This page documents production updates to Google Security Operations. You can periodically check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
September 14, 2026
MANDIANT_ACTIVE_BREACH_IOC,MANDIANT_FUSION_IOC, andOPEN_SOURCE_INTEL_IOC` feeds are being removed
The MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds are deprecated in favor of the GTI_IOC feed. After March 18, 2027, we will be removing the MANDIANT_ACTIVE_BREACH_IOC, MANDIANT_FUSION_IOC, and OPEN_SOURCE_INTEL_IOC feeds. For more information on how to migrate, see Migrate Mandiant legacy feeds to GTI.
September 11, 2026
Deprecation of write permissions from the chronicle.readonly OAuth scope
Effective January 25, 2027, write permissions will be removed from the chronicle.readonly OAuth scope, restricting it strictly to read operations. You can continue using chronicle.readonly for read operations. Make sure you update any workflows performing write operations to use the chronicle OAuth scope.
September 03, 2026
Self-service Bindplane Enterprise license download
This feature is currently in Preview for Google Security Operations tenants in the US and EU regions. Google Security Operations Enterprise Plus and Google Unified Security (GUS) customers can now download their Bindplane Enterprise (Google Edition) license key directly from the platform console under SIEM Settings > Collection Agents.
For more information, see Bindplane Enterprise (Google Edition).
August 26, 2026
[Spotlight Feature] Mandiant Frontline Threats rule packs
Curated Detections has been enhanced with additional Mandiant Frontline Threats detections for Linux, MacOS, and Google Cloud. The following rule packs have been added to the Content Hub:
August 24, 2026
Unroll Processor for Data Processing Pipelines
Google SecOps data processing pipelines now support the Unroll processor (event breaking). This processor allows you to split log entries containing arrays or slices of events into multiple individual log events prior to parsing and ingestion.
Key details:
- Event Breaking Capability: Automatically expands log arrays into discrete log events.
- Pre-parsing Requirement: The Unroll processor requires structured data inputs. Raw string payloads must first be parsed using a Transform processor (e.g.,
set(body, ParseJSON(body))) positioned prior to the Unroll processor in the pipeline execution sequence.
For details on configuring data processing pipelines and processors, see Set up and manage data processing pipelines.
August 12, 2026
[Spotlight Feature] Analyze feed activity with Cloud Logging
This feature is in public preview. To use this feature, your Google SecOps instance must be configured with a Bring Your Own Project (BYOP) Google Cloud project. You can now monitor, debug, and troubleshoot Google SecOps SIEM ingestion pipelines and feeds using Cloud Logging. By sending, viewing, and querying ingestion and feed activity logs in Logs Explorer, you can diagnose log delivery issues, such as, missing, delayed, or failing logs, and decrease the time required to resolve ingestion anomalies.
This visibility into push- and pull-based ingestion mechanisms provides the following capabilities:
- Investigate telemetry: Use Gemini Cloud Assist to investigate logging and metrics telemetry directly from the Google SecOps console.
- Debug feeds: Use the Debug with logs option on the Feed management page to open Logs Explorer pre-filtered for a specific feed.
- Filter routed logs: Configure exclusion filters in the Log Router to exclude specific logs, such as Storage Transfer Service (STS) logs, from being routed to Cloud Logging.
For more information, see Analyze feed activity with Cloud Logging.
July 29, 2026
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- Airlock Digital Application Allowlisting (
AIRLOCK_DIGITAL) - AIX system (
AIX_SYSTEM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Akamai SIEM Connector (
AKAMAI_SIEM_CONNECTOR) - Apache (
APACHE) - Arcsight CEF (
ARCSIGHT_CEF) - Armis Alerts (
ARMIS_ALERTS) - Aruba Switch (
ARUBA_SWITCH) - Atlassian Cloud Admin Audit (
ATLASSIAN_AUDIT) - Linux Auditing System (AuditD) (
AUDITD) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS Control Tower (
AWS_CONTROL_TOWER) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Key Vault logging (
AZURE_KEYVAULT_AUDIT) - Microsoft Azure Resource (
AZURE_RESOURCE_LOGS) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - BeyondTrust (
BOMGAR) - Cato Networks (
CATO_NETWORKS) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Harmony (
CHECKPOINT_HARMONY) - Chrome Management (
CHROME_MANAGEMENT) - ChromeOS XDR (
CHROMEOS_XDR) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT) - Cisco ISE (
CISCO_ISE) - Cisco Router (
CISCO_ROUTER) - Cisco Switch (
CISCO_SWITCH) - Cisco UCM (
CISCO_UCM) - Claroty Xdome (
CLAROTY_XDOME) - Claude Compliance Logs (
CLAUDE_COMPLIANCE_LOGS) - HP Aruba (ClearPass) (
CLEARPASS) - Cloudflare (
CLOUDFLARE) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - CrowdStrike Falcon (
CS_EDR) - Darktrace (
DARKTRACE) - EfficientIP DDI (
EFFICIENTIP_DDI) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - Fastly CDN (
FASTLY_CDN) - FireEye eMPS (
FIREEYE_EMPS) - FireEye HX (
FIREEYE_HX) - FireEye NX (
FIREEYE_NX) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet FortiClient (
FORTINET_FORTICLIENT) - Fortinet Switch (
FORTINET_SWITCH) - GCP Cloud Audit (
GCP_CLOUDAUDIT) - Security Command Center External Exposure (
GCP_SECURITYCENTER_EXTERNAL_EXPOSURE) - Gitlab (
GITLAB) - Google Threat Intelligence IOC (
GTI_IOC) - AWS GuardDuty (
GUARDDUTY) - Huawei Switches (
HUAWEI_SWITCH) - IBM Security Access Manager (
IBM_SAM) - Microsoft IIS (
IIS) - Illumio Core (
ILLUMIO_CORE) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox (
INFOBLOX) - Infoblox DHCP (
INFOBLOX_DHCP) - Jamf pro context (
JAMF_PRO_CONTEXT) - Mobile Endpoint Security (
LOOKOUT_MOBILE_ENDPOINT_SECURITY) - Apple macOS (
MACOS) - McAfee IPS (
MCAFEE_IPS) - Micro Focus iManager (
MICROFOCUS_IMANAGER) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft SQL Server (
MICROSOFT_SQL) - Mimecast URL Logs (
MIMECAST_URL_LOGS) - MISP Threat Intelligence (
MISP_IOC) - NetApp ONTAP (
NETAPP_ONTAP) - Netskope V2 (
NETSKOPE_ALERT_V2) - Unix system (
NIX_SYSTEM) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Onapsis (
ONAPSIS) - OpenVPN (
OPEN_VPN) - Oracle Fusion (
ORACLE_FUSION) - Ping Identity (
PING) - Proofpoint Sendmail Sentrion (
PROOFPOINT_SENDMAIL_SENTRION) - SailPoint IAM (
SAILPOINT_IAM) - Salesforce (
SALESFORCE) - Sendmail (
SENDMAIL) - Sentinelone Alerts (
SENTINELONE_ALERT) - ServiceNow Audit (
SERVICENOW_AUDIT) - ServiceNow CMDB (
SERVICENOW_CMDB) - ServiceNow Security (
SERVICENOW_SECURITY) - SonicWall (
SONIC_FIREWALL) - STIX Threat Intelligence (
STIX) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Thinkst Canary (
THINKST_CANARY) - ThreatConnect IOC V3 (
THREATCONNECT_IOC_V3) - ThreatLocker Platform (
THREATLOCKER) - Varonis (
VARONIS) - VMware ESXi (
VMWARE_ESX) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - wiz.io (
WIZ_IO) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zoom Operation Logs (
ZOOM_OPERATION_LOGS)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Adobe Experience Platform (
ADOBE_EXPERIENCE_PLATFORM) - AudioCodes Session Border Controller (
AUDIOCODES_SBC) - Azure Application Gateway for Containers (
AZURE_GATEWAY_CONTAINERS) - Azure Logic Apps (
AZURE_LOGIC_APPS) - Azure NAT Gateway Flow (
AZURE_NATGW_FLOW) - Broadcom DX NetOps Spectrum (
BROADCOM_DX_NETOPS_SPECTRUM) - Carto Activity (
CARTO_ACTIVITY) - Claude Code Observability (
CLAUDE_CODE_OBSERVABILITY) - Cyble Attack Surface Management (
CYBLE_ASM) - Cyble Brand Intelligence & Protection (
CYBLE_BIP) - Darkweb IQ (
DARKWEB_IQ) - Ellio Threat Intelligence (
ELLIO_THREAT_INTEL) - Exeon NDR (
EXEON_NDR) - Gravitee (
GRAVITEE) - Kaspersky anti targeted attack (
KASPERSKY_ANTI_TARGETED_ATTACK) - Microsoft Copilot Interaction (
MICROSOFT_COPILOT_INTERACTION) - OSTTRA MarkitWire (
OSTTRA_MARKITWIRE) - Proofpoint Adaptive Email Security (
PROOFPOINT_ADAPTIVE_EMAIL_SECURITY) - Secomea GateManager (
SECOMEA_GATEMANAGER) - Trend Micro Vision One Risk Event (
TRENDMICRO_VISION_ONE_RISK_EVENT) - TXOne EdgeIPS (
TXONE_EDGEIPS) - Vectra Respond UX (
VECTRA_RUX) - Zoho CRM (
ZOHO_CRM)
View prebuilt parser version content
You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.
July 20, 2026
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
Google Security Operations is deprecating its legacy SIEM APIs—Backstory API (including Customer Management API) and Ingestion API—in favor of the modern Chronicle API.
Key dates
- October 26, 2026: New Google SecOps instances provisioned from this date will no longer support legacy API calls.
- July 20, 2027: All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down.
This change applies only to custom scripts, integrations, SOAR connectors, or ingestion feeds calling legacy Backstory API or Ingestion API endpoints. Any changes impacting the Google SecOps UI are already addressed and don't call for your action.
Next steps
Audit API usage to identify any affected components that currently call legacy Backstory API or Ingestion API endpoints, and replace them with Chronicle API endpoints.
Validate and test that your updated components work properly.
For more information, see Migrate from legacy API to Chronicle API.
July 15, 2026
Advanced Filtering in Dashboards
This feature is in public preview.
Advanced Filtering in dashboards is now available in Google SecOps. This feature enhances dashboard capabilities by enabling security analysts to use query variables, also known as tokens, to inject dynamic values, complex regular expressions, or boolean logic directly into YARA-L queries at runtime.
Key aspects of Advanced Filtering include:
- Token Variable Definition: When creating an advanced filter, you can define a Token Variable. Token variable names must consist only of alphanumeric characters and underscores (
^[a-zA-Z0-9_]+$) and must be unique within the dashboard. - Filter Value Generation: Token values can be generated dynamically from YARA-L query results or entered manually as a static list.
- Customizable Wrappers: You can specify prefixes and suffixes to wrap token values, enabling specific logic such as regular expressions.
- Multi-Select Support: The ability to select multiple options for a token can be enabled, with a configurable delimiter (for example,
|) for combining values in queries.
For more information, see Advanced filtering.
Parser extensions for code snippets now support Append/Replace for Repeated Fields
You can now use append and replace functionality for repeated fields when creating code snippet extensions. Previously, this was only available for no-code extensions. This enhancement provides more granular control over how data is handled in repeated UDM fields, allowing you to either add new values or entirely replace existing ones.
For more information, see Repeated fields selector.
July 01, 2026
[Spotlight Feature] Security Tokens
Security Tokens are now available for metering agentic consumption within Google SecOps. Tokens are consumed by generally available security agents only. These agents are invoked automatically or manually using the web interface, CLI, chat, or Model Context Protocol (MCP). Assistive features, such as standard chat panels and automated summaries, along with preview agents, won't consume Security Tokens.
Security Tokens will start rolling out across all regions starting July 1. For more information, see Google SecOps Agentic SOC Security Tokens pricing and billing.
June 30, 2026
Increased multiple event limits
Multiple event rule limits have been increased to 200 for Enterprise customers and 400 for Enterprise+ customers.
For more information, see Package comparison
Unified rules interface
The new rules interface is now available in public preview.
The Google SecOps unified rules interface brings custom and curated rule management into a single, cohesive workflow. This optimizes detection engineering with a redesigned dashboard, an advanced rule editor, and expanded API capabilities to streamline rule deployment and troubleshooting.
You can still revert to the legacy experience. At the top right of the screen, click Switch to the legacy experience.
For more information about the Unified rules interface, see Manage unified rules.
June 28, 2026
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- AIX system (
AIX_SYSTEM) - Amazon API Gateway (
AWS_API_GATEWAY) - Apache (
APACHE) - Appian Cloud (
APPIAN_CLOUD) - Aruba Switch (
ARUBA_SWITCH) - Atlassian Bitbucket (
ATLASSIAN_BITBUCKET) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS GuardDuty (
GUARDDUTY) - AWS Network Firewall (
AWS_NETWORK_FIREWALL) - AWS RDS (
AWS_RDS) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS VPC Flow (
AWS_VPC_FLOW) - AWS VPC Flow (CSV) (
AWS_VPC_FLOW_CSV) - AWS WAF (
AWS_WAF) - Azure AD (
AZURE_AD) - Barracuda WAF (
BARRACUDA_WAF) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Cato Networks (
CATO_NETWORKS) - Check Point Harmony (
CHECKPOINT_HARMONY) - Chrome Management (
CHROME_MANAGEMENT) - CircleCI (
CIRCLECI) - Cisco ACS (
CISCO_ACS) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco Router (
CISCO_ROUTER) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Cisco Umbrella Cloud Firewall (
UMBRELLA_FIREWALL) - Cisco Umbrella Web Proxy (
UMBRELLA_WEBPROXY) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco WLC/WCS (
CISCO_WIRELESS) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Xdome (
CLAROTY_XDOME) - Cloudflare (
CLOUDFLARE) - Corelight (
CORELIGHT) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CyberArk PTA Privileged Threat Analytics (
CYBERARK_PTA) - Cynet 360 AutoXDR (
CYNET_360_AUTOXDR) - Dell Switch (
DELL_SWITCH) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - FireEye ETP (
FIREEYE_ETP) - FireEye NX (
FIREEYE_NX) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - FortiMail Email Security (
FORTINET_FORTIMAIL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GitHub (
GITHUB) - Google Cloud Audit (
GCP_CLOUDAUDIT) - Google Cloud DNS (
GCP_DNS) - HAProxy (
HAPROXY) - IBM Tape Storages (
IBM_LTO) - Imperva CEF (
IMPERVA_CEF) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox DNS (
INFOBLOX_DNS) - Island Browser logs (
ISLAND_BROWSER) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS) - Kemp Load Balancer (
KEMP_LOADBALANCER) - Kubernetes Node (
KUBERNETES_NODE) - ManageEngine ADAudit Plus (
ADAUDIT_PLUS) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Microsoft SQL Server (
MICROSOFT_SQL) - MISP Threat Intelligence (
MISP_IOC) - NetApp ONTAP (
NETAPP_ONTAP) - NetIQ eDirectory (
NETIQ_EDIRECTORY) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - NGINX (
NGINX) - Noname API Security (
NONAME_API_SECURITY) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Oracle (
ORACLE_DB) - Oracle Cloud Infrastructure VCN Flow Logs (
OCI_FLOW) - Oracle NetSuite (
ORACLE_NETSUITE) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Access (
PAN_CASB) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Ping Identity (
PING) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - RSA (
RSA_AUTH_MANAGER) - Salesforce (
SALESFORCE) - Security Command Center Error (
GCP_SECURITYCENTER_ERROR) - Security Command Center Misconfiguration (
GCP_SECURITYCENTER_MISCONFIGURATION) - Security Command Center Observation (
GCP_SECURITYCENTER_OBSERVATION) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
GCP_SECURITYCENTER_THREAT) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Security Command Center Unspecified (
GCP_SECURITYCENTER_UNSPECIFIED) - Security Command Center Vulnerability (
GCP_SECURITYCENTER_VULNERABILITY) - Sendmail (
SENDMAIL) - Sentinelone Activity (
SENTINELONE_ACTIVITY) - ServiceNow CMDB (
SERVICENOW_CMDB) - Sophos Firewall (Next Gen) (
SOPHOS_FIREWALL) - Squid Web Proxy (
SQUID_WEBPROXY) - Symantec EDR (
SYMANTEC_EDR) - Symantec Endpoint Protection (
SEP) - Sysdig (
SYSDIG) - Thinkst Canary (
THINKST_CANARY) - Trellix EDRF Trace Data and Telemetry (
TRELLIX_EDRF) - Trend Micro Vision One Detections (
TRENDMICRO_VISION_ONE_DETECTIONS) - Trend Micro Vision One Workbench (
TRENDMICRO_VISION_ONE_WORKBENCH) - Unix system (
NIX_SYSTEM) - Varonis (
VARONIS) - Veeam (
VEEAM) - VMware vCenter (
VMWARE_VCENTER) - VMWare VSphere (
VMWARE_VSPHERE) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Windows Sysmon (
WINDOWS_SYSMON) - wiz.io (
WIZ_IO) - Workday User Activity (
WORKDAY_USER_ACTIVITY) - Zeek JSON (
BRO_JSON) - Zscaler (
ZSCALER_WEBPROXY) - ZScaler NGFW (
ZSCALER_FIREWALL)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Cisco Secure Access Enrollment (
CISCO_SECURE_ACCESS_ENROLLMENT) - Cisco Secure Access Network (
CISCO_SECURE_ACCESS_NETWORK) - CyberArk Certificate Manager SaaS (
CYBERARK_CERTIFICATE_MANAGER_SAAS) - Gemini Enterprise Agent Platform (
GEMINI_ENTERPRISE_AGENT_PLATFORM) - Schneider Electric GeoScada OT (
GEOSCADA_OT) - Model Context Protocol Dev (
MCPDEV) - Model Context Protocol Modify (
MCPMODIFY) - Model Context Protocol View (
MCPVIEW) - NetApp Ransomware Resilience (
NETAPP_RANSOMWARE_RESILIENCE) - Netskope Log Streaming (
NETSKOPE_LOG_STREAMING) - Pylon Audit Logs (
PYLON_LOGS) - Reco AI CSPM (
RECO_CSPM) - Salt Security API Protection Platform (
SALT_SECURITY) - SentinelOne Application (
SENTINELONE_APPLICATION) - Wiz Vulnerabilities (
WIZ_VULNERABILITIES)
June 26, 2026
Improved documentation portal navigation
Finding help is now easier! We've updated the navigation of our documentation portal to be primarily user-centric. Sections have been reorganized and renamed to align with your workflows, providing a logical path through the documentation.
We've also added:
- A Support tab for technical support, changelogs, and release notes
- A Use cases tab for persona-driven CUJs and workflows
June 23, 2026
Ask Gemini Cloud Assist in Feed Management
Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation, setup, and general troubleshooting questions.
A new Ask Gemini Cloud Assist button is now available in the Feed Management interface. You can click this button to open the Gemini Cloud Assist panel and ask questions to get guidance on:
- Configuring and managing data feeds.
- Understanding ingestion pre-requisites and setup steps for different log sources.
- Resolving common setup issues.
Note: Gemini Cloud Assist provides recommendations and answers to your questions, but does not perform configuration changes on your behalf. You must apply any recommended changes manually to your feeds.
For more information, see Feed management overview.
Ingestion metrics reporting correction
Google Security Operations has resolved an issue where certain ingestion metrics—which are displayed in both the dashboard and Cloud Monitoring—were under-reported.
Because of this correction, you might notice a one-time apparent spike in your ingestion metrics when the update is enabled for your region (between June 29 and July 10, 2026). The actual log volume ingested remains unchanged.
Historical metrics recorded before this update will not be modified or backfilled. This correction does not affect customer billing.
If you have questions or need assistance, contact Google Security Operations support.
June 17, 2026
Auto-collapse setting for the query editor
You can now configure the query editor to automatically collapse after you run a search, maximizing the screen space available for viewing your search results. By default, the query editor remains expanded.
For more information, see Configure query editor behavior.
June 16, 2026
New Documentation changelogs
Google SecOps is now releasing a monthly changelog to capture major documentation updates.
For more information, refer to Documentation changelog.
June 13, 2026
Non-prioritized IoC Matching rules Category
Google SecOps has introduced a new detection category, Non-prioritized IoC Matching rules, as part of the Curated Detections feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.
This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.
For more information, refer to Non-prioritized IoC Matching rules category overview.
June 12, 2026
[Spotlight Feature] Investigate detections in Google SecOps Search
Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the Alerts and Detections tab, providing a more holistic workflow for threat investigation.
For more details, see Investigate detections in Search.
Asynchronous Search APIs for large datasets
Google SecOps now supports asynchronous Search APIs that let you perform long-running queries without blocking your applications. This is ideal for searches that return a large volume of results.
- Non-blocking queries: Initiate searches and receive an operation ID to track progress, so your application remains responsive.
- Handle large result sets: Retrieve up to 1 million results from data sources including Unified Data Model (UDM) events, data tables, and Entity Context Graph (ECG).
- Paginated results: View results efficiently in manageable pages.
For more information, see Asynchronous Search APIs and Result limits for data sources.
June 09, 2026
UDM fields now show the sources of enrichment
The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its data source: U for unenriched fields and E for enriched fields. Enriched fields contain additional metadata values that indicate the source of the enriched data.
For more information, see: Viewing events.
May 31, 2026
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- 1Password Audit Events (
ONEPASSWORD_AUDIT_EVENTS) - AIX system (
AIX_SYSTEM) - Apache (
APACHE) - Aruba EdgeConnect SD-WAN (
ARUBA_EDGECONNECT_SDWAN) - Avaya Aura Experience Portal (
AVAYA_AURA) - AWS CloudFront (
AWS_CLOUDFRONT) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS GuardDuty (
GUARDDUTY) - AWS Security Hub (
AWS_SECURITY_HUB) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure AD Sign-In (
AZURE_AD_SIGNIN) - Azure SQL (
AZURE_SQL) - Azure Storage Audit (
AZURE_STORAGE_AUDIT) - Barracuda WAF (
BARRACUDA_WAF) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Chrome Management (
CHROME_MANAGEMENT) - Cisco ACS (
CISCO_ACS) - Cisco ISE (
CISCO_ISE) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Secure Workload (
CISCO_SECURE_WORKLOAD) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Xdome (
CLAROTY_XDOME) - Claude Compliance Logs (
CLAUDE_COMPLIANCE_LOGS) - Cloudflare (
CLOUDFLARE) - Cloudflare Warp (
CLOUDFLARE_WARP) - Corelight (
CORELIGHT) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CyberArk (
CYBERARK) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Duo Administrator Logs (
DUO_ADMIN) - EfficientIP DDI (
EFFICIENTIP_DDI) - Elastic Audit Beats (
ELASTIC_AUDITBEAT) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT) - F5 ASM (
F5_ASM) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - GitHub (
GITHUB) - Google Cloud Asset Inventory (
GCP_CLOUD_ASSET_INVENTORY) - Google Cloud Audit (
GCP_CLOUDAUDIT) - Google Compute Context (
GCP_COMPUTE_CONTEXT) - Google Threat Intelligence IOC (
GTI_IOC) - GTB Technologies DLP (
GTB_DLP) - HP Aruba (ClearPass) (
CLEARPASS) - IBM Websphere Application Server (
IBM_WEBSPHERE_APP_SERVER) - IBM z/OS (
IBM_ZOS) - Imperva (
IMPERVA_WAF) - Imperva CEF (
IMPERVA_CEF) - Imperva DRA (
IMPERVA_DRA) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Island Browser logs (
ISLAND_BROWSER) - Juniper (
JUNIPER_FIREWALL) - Juniper Mist (
JUNIPER_MIST) - Kubernetes Node (
KUBERNETES_NODE) - LastPass Password Management (
LASTPASS) - Linux Auditing System (AuditD) (
AUDITD) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft IIS (
IIS) - Mobileiron (
MOBILEIRON) - Mongo Database (
MONGO_DB) - MySQL (
MYSQL) - Netapp Storagegrid (
NETAPP_STORAGEGRID) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - NGFW Enterprise (
GCP_NGFW_ENTERPRISE) - Office 365 (
OFFICE_365) - Office 365 Message Trace (
OFFICE_365_MESSAGETRACE) - Okta Scaleft (
OKTA_SCALEFT) - Oracle (
ORACLE_DB) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT) - Orca Cloud Security Platform (
ORCA) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Red Hat Directory Server LDAP (
REDHAT_DIRECTORY_SERVER) - Red Hat OpenShift (
REDHAT_OPENSHIFT) - Salesforce (
SALESFORCE) - Sangfor Next Generation Firewall (
SANGFOR_NGAF) - Security Command Center Error (
GCP_SECURITYCENTER_ERROR) - Security Command Center Misconfiguration (
GCP_SECURITYCENTER_MISCONFIGURATION) - Security Command Center Observation (
GCP_SECURITYCENTER_OBSERVATION) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
GCP_SECURITYCENTER_THREAT) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Security Command Center Unspecified (
GCP_SECURITYCENTER_UNSPECIFIED) - Security Command Center Vulnerability (
GCP_SECURITYCENTER_VULNERABILITY) - SentinelOne Singularity Cloud Funnel (
SENTINELONE_CF) - ServiceNow Security (
SERVICENOW_SECURITY) - Sourcefire (
SOURCEFIRE_IDS) - Suricata EVE (
SURICATA_EVE) - Symantec Endpoint Protection (
SEP) - Sysdig (
SYSDIG) - Trend Micro Deep Security (
TRENDMICRO_DEEP_SECURITY) - Trend Micro Vision One Observerd Attack Techniques (
TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES) - Ubiquiti UniFi Switch (
UBIQUITI_SWITCH) - Unix system (
NIX_SYSTEM) - Upwind (
UPWIND) - VMware ESXi (
VMWARE_ESX) - VMWare VSphere (
VMWARE_VSPHERE) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Wiz.io (
WIZ_IO) - Workday User Activity (
WORKDAY_USER_ACTIVITY) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zscaler (
ZSCALER_WEBPROXY) - Zscaler CASB (
ZSCALER_CASB) - Zscaler DLP (
ZSCALER_DLP) - Zscaler Private Access (
ZSCALER_ZPA)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Azure Software Vulnerabilities (
AZURE_SOFTWARE_VULNERABILITIES) - Caller Verify (
CALLER_VERIFY) - CertSecure Log (
CERTSECURE_LOG) - Cisco MultiCloud Defense Firewall (
CISCO_MULTICLOUD_DEFENSE_FIREWALL) - Cursor (
CURSOR) - Cyfirma (
CYFIRMA_DECYFIR_LOG) - Databahn (
DATABAHN) - Flare Darkweb Alerts (
FLARE_DARKWEB_ALERTS) - Fortinet FortiAppSec Cloud (
FORTINET_FORTIAPPSEC) - Hikvision Network Video Recorders (
HIKVISION_NVR) - IBM B2B Integrator (
IBM_B2B_INTEGRATOR) - IBM InfoSphere Virtual Data Pipeline (
IBM_VDP) - Imperva Account TakeOver (
IMPERVA_ATO) - Imperva Client Side Protection (
IMPERVA_CSP) - Imperva DNS (
IMPERVA_DNS) - Imperva Network Security (
IMPERVA_NETWORK_SECURITY) - Microsoft Defender XDR (
MICROSOFT_DEFENDER_XDR) - Nakivo Backup and Recovery (
NAKIVO_BACKUP) - Netcraft Takedown (
NETCRAFT_TAKEDOWN) - Next Level Performance Amplify (
NXL_AMPLIFY) - Siemens Desigo (
SIEMENS_DESIGO)
May 28, 2026
Upgraded Chronicle API
We've upgraded the following Chronicle API resources from v1 beta to v1. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for all new integrations, for a more robust, secure, and extensible experience. Learn more about API Stability.
The following features and resources are included in this update:
- Alerts and ATIs, UEBA: Threat Collection, IoC, CoverageDetail, EntityRisk
- Dashboards: NativeDashboard, DashboardChart, DashboardQuery, FeaturedContentNativeDashboard
- Data Tables: DataTable, DataTableRow, DataTableOperationError
- Ingestion: Logs, Feed, LogTypeSchema, FeedSourceSchema, FeedPack, Forwarder
- Normalization: Logtype, Parser, IngestionLogLabel
- Detections: FindingsRefinement, VerifyRuleText, FeaturedContentRule, RuleExecutionError
- Search & Investigation: Event, Entity, SearchQuery, SavedColumnSet
- Exports: BigQueryExportService
- Enrichment Controls: EnrichmentControl, EnrichmentCombination
For a full list of updated resources and links to the documentation, please see the Chronicle API documentation.
May 27, 2026
Standard parser support policy
Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The new policy structures service level objectives (SLOs) and request triaging by customer support tiers (Standard versus Expert/Expert+), and prioritizes core security data through Important UDM Fields. Additionally, the policy outlines a community-driven model where low-usage, longtail prebuilt parsers migrate to a dedicated GitHub repository maintained by partners and the Google SecOps community.
For more information, see Standard parser support policy.
May 18, 2026
Enhanced Data Export API general availability and improvements
The Data Export API is now GA and introduces significant security and capability improvements. This feature facilitates the bulk export of your security data from Google SecOps to a Google Cloud Storage bucket that you control, and it provides a more secure and scalable data archival experience than the legacy Data Export API feature.
Here's what's new:
- Advanced data filtering: the API now lets you additionally scope export jobs using namespaces and ingestion labels.
- Zero-trust security (customer-managed encryption keys): full integration with Google Cloud Key Management Service (KMS) ensures that all exported data is encrypted with customer-managed keys.
- Identity-aware extraction (RBAC): export jobs now inherit the data RBAC scope of users creating an export job, preventing unauthorized data extraction.
For more information, see Data Export API (enhanced).
The legacy Data Export API is deprecated in favor of the enhanced Data Export API, which provides a more secure and scalable data archival experience. After June 18, 2026, legacy Data Export API won't work.
The fetchavailablelogtypes API endpoint is deprecated in favor of the list endpoint. After June 18, 2026, the fetchavailablelogtypes API endpoint won't work.
The updateDataExport endpoint in the enhanced Data Export API is deprecated. The reduction in job queue times using the enhanced Data Export API has eliminated the need for the update functionality of the updateDataExport API endpoint. The updateDataExport endpoint was present in v1alpha only; it wasn't present in in v1beta or v1. After June 18, 2026, the updateDataExport API endpoint won't work. You can still cancel queued export jobs.
The logType field in the enhanced Data Export API is deprecated in favor of the new (optional)includeLogTypes field, which supports an array of log types for data filtering. If left blank, the export job includes all log types by default. The logType field was present in v1alpha only; it wasn't present in in v1beta or v1. After June 18, 2026, the logType field is discontinued.
May 17, 2026
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect Arista VeloCloud SD-WAN logs
- Collect Microsoft Defender for Endpoint logs
- Collect PTC Windchill logs
- Collect Riverbed SteelHead logs
- Collect Sangfor Proxy logs
- Collect SAP BTP logs
- Collect SAP NetWeaver logs
- Collect SAP SM20 logs
- Collect SAP SuccessFactors logs
- Collect SAP Sybase ASE logs
- Collect Saviynt Enterprise Identity Cloud logs
- Collect SecureLink logs
- Collect Semperis DSP logs
- Collect Sonrai Security logs
- Collect SOTI MobiControl logs
- Collect Splunk Attack Analyzer logs
- Collect SpyCloud logs
- Collect Stealthbits Audit logs
- Collect Stealthbits StealthDEFEND logs
- Collect STIX Threat Intelligence logs
- Collect Swift Alliance Messaging Hub logs
- Collect Symantec Messaging Gateway logs
- Collect Symantec Security Analytics logs
- Collect Tableau logs
- Collect Talon logs
- Collect TCPWave DDI logs
- Collect Teleport Access Plane logs
- Collect Tenable Audit logs
- Collect Tenable CSPM logs
- Collect Teradata Database logs
- Collect Terraform Enterprise logs
- Collect Tetragon eBPF audit logs
- Collect ThreatLocker Platform logs
- Collect ThreatX WAF logs
- Collect Tintri logs
- Collect Trend Micro Apex Central logs
- Collect uberAgent logs
- Collect Ubika WAF logs
- Collect UKG logs
- Collect UPX AntiDDoS logs
- Collect Verba Recording System logs
- Collect Vercel WAF logs
- Collect Virtru Email Encryption logs
- Collect WatchGuard EDR logs
- Collect Windows AppLocker logs
- Collect Windows Defender Antivirus logs
- Collect Windows Firewall logs
- Collect Windows Hyper-V logs
- Collect Windows Network Policy Server logs
May 12, 2026
Time range selection for searches
Google SecOps has now added relative and absolute time range options to define the required time period for retrieving search results.
- Relative time range: Set a search window looking backward from the current time using custom intervals.
- Absolute time range: Define fixed start and end times using calendar presets, exact date and time selections, or event-based timeframes.
For more information, see Set the date and time range.
May 05, 2026
Google SecOps has updated the list of list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- Akeyless Vault Platform (
AKEYLESS_VAULT) - Apache Cassandra (
CASSANDRA) - Aruba (
ARUBA_WIRELESS) - Aruba EdgeConnect SD-WAN (
ARUBA_EDGECONNECT_SDWAN) - Auth0 (
AUTH_ZERO) - AWS Aurora (
AWS_AURORA) - AWS EC2 VPCs (
AWS_EC2_VPCS) - AWS Security Hub (
AWS_SECURITY_HUB) - Azure Firewall (
AZURE_FIREWALL) - Azure Front Door (
AZURE_FRONT_DOOR) - Barracuda CloudGen Firewall (
BARRACUDA_CLOUDGEN_FIREWALL) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Sandblast (
CHECKPOINT_EDR) - Checkpoint SmartDefense (
CHECKPOINT_SMARTDEFENSE) - Chronicle SOAR Audit (
CHRONICLE_SOAR_AUDIT) - Cisco Application Centric Infrastructure (
CISCO_ACI) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Secure Workload (
CISCO_SECURE_WORKLOAD) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Cisco WLC/WCS (
CISCO_WIRELESS) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Xdome (
CLAROTY_XDOME) - Cloudflare Warp (
CLOUDFLARE_WARP) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CyberArk (
CYBERARK) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - EPIC Systems (
EPIC) - F5 ASM (
F5_ASM) - F5 BIGIP Access Policy Manager (
F5_BIGIP_APM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - F5 Distributed Cloud Services (
F5_DCS) - FireEye eMPS (
FIREEYE_EMPS) - FireEye NX (
FIREEYE_NX) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiEDR (
FORTINET_FORTIEDR) - Fortinet Proxy (
FORTINET_WEBPROXY) - GitHub (
GITHUB) - Google Cloud Audit (
GCP_CLOUDAUDIT) - Google Threat Intelligence IOC (
GTI_IOC) - Guardicore Centra (
GUARDICORE_CENTRA) - HP Aruba (ClearPass) (
CLEARPASS) - Huawei Switches (
HUAWEI_SWITCH) - IBM Websphere Application Server (
IBM_WEBSPHERE_APP_SERVER) - IBM z/OS (
IBM_ZOS) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox (
INFOBLOX) - Juniper (
JUNIPER_FIREWALL) - Kubernetes Node (
KUBERNETES_NODE) - Linux Auditing System (AuditD) (
AUDITD) - ManageEngine ADManager Plus (
ADMANAGER_PLUS) - McAfee ePolicy Orchestrator (
MCAFEE_EPO) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Microsoft Defender For Cloud (
MICROSOFT_DEFENDER_CLOUD_ALERTS) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Identity (
MICROSOFT_DEFENDER_IDENTITY) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Mobileiron (
MOBILEIRON) - Model Armor (
GCP_MODEL_ARMOR) - MySQL (
MYSQL) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Noname API Security (
NONAME_API_SECURITY) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT) - Oracle NetSuite (
ORACLE_NETSUITE) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Access (
PAN_CASB) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Ping Identity (
PING) - PostFix Mail (
POSTFIX_MAIL) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Rapid7 Insight (
RAPID7_INSIGHT) - SAP Hana Audit (
SAP_HANA_AUDIT) - SecureAuth (
SECUREAUTH_SSO) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
GCP_SECURITYCENTER_THREAT) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - SentinelOne Deep Visibility (
SENTINEL_DV) - SentinelOne Singularity Cloud Funnel (
SENTINELONE_CF) - Silverfort Authentication Platform (
SILVERFORT) - SiteMinder Web Access Management (
CA_SSO_WEB) - SonicWall (
SONIC_FIREWALL) - Squid Web Proxy (
SQUID_WEBPROXY) - STIX Threat Intelligence (
STIX) - Suricata EVE (
SURICATA_EVE) - Sysdig (
SYSDIG) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Thinkst Canary (
THINKST_CANARY) - Trend Micro Apex one (
TRENDMICRO_APEX_ONE) - Unix system (
NIX_SYSTEM) - Vectra XDR (
VECTRA_XDR) - VMware ESXi (
VMWARE_ESX) - Wallix Bastion (
WALLIX_BASTION) - WatchGuard (
WATCHGUARD) - Windows Defender AV (
WINDOWS_DEFENDER_AV) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - wiz.io (
WIZ_IO) - Zscaler Email DLP (
ZSCALER_EMAIL_DLP)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Altiris Logs (
ALTIRIS_LOGS) - Aruba Access Point (
ARUBA_AP) - BloxOne Threat Defense DHCP (
BLOXONE_DHCP) - Checkmarx One (
CHECKMARX_ONE) - Cisco Nexus Dashboard Orchestrator (
CISCO_NDO) - CrowdStrike Cloud Security (
CROWDSTRIKE_CSPM) - F5 F5OS-A Logging (
F5_F5OS_A) - GateWatcher NDR (
GATEWATCHER_NDR) - Hashicorp Terraform (
HASHICORP_TERRAFORM) - Jamf Protect Alerts V2 (
JAMF_PROTECT_V2) - Oracle Cloud Infrastructure Web Application Firewall (
OCI_WAF) - Qualys File Integrity Monitoring (
QUALYS_FIM) - SailPoint IdentityNow (
SAILPOINT_IDENTITYNOW) - ServiceNow Certificate Logs (
SERVICENOW_CERTIFICATE) - ServiceNow User Logs (
SERVICENOW_USER) - ServiceNow User Login History (
SERVICENOW_USER_LOGIN_HISTORY) - SiteGuard Server (
SITEGUARD_SERVER) - Tosi Hub (
TOSI_HUB) - Trellix Network Detection and Response (
TRELLIX_NDR)
April 22, 2026
Support for the legacy Google Security Operations SIEM infrastructure will end on April 30, 2027. After this date, you will no longer have access to your Google SecOps SIEM instance on the legacy infrastructure. You need to self-migrate Google Security Operations SIEM in legacy Infrastructure to Google Cloud to align with industry standards and improve your reliability, privacy, security, compliance, and granular access controls. Follow the Migration guide and Community post to begin your transition.
This migration applies to you only if your SIEM instance meets one of the conditions below:
- Not deployed in your Google Cloud Project
- Not using Google Cloud Authentication (Workforce Identity Federation / Cloud Identity)
- Not using Google Cloud IAM for Feature Role based access controls.
This migration does not apply to you if your SIEM instance meets all the conditions below:
- Is deployed in your Google Cloud project
- Uses Workforce Identity Federation or Cloud Identity for authentication
- Uses Google Cloud IAM to manage granular access permissions
April 19, 2026
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect Group-IB Threat Intelligence logs
- Collect Microsoft System Center Endpoint Protection (SCEP) logs
- Collect Nagios XI logs
- Collect Neo4j Aura logs
- Collect Nucleus Security - Nucleus Unified Vulnerability Management logs
- Collect Nyansa Voyance / VMware Edge Network Intelligence logs
- Collect Okera Dynamic Access Platform (ODAP) audit logs
- Collect Okta Advanced Server Access logs
- Collect Onapsis Platform logs
- Collect One Identity TPAM logs
- Collect Oracle Cloud Infrastructure - Oracle Cloud Guard logs
- Collect Cisco Identity Intelligence logs
- Collect Microsoft SharePoint (Office 365) logs
- Collect NetApp Console (formerly BlueXP) audit logs
- Collect Netwrix Auditor logs
- Collect Nokia VitalQIP DDI logs
- Collect OpenAI Audit logs
- Collect OpenTelemetry Netflow Receiver logs
- Collect Oracle Fusion Cloud Applications logs
- Collect Oracle NetSuite - NetSuite Applications Suite logs
- Collect Oracle NetSuite logs
- Collect Vectra Alerts logs
- Collect Vectra XDR logs
- Collect Windows Event logs (XML format)
- Collect WinSCP logs
- Collect Workday User Activity logs
- Collect WP Engine logs
- Collect XAMS by Xiting logs
- Collect Yubico OTP logs
- Collect Zero Networks logs
- Collect Zix Email Encryption logs
- Collect Zscaler NSS Feeds for Alerts logs
- Collect ZyXEL ZyWALL logs
April 08, 2026
Emerging Threats Center general availability
The Emerging Threats Center is now in General Availability (GA) and includes the following new features and enhancements:
- Expanded campaign filtering: Filter the Emerging Threats feed by new categories, including associated malware, tools, and threat actors.
- MITRE ATT&CK matrix visualization: Evaluate your detection rule coverage for specific tactics, techniques, and procedures (TTPs) using the new visualization matrix in the Associated Rules panel. You can customize heat map metrics, filter the matrix by rule or alerting status, and view detailed context for specific sub-techniques.
- Enhanced Entity context panel: Investigate an indicator of compromise (IoC) using the Entity context panel to view its point-in-time state and related cases.
- GTI-associated IoC categories: Filter GTI-associated IoCs by specific categories, including Files, URLs, Domains, and IPs.
For more information, see Emerging Threats Center overview and Emerging Threats Center detail view.
April 07, 2026
Search query editor enhancements
Google SecOps has enhanced the search query editor to provide intelligent auto-suggestions and improved error handling.
- Auto-suggestions: The query editor now provides context-aware auto-suggestions for fields, operators, and valid values as you type.
- Error handling: The editor now highlights syntax errors with a red squiggly line and displays a tooltip with the specific error description when you hover over it. Additionally, runtime errors now display persistently in the Results panel to assist with troubleshooting.
For more information, see Use auto-suggestions to build queries.
Health Hub
This feature is currently in Preview.
The Health Hub is the central location in Google Security Operations for you to monitor the status and health of all configured data sources. The Health Hub provides crucial information on data sources and log types, offering the context needed to diagnose and remediate data pipeline issues.
The Health Hub includes information about the following:
- Ingestion volumes and ingestion health.
- Parsing volumes from raw logs to Unified Data Model (UDM) events.
- Context and links to interfaces with additional relevant information and functionality.
- Irregular and failed sources and log types.
For more information, see Use the Health Hub.
April 06, 2026
Updates to search query limits and error messaging
Google SecOps has updated search query limits for programmatic and web interface access:
- Increased Queries Per Hour (QPH) limits of up to 2,000 for APIs and 1,000 for the web interface.
- New concurrency limits for both simple and complex queries.
- More descriptive error messages for quota failures in the API and web interface.
For more information, see Search limits and quotas
v1 Cloud Storage Feed Types (GCS, S3, SQS, Azure)
The v1 feed types for GOOGLE_CLOUD_STORAGE, AMAZON_S3, AMAZON_SQS, and AZURE_BLOBSTORE are deprecated and will be discontinued on March 15, 2027. The new v2 feed types use the Google Cloud Storage Transfer Service (STS) to provide improved performance, scalability, and reliability.
To ensure continued ingestion, transition your feeds before the March 15, 2027 shutdown date:
- Google SecOps will automatically migrate your feeds using v1 feed types to v2 in waves starting from April 6, 2026. To facilitate this, some feeds may require additional IP allowlist or service account permission updates.
You can also self-migrate by creating new feeds using v2 feed types to substitute your existing feeds using v1 feed types by following the steps documented in our feed configuration guides before March 15, 2027.
Key Dates:
- April 6, 2026: Transition begins; auto-migration available.
- October 1, 2026: Support for v1 feeds is discontinued.
- March 15, 2027: v1 feeds reach End of Life (EOL) and will stop returning data.
For more information, see Feature deprecations.
April 03, 2026
Google Security Operations has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- Abnormal Security (
ABNORMAL_SECURITY) - Active Countermeasures (
AI_HUNTER) - AIX system (
AIX_SYSTEM) - Apache (
APACHE) - Apache Cassandra (
CASSANDRA) - Aruba (
ARUBA_WIRELESS) - Aruba EdgeConnect SD-WAN (
ARUBA_EDGECONNECT_SDWAN) - Auth0 (
AUTH_ZERO) - AWS Aurora (
AWS_AURORA) - AWS CloudFront (
AWS_CLOUDFRONT) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS VPC Flow (
AWS_VPC_FLOW) - AWS WAF (
AWS_WAF) - Azure AD (
AZURE_AD) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Azure Front Door (
AZURE_FRONT_DOOR) - Azure SQL (
AZURE_SQL) - BeyondTrust (
BOMGAR) - BeyondTrust BeyondInsight (
BEYONDTRUST_BEYONDINSIGHT) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Broadcom Support Portal Audit Logs (
BROADCOM_SUPPORT_PORTAL) - Check Point Harmony (
CHECKPOINT_HARMONY) - Chronicle SOAR Audit (
CHRONICLE_SOAR_AUDIT) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Cisco Umbrella DNS (
UMBRELLA_DNS) - Cisco WSA (
CISCO_WSA) - Cloud DNS (
GCP_DNS) - Cloud SQL (
GCP_CLOUDSQL) - Cloudflare (
CLOUDFLARE) - Cloudflare Warp (
CLOUDFLARE_WARP) - Code42 Incydr (
CODE42_INCYDR) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Cybereason EDR (
CYBEREASON_EDR) - CYJAX Threat Intelligence (
CYJAX_THREAT_INTELLIGENCE) - Cyware Threat Intelligence Exchange (
CTIX) - Databricks (
DATABRICKS) - Duo Auth (
DUO_AUTH) - Elastic Defend (
ELASTIC_DEFEND) - ESET AV (
ESET_AV) - F5 ASM (
F5_ASM) - F5 BIGIP Access Policy Manager (
F5_BIGIP_APM) - FireEye eMPS (
FIREEYE_EMPS) - FireEye ETP (
FIREEYE_ETP) - FireEye NX (
FIREEYE_NX) - Forescout NAC (
FORESCOUT_NAC) - ForgeRock Identity Cloud (
FORGEROCK_IDENTITY_CLOUD) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - GitHub (
GITHUB) - Google Threat Intelligence IOC (
GTI_IOC) - HP Aruba (ClearPass) (
CLEARPASS) - Huawei Switches (
HUAWEI_SWITCH) - IBM DataPower Gateway (
IBM_DATAPOWER) - IBM Safenet (
IBM_SAFENET) - IBM Websphere Application Server (
IBM_WEBSPHERE_APP_SERVER) - Imperva Advanced Bot Protection (
IMPERVA_ABP) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Juniper (
JUNIPER_FIREWALL) - Kolide Endpoint Security (
KOLIDE) - Kubernetes Audit (
KUBERNETES_AUDIT) - Kubernetes Node (
KUBERNETES_NODE) - Linux Auditing System (AuditD) (
AUDITD) - Maria Database (
MARIA_DB) - McAfee ePolicy Orchestrator (
MCAFEE_EPO) - McAfee Skyhigh CASB (
MCAFEE_SKYHIGH_CASB) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Defender For Cloud (
MICROSOFT_DEFENDER_CLOUD_ALERTS) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Microsoft SQL Server (
MICROSOFT_SQL) - Mimecast Mail V2 (
MIMECAST_MAIL_V2) - Mobile Endpoint Security (
LOOKOUT_MOBILE_ENDPOINT_SECURITY) - Mobileiron (
MOBILEIRON) - NetApp ONTAP (
NETAPP_ONTAP) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Obsidian (
OBSIDIAN) - Office 365 (
OFFICE_365) - Oort Security Tool (
OORT) - Oracle (
ORACLE_DB) - Orca Cloud Security Platform (
ORCA) - Palo Alto Cortex XDR Events (
PAN_CORTEX_XDR_EVENTS) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - PostFix Mail (
POSTFIX_MAIL) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Red Hat OpenShift (
REDHAT_OPENSHIFT) - Salesforce (
SALESFORCE) - SAP Change Document (
SAP_CHANGE_DOCUMENT) - SAP Gateway (
SAP_GATEWAY) - SAP Hana Audit (
SAP_HANA_AUDIT) - SAP Security Audit (
SAP_SECURITY_AUDIT) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Sensitive Data Risk (
GCP_SECURITYCENTER_SENSITIVE_DATA_RISK) - Security Command Center Threat (
GCP_SECURITYCENTER_THREAT) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Snyk Group level audit Logs (
SNYK_SDLC) - Suricata EVE (
SURICATA_EVE) - Symantec EDR (
SYMANTEC_EDR) - Sysdig (
SYSDIG) - Tenable Active Directory Security (
TENABLE_ADS) - ThreatConnect IOC V3 (
THREATCONNECT_IOC_V3) - Trellix HX Alerts (
TRELLIX_HX_ALERTS) - Trellix HX Audit Events (
TRELLIX_HX_AUDIT) - Trellix HX Event Streamer (
TRELLIX_HX_ES) - Trellix HX Hosts (
TRELLIX_HX_HOSTS) - Trend Micro Vision One Endpoint Vulnerabilities (
TRENDMICRO_VISION_ONE_ENDPOINT_VULNERABILITIES) - Trend Micro Vision One Observerd Attack Techniques (
TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES) - Trend Micro Vision One Workbench (
TRENDMICRO_VISION_ONE_WORKBENCH) - TrendMicro Apex Central (
TRENDMICRO_APEX_CENTRAL) - TXOne Stellar (
TRENDMICRO_STELLAR) - Ubika Waf (
UBIKA_WAF) - Unix system (
NIX_SYSTEM) - Varonis (
VARONIS) - Vmware Avinetworks iWAF (
VMWARE_AVINETWORKS_IWAF) - VMware ESXi (
VMWARE_ESX) - VMware Horizon (
VMWARE_HORIZON) - Wallix Bastion (
WALLIX_BASTION) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - wiz.io (
WIZ_IO) - Zeek JSON (
BRO_JSON) - Zscaler (
ZSCALER_WEBPROXY)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Action1 (
ACTION1) - CDNetworks Cloud Security (
CDNETWORKS_CLOUD_SECURITY) - Claude Compliance Logs (
CLAUDE_COMPLIANCE_LOGS) - Dell RecoverPoint (
DELL_RECOVERPOINT) - IBM Storwize (
IBM_STORWIZE) - LeapXpert Audit Logs (
LEAPXPERT_AUDIT) - Oracle Key Vault Audit Logs (
ORACLE_KEY_VAULT_AUDIT_LOGS) - RSA Cloud (
RSA_CLOUD) - ServiceNow Antivirus Activity (
SERVICENOW_ANTIVIRUS_ACTIVITY) - ServiceNow Attachment (
SERVICENOW_ATTACHMENT) - ServiceNow Email (
SERVICENOW_EMAIL) - Versa Director (
VERSA_DIRECTOR) - ZPE Systems NodeGrid (
ZPE_SYSTEMS_NODEGRID)
March 31, 2026
Multi-stage queries in YARA-L
The Multi-stage queries feature is now GA. This feature lets you feed the output of one query stage into the input of another, providing more granular data transformation than a single, monolithic query.
You can use multi-stage queries in both Dashboards and Search to build sophisticated detection and visualization logic. No action is required to enable this feature.
Learn more about how to create multi-stage queries with YARA-L 2.0.
March 25, 2026
Credential validation for third-party API feed types
Credential validation is now available for all 49 third-party API connectors.
When you create a feed using a third-party API feed type, Google SecOps now automatically validates the provided credentials. This ensures that if credentials are incorrect:
- Immediate feedback: The web interface displays an error message explaining the configuration failure.
- Prevention of broken feeds: The system blocks the creation of the feed until valid credentials are provided, preventing the creation of broken feeds that fail to ingest data later.
March 23, 2026
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect Cisco Umbrella Cloud Firewall logs
- Collect Cisco Umbrella IP logs
- Collect Claroty xDome for Healthcare logs
- Collect CloudM logs
- Collect Digital Guardian EDR logs
- Collect DNSFilter logs
- Collect Dope Security SWG logs
- Collect Druva Backup logs
- Collect EfficientIP DDI logs
- Collect Elastic Defend logs
- Collect Elastic Windows Event Log Beats logs
- Collect Ergon Informatik Airlock IAM logs
- Collect ESET Threat Intelligence logs
- Collect F5 Distributed Cloud Services logs
- Collect F5 Shape logs
- Collect F5 Silverline logs
- Collect Falco IDS logs
- Collect Fastly CDN logs
- Collect File Scanning Framework logs
- Collect FireEye ETP logs
- Collect FireEye HX Audit logs
- Collect FireEye NX Audit logs
- Collect Fivetran logs
- Collect Forcepoint Mail Relay logs
- Collect GitGuardian Enterprise logs
- Collect Google Cloud Looker audit logs
- Collect Guardicore Centra logs
- Collect HCL BigFix logs
- Collect HID DigitalPersona logs
- Collect IBM AS/400 logs
- Collect IBM Informix logs
- Collect IBM MaaS360 logs
- Collect IBM Mainframe Storage logs
- Collect IBM OpenPages logs
- Collect IBM Security Access Manager logs
- Collect IBM Security Identity Manager logs
- Collect iBoss Web Proxy logs
- Collect Intel 471 Watcher Alerts logs
- Collect Intel Endpoint Management Assistant logs
- Collect IONIX Attack Surface Management logs
- Collect Island Enterprise Browser logs
- Collect Jamf Protect Telemetry V2 logs
- Collect Keycloak logs
- Collect Kong Gateway logs
- Collect LenelS2 OnGuard logs
- Collect Lookout Mobile Endpoint Security logs
- Collect Lucid audit logs
- Collect ManageEngine Exchange Reporter Plus logs
- Collect Mandiant Threat Intelligence Custom IOC logs
- Collect Menlo Security Isolation Platform (MSIP) logs
- Collect Metabase logs
- Collect Microsoft Defender for Endpoint on iOS logs
- Collect Microsoft Dynamics 365 User Activity logs
- Collect Microsoft IAS / Network Policy Server (NPS) logs
- Collect Microsoft Network Policy Server (NPS) logs
- Collect OAuth2 Proxy logs
- Collect Office 365 Message Trace logs
- Collect Progress MOVEit Transfer logs
- Collect Netscout Arbor Sightline logs
- Collect Skyhigh Secure Web Gateway (On-Premises) logs
- Collect ThreatDown EDR logs
- Collect Trellix Endpoint Security (HX) alert logs
- Collect Trellix Endpoint Security (HX) audit event logs
- Collect Trellix Endpoint Security (HX) host inventory logs
March 18, 2026
Bindplane features for Google SecOps general availability
The following Bindplane features that relate to Google SecOps are now in General Availability (GA):
Single sign-on with custom claims role mapping: gives a production-ready way to manage Bindplane access through your identity provider. For more information, see Single Sign-On (Cloud).
SecOps parser validator: validates that your logs will be parsed correctly by Google SecOps directly from the snapshot view. Get immediate feedback on parsed events or validation errors without waiting for data to appear in Google SecOps. For more information, see Validate SecOps Parser.
Forwarder migration tool: provides production-ready paths to migrate existing forwarder configurations into Bindplane-managed pipelines. For more information, see Migrate Configurations.
March 12, 2026
Manage parser versions
The Manage parser versions feature is in Public Preview for all customers.
March 10, 2026
Set up and manage data processing pipelines
This feature is currently in Preview.
You can now use the Data Processing pipelines to filter, transform, and redact Google SecOps data before ingestion. This feature provides more control over ingested data, letting you reduce costs by filtering out unwanted events, transform data for better compatibility, and protect sensitive information by redacting or masking values before storage.
You can configure data processing pipelines using the Bindplane console or the Google SecOps Data Pipeline APIs.
For more information, see Set up and manage data processing pipelines.
March 05, 2026
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region. For more information, see Supported log types and default parsers.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- Acalvio (
ACALVIO) - AIX system (
AIX_SYSTEM) - Akamai WAF (
AKAMAI_WAF) - Apache (
APACHE) - Apache Cassandra (
CASSANDRA) - Apache Hadoop (
HADOOP) - Arcsight CEF (
ARCSIGHT_CEF) - Aruba EdgeConnect SD-WAN (
ARUBA_EDGECONNECT_SDWAN) - Attivo Networks (
ATTIVO) - AWS Aurora (
AWS_AURORA) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS GuardDuty (
GUARDDUTY) - AWS Network Firewall (
AWS_NETWORK_FIREWALL) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS WAF (
AWS_WAF) - Azure AD (
AZURE_AD) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Azure AD Sign-In (
AZURE_AD_SIGNIN) - Azure Firewall (
AZURE_FIREWALL) - Azure Front Door (
AZURE_FRONT_DOOR) - Barracuda Email (
BARRACUDA_EMAIL) - Barracuda Firewall (
BARRACUDA_FIREWALL) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Harmony (
CHECKPOINT_HARMONY) - Cisco Application Centric Infrastructure (
CISCO_ACI) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco ISE (
CISCO_ISE) - Cisco Router (
CISCO_ROUTER) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Switch (
CISCO_SWITCH) - Cisco TACACS+ (
CISCO_TACACS) - Cisco UCM (
CISCO_UCM) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Continuous Threat Detection (
CLAROTY_CTD) - Claroty Enterprise Management Console (
CLAROTY_EMC) - Claroty Xdome (
CLAROTY_XDOME) - Cloud SQL (
GCP_CLOUDSQL) - Cloudflare (
CLOUDFLARE) - Cloudflare Audit (
CLOUDFLARE_AUDIT) - Cloudflare WAF (
CLOUDFLARE_WAF) - Cloudflare Warp (
CLOUDFLARE_WARP) - Corelight (
CORELIGHT) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - CyberArk (
CYBERARK) - CyberArk Endpoint Privilege Manager (EPM) (
CYBERARK_EPM) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Dell EMC Data Domain (
DELL_EMC_DATA_DOMAIN) - Dell Switch (
DELL_SWITCH) - Duo Auth (
DUO_AUTH) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - F5 Distributed Cloud Services (
F5_DCS) - F5 DNS (
F5_DNS) - FireEye NX (
FIREEYE_NX) - Forcepoint NGFW (
FORCEPOINT_FIREWALL) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Google Cloud (
GCP_SECURITYCENTER_THREAT) - Google Cloud (
GCP_MONITORING_ALERTS) - Google Threat Intelligence IOC (
GTI_IOC) - GreyNoise (
GREYNOISE) - Halcyon Anti Ransomware (
HALCYON) - HP Aruba (ClearPass) (
CLEARPASS) - Huawei Switches (
HUAWEI_SWITCH) - Infoblox DNS (
INFOBLOX_DNS) - Island Browser logs (
ISLAND_BROWSER) - Kubernetes Node (
KUBERNETES_NODE) - Linux Auditing System (AuditD) (
AUDITD) - Linux Sysmon (
LINUX_SYSMON) - ManageEngine ADAudit Plus (
ADAUDIT_PLUS) - Maria Database (
MARIA_DB) - McAfee IPS (
MCAFEE_IPS) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Defender For Cloud (
MICROSOFT_DEFENDER_CLOUD_ALERTS) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Microsoft SQL Server (
MICROSOFT_SQL) - MISP Threat Intelligence (
MISP_IOC) - Mobileiron (
MOBILEIRON) - MySQL (
MYSQL) - NetApp ONTAP (
NETAPP_ONTAP) - Netskope V2 (
NETSKOPE_ALERT_V2) - NGINX (
NGINX) - Nozomi Networks Scada Guardian (
NOZOMI_GUARDIAN) - Office 365 (
OFFICE_365) - Open Cybersecurity Schema Framework (OCSF) (
OCSF) - Orca Cloud Security Platform (
ORCA) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Ping One (
PING_ONE) - PingIdentity Directory Server Logs (
PING_DIRECTORY) - PostFix Mail (
POSTFIX_MAIL) - PostgreSQL (
POSTGRESQL) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Red Hat OpenShift (
REDHAT_OPENSHIFT) - Rubrik Security Cloud (
RUBRIK_SECURITY_CLOUD) - SailPoint IdentityIQ (
SAILPOINT_IIQ) - Salesforce (
SALESFORCE) - SAP Change Document (
SAP_CHANGE_DOCUMENT) - SAP Gateway (
SAP_GATEWAY) - SAP HANA (
SAP_HANA) - SAP Hana Audit (
SAP_HANA_AUDIT) - SAP Identity and Authentication Data (
SAP_IDENTITY_AND_AUTH_DATA) - SAP Internet Communication Manager (
SAP_ICM) - SAP Security Audit (
SAP_SECURITY_AUDIT) - SAP Webdispatcher (
SAP_WEBDISP) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Sophos Central (
SOPHOS_CENTRAL) - STIX Threat Intelligence (
STIX) - Stormshield Firewall (
STORMSHIELD_FIREWALL) - Suricata EVE (
SURICATA_EVE) - Symantec Endpoint Protection (
SEP) - Sysdig (
SYSDIG) - Tableau (
TABLEAU) - Teleport Access Plane (
TELEPORT_ACCESS_PLANE) - Trend Micro (
TIPPING_POINT) - Tripwire (
TRIPWIRE_FIM) - TXOne Stellar (
TRENDMICRO_STELLAR) - Ubika Waf (
UBIKA_WAF) - Unix system (
NIX_SYSTEM) - Velo Firewall (
VELO_FIREWALL) - Veritas NetBackup (
