CYFIRMA_DECYFIR_LOG) - Databahn (
DATABAHN) - Flare Darkweb Alerts (
FLARE_DARKWEB_ALERTS) - Fortinet FortiAppSec Cloud (
FORTINET_FORTIAPPSEC) - Hikvision Network Video Recorders (
HIKVISION_NVR) - IBM B2B Integrator (
IBM_B2B_INTEGRATOR) - IBM InfoSphere Virtual Data Pipeline (
IBM_VDP) - Imperva Account TakeOver (
IMPERVA_ATO) - Imperva Client Side Protection (
IMPERVA_CSP) - Imperva DNS (
IMPERVA_DNS) - Imperva Network Security (
IMPERVA_NETWORK_SECURITY) - Microsoft Defender XDR (
MICROSOFT_DEFENDER_XDR) - Nakivo Backup and Recovery (
NAKIVO_BACKUP) - Netcraft Takedown (
NETCRAFT_TAKEDOWN) - Next Level Performance Amplify (
NXL_AMPLIFY) - Siemens Desigo (
SIEMENS_DESIGO)
May 28, 2026
Upgraded Chronicle API
We've upgraded the following Chronicle API resources from v1 beta to v1. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for all new integrations, for a more robust, secure, and extensible experience. Learn more about API Stability.
The following features and resources are included in this update:
- Alerts and ATIs, UEBA: Threat Collection, IoC, CoverageDetail, EntityRisk
- Dashboards: NativeDashboard, DashboardChart, DashboardQuery, FeaturedContentNativeDashboard
- Data Tables: DataTable, DataTableRow, DataTableOperationError
- Ingestion: Logs, Feed, LogTypeSchema, FeedSourceSchema, FeedPack, Forwarder
- Normalization: Logtype, Parser, IngestionLogLabel
- Detections: FindingsRefinement, VerifyRuleText, FeaturedContentRule, RuleExecutionError
- Search & Investigation: Event, Entity, SearchQuery, SavedColumnSet
- Exports: BigQueryExportService
- Enrichment Controls: EnrichmentControl, EnrichmentCombination
For a full list of updated resources and links to the documentation, please see the Chronicle API documentation.