Google Security Operations SIEM release notes

This page documents production updates to Google Security Operations. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 14, 2026

Deprecated

MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed

The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.

September 11, 2026

Deprecated

Deprecation of write permissions from the chronicle.readonly OAuth scope

Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.

September 03, 2026

Feature

Self-service Bindplane Enterprise license download

This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane Enterprise (Google Edition) license key directly from the platform console under SIEM Settings > Collection Agents.

For more information, see Bindplane Enterprise (Google Edition).

August 26, 2026

Feature

[Spotlight Feature] Mandiant Frontline Threats rule packs

Curated Detections has been enhanced with additional Mandiant Frontline Threats detections for Linux, MacOS, and Google Cloud. The following rule packs have been added to the Content Hub:

August 24, 2026

Feature

Unroll Processor for Data Processing Pipelines

Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing arrays or slices of events into multiple individual log events prior to parsing and ingestion.

Key details:

  • Event Breaking Capability: Automatically expands log arrays into discrete log events.
  • Pre-parsing Requirement: The Unroll processor requires structured data inputs. Raw string payloads must first be parsed using a Transform processor (e.g., set(body, ParseJSON(body))) positioned prior to the Unroll processor in the pipeline execution sequence.

For details on configuring data processing pipelines and processors, see Set up and manage data processing pipelines.

August 12, 2026

Feature

[Spotlight Feature] Analyze feed activity with Cloud Logging

This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.

This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:

  • Investigate telemetry: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
  • Debug feeds: Use the