VERITAS_NETBACKUP) - Versa Firewall (
VERSA_FIREWALL) - Vmware Avinetworks iWAF (
VMWARE_AVINETWORKS_IWAF) - VMware ESXi (
VMWARE_ESX) - VMware vCenter (
VMWARE_VCENTER) - WatchGuard (
WATCHGUARD) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - wiz.io (
WIZ_IO) - Workday Audit Logs (
WORKDAY_AUDIT) - Zscaler (
ZSCALER_WEBPROXY) - ZScaler VPN (
ZSCALER_VPN)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Alibaba Security Center (
ALIBABA_SECURITY_CENTER) - Apache Airflow (
APACHE_AIRFLOW) - Baramundi (
BARAMUNDI) - Bravura Security (
BRAVURA) - Buildkite Audit (
BUILDKITE_AUDIT) - Palo Alto Cortex Xpanse (
CORTEX_XPANSE) - Cyfirma DeCYFIR ServiceNow (
CYFIRMA_DECYFIR) - DATEV (
DATEV) - ELO (
ELO) - Forcepoint Secure Web Gateway (
FORCEPOINT_SWG) - JumpServer PAM (
JUMPSERVER_PAM) - Keep Aware (
KEEP_AWARE) - Lark Suite (
LARK_SUITE) - Macmon (
MACMON) - Mamori Database Activity Monitoring (
MAMORI_DAM) - N8N Security Audit Logs (
N8N_SECURITY_AUDIT_LOGS) - Oracle Cloud Infrastructure LoadBalancer (
OCI_LOADBALANCER) - OpenText Self Service Password Reset (
OPENTEXT_SSPR) - Rackspace (
RACKSPACE) - Secui Bluemax NGF (
SECUI_BLUEMAX_NGF) - Symantec Advanced Threat Protection (
SYMANTEC_ATP) - Tenable Vulnerabilities Management (
TENABLE_VMGNT) - Trellix EDRF Trace Data and Telemetry (
TRELLIX_EDRF) - Trend Micro Vision One Endpoint Vulnerabilities (
TRENDMICRO_VISION_ONE_ENDPOINT_VULNERABILITIES) - Zafran (
ZAFRAN)
March 02, 2026
New Unified rules interface
This feature is currently in Preview.
Google SecOps has launched a unified rules interface that brings custom and curated rule management into a single, cohesive workflow. This update optimizes detection engineering with a redesigned dashboard, an advanced rule editor, and expanded API capabilities to streamline rule deployment and troubleshooting.
Key enhancements
Developer and IDE enhancements:
Centralized management: A unified, single dashboard lets you browse, filter, and manage both custom and curated rules from one location. You can also update configurations for multiple rules simultaneously.
Curated rule transparency: You can now view the YARA-L text of curated rules, search directly within their logic, and independently toggle individual rule statuses without needing to alter the parent rule pack deployment.
Integrated IDE experience: The rule editor now features an enhanced IDE experience with inline error highlights, UDM field definitions on hover.
Expanded API and structured search:
The Rules API and dashboard have been upgraded to support deeper programmatic access and complex filtering:
Robust search syntax: Both the UI and API now support AIP-160 compliant structured search. You can filter rules by text, tags, author, and execution state.
Batch modifications: The
rules.modifyRulesmethod now supports non-atomic batch updates, letting you change live status, alerting status, tags, and archive status across multiple rules in a single API request.Advanced resource views: The
rules.listmethod introducesCONFIG_ONLYandTRENDSviews. These views provide expanded deployment information, access to curated rule resources, and larger page sizes (up to 5000 results) for efficient querying.
For details, see Manage unified rules.
February 25, 2026
Added support for Google Cloud VPC Service Controls
This feature is currently in Preview.
VPC Service Controls helps protect against accidental or targeted action by external entities or insider entities, which helps to minimize unwarranted data exfiltration risks from Google Cloud services. You can use VPC Service Controls to create perimeters that protect the resources and data of services that you explicitly specify. For more information, see Overview of VPC Service Controls.
February 24, 2026
New: cross joins in multi-stage queries
You can now use cross joins in YARA-L 2.0 multi-stage queries let you compare individual UDM event data against aggregated statistics calculated in previous YARA-L stages. They are supported in:
- Search
- Dashboards
For more information, see Cross joins in multi-stage queries.
RBAC for ingestion metrics
Administrators can now use RBAC for ingestion metrics to restrict visibility of system health data, such as ingestion volume, errors, and throughput, based on a user's business scope.
The Data Ingestion and Health dashboard now uses Data Access scopes. When a scoped user loads the dashboard, the system automatically filters metrics to show only data that matches their assigned labels: Namespace, Log Type, and Ingestion Source.
For more information, see Ingestion metrics.
February 23, 2026
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect Big Switch BigCloudFabric logs
- Collect BMC AMI Defender logs
- Collect Broadcom Support Portal Audit logs
- Collect CA ACF2 logs
- Collect CA LDAP logs
- Collect ChromeOS XDR logs
- Collect Chronicle SOAR Audit logs
- Collect Cisco CTS logs
- Collect Cisco FireSIGHT Management Center logs
- Collect Cisco Vision Dynamic Signage Director logs
- Collect ClamAV logs
- Collect Cofense logs
- Collect Crowdstrike IOC logs
- Collect Custom Application Access logs
- Collect Custom Security Data Analytics logs
- Collect Cyber 2.0 IDS logs
- Collect CyberArk logs
- Collect Cybereason EDR logs
- Collect Dataminr Alerts logs
- Collect Digital Shadows Indicators logs
- Collect Mimecast Mail V2 logs
- Collect Okta User Context logs
- Collect RH-ISAC IOC logs
- Collect ServiceNow CMDB data
February 20, 2026
New capabilities in Feeds page
The following options have been added to the Feeds page:
- Search
- Filtering (using feed attributes)
- Pagination
- Last Refreshed Time
- Feed Metadata Export to CSV
February 12, 2026
Advanced Joins in Search
Google SecOps now supports expanded capabilities for correlating data across multiple sources. These join operations are also supported in multistage queries.
Joins without a match section: You can now use join operations to correlate
and combine data from multiple sources based on common field values without
requiring a match section (unlike statistical joins). Results are displayed in a
Joins table, which you can download as a CSV, or for event-to-event joins,
exported to a datatable for further analysis.
For more information, see Implement joins without a match section.
Outer joins: Search now supports left and right outer joins. Unlike standard
inner joins, these operations let you retrieve all records from a primary
data source even if no matching entry exists in the secondary source (unmatched
fields are returned as null). This action lets you correlate data
without losing unmatched events.
For more information, see Correlate data with outer joins.
February 09, 2026
Enhanced rule observability: New metadata, visual indicators, and dashboards
Google Security Operations has introduced updates to how detection and alert data is processed and visualized. These changes help Google SecOps teams distinguish between primary rule runs and rule replays, which provides clarity on detection delays and the impact of late-arriving enrichment data.
Key improvements
- Enhanced metadata: Detection and alert objects now include specific metadata that identifies whether they were produced during a primary rule run, or as part of a rule replay or retrohunt.
- Improved troubleshooting: This data lets Google SecOps teams definitively answer critical operational questions, such as the cause of perceived detection delays or the specific impact of late-arriving enrichment data on active rules.
- Rule replay insights: Learn more about the distinction between primary runs and replays to manage the re-enrichment of Unified Data Model (UDM) events. For detailed definitions and technical workflows, see Understand rule replays and Understand rule detection delays.
- New detection dashboard: To support these backend metadata changes, a new Detection Health dashboard is now available. This interface provides a visual representation of rule performance and replay status, letting teams monitor detection health more effectively.
- Custom reporting: There are new fields available in the Detections schema, letting you build custom dashboards.
New metadata and third-party integration: Detections and alerts now emit specific metadata to help customers track timing and latency. This data is available for integration with third-party systems using the following fields:
detectionTimingDetails: An enum identifying the run type:DETECTION_TIMING_DETAILS_REPROCESSINGDETECTION_TIMING_DETAILS_RETROHUNTDETECTION_TIMING_DETAILS_UNSPECIFIEDlatencyMetrics