Skip to main content
Google Cloud Documentation
Technology areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
Cross-product tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
/
Console
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • Google Security Operations
Start free
Overview Guides Use cases Reference Support Resources
Google Cloud Documentation
  • Technology areas
    • More
    • Overview
    • Guides
    • Use cases
    • Reference
    • Support
    • Resources
  • Cross-product tools
    • More
  • Console
  • Discover
  • Introduction
    • Google SecOps overview
    • Google Unified Security overview
    • Recommended Google Unified Security products
    • Understand the Google SecOps platform
  • Google SecOps lifecycle
    • Collect data
      • Data ingestion overview
      • UDM overview
    • Detect threats
      • Applied Threat Intelligence overview
      • Get started with YARA-L
    • Investigate alerts
      • Investigation and case management overview
      • Investigate alerts and entity context
    • Respond to alerts
      • Playbook automation overview
      • Embed AI agents in playbooks
      • Respond to alerts and cases
    • Manage and monitor
      • Content Hub overview
      • Ingestion metrics overview
      • Dashboards overview
  • Gemini in Google SecOps
    • Overview
    • Access in-product help with Gemini
  • Licensing
    • Google SecOps packages overview
    • Google SecOps Security Tokens overview
  • Get started
  • Access a Google SecOps instance
  • Log in to Google SecOps
  • Navigate the Google SecOps platform
  • Configure user preferences
  • Administer
  • Set up an instance
    • Deploy an instance
    • Understand your billing
    • Configure a Google Cloud project
    • Link an instance to Google Cloud
    • Configure authentication
      • Configure Google Cloud identity
      • Configure third-party identity
      • Change authentication
  • Configure feature access
  • Configure data access
    • Data RBAC overview
    • Configure data RBAC
    • Manage RBAC impact
      • Overview
      • Control access to dashboards
      • Control access to data tables
      • Control access to 1P cases and alerts
      • Control access to reference lists
    • Configure legacy RBAC
  • Configure SOAR access
    • Overview
    • Manage permission groups
      • Overview
      • Understand user groups
      • Create a managed user
      • Create a collaborator user
      • Create a view-only user
    • Manage SOC roles
    • Manage environments
      • Overview
      • Manage environment groups
      • Configure custom environment groups
    • Enable access
      • Enable SOAR access
      • Map users with Cloud identity
      • Map users with third-party identity
      • Apply multiple control access parameters
    • Enable federated access
    • View all users
    • Delete a user account
  • Configure compliance
    • Configure CMEK
    • Configure VPC service controls
  • Configure MCP
  • Configure instance settings
    • Manage operational settings
      • Define a landing page
      • Rebrand your platform
      • Set time zone
      • Configure email settings
      • Manage preview features
    • Manage data retention
      • Configure SIEM data retention
      • Configure SOAR data retention
    • Monitor and audit platform activity
      • Manage audit logs
      • Monitor user activities
    • Manage administrative assets
      • Create custom lists
      • Create email HTML templates
      • Create email templates
      • Add variables to email templates
      • Create user requests
      • Manage properties metadata
      • Retrieve raw Python logs
    • Manage case settings
      • Manage case stages
      • Configure case naming conventions
      • Create custom fields for cases
      • Manage custom case closure fields
      • Configure the close case dialog
      • Configure the default case view
    • Manage alert settings
      • Configure alert grouping
      • Configure alert overflow
      • Configure the default alert view
      • Exclude entities from alerts
    • Manage case and alert tags
    • Configure networks and multi-tenancy
      • Manage networks
      • Define domains for MSSPs
      • Manage environment load balancing
  • Upgrade and migrate
    • Migrate SOAR to Google Cloud
      • Overview
      • Pre-migration validation guide
      • Manage MSSP migration
      • Migrate SOAR permissions to IAM
      • Map SOAR permissions to IAM
      • Migrate to Chronicle API
      • SOAR API mapping table
      • Migrate remote agent authentication infrastructure
      • Frequently asked questions
    • Migrate SIEM to Google Cloud
      • SIEM migration overview
      • Migrate to a Google Cloud project
      • Migrate to Google Cloud authentication
      • Migrate from legacy RBAC to feature RBAC
    • Migrate from legacy SIEM APIs to Chronicle API
      • Overview
      • SIEM API endpoint mapping
    • Migrate an instance to a BYOP project
    • Migrate from legacy features
      • Migrate CBN alerts to YARA-L alerts
      • Migrate from CrowdStrike Detects API to Alerts API
  • Deprovision
  • Build and integrate
  • Deploy centralized content
    • Content Hub overview
    • Run use cases from the Content Hub
    • Power ups and utilities
      • Connectors
      • Email utilities
      • Enrichment
      • File utilities
      • Functions
      • GitSync
      • Image utilities
      • TemplateEngine
      • Insights
      • Lists
      • Tools
  • Develop custom capabilities
    • Use the IDE
    • Get started
      • Develop your first custom integration
      • Develop your first custom action
      • Develop your first email connector
      • Develop your first use case
    • Build and design custom components
      • Build custom integrations
      • Create custom actions
      • Write automated jobs
    • Build and configure connectors
      • Build connector logic
      • Configure custom connectors
      • Test custom connectors
    • Map and model alerts
    • Publish custom integrations
    • Advanced data modeling
      • Develop custom transformers
      • Configure calculated fields for cases
  • Manage response integrations
    • Configure response integrations
    • Roll back response integrations
    • Upgrade the Python version
    • Manage integration dependencies
    • Support multiple instances
    • Test response integrations
    • Manage secrets with secret managers
  • Manage remote agents
    • Get started
      • Overview
      • Review deployment requirements
      • Review data flow and protocols
    • Deploy remote agents
      • Deploy with Docker
      • Deploy with Podman
      • Deploy on Debian
      • Deploy on RHEL
      • Deploy on CentOS
      • Configure high availability
      • Redeploy connectors
    • Configure and validate connectivity
      • Configure the Installer and Docker
      • Configure remote execution
      • Test the connection flow
    • Manage and upgrade remote agents
      • Remote agent scaling strategy
      • Monitor and manage remote agents
      • Perform a standard upgrade
      • Major upgrade with Docker
      • Major upgrade with Podman
      • Major upgrade with RHEL
      • Major upgrade with CentOS
      • Redeploy remote agents
    • Troubleshoot remote agents
  • Collaborate and share
    • Contribute community response integrations
    • Become a technology partner
  • Ingest
  • Prepare for data ingestion
    • Overview
    • Ingestion methods and data types
    • Ingest and parse log data
    • Parsers overview
    • Data feeds overview
    • Data enrichment and aliasing overview
  • Collect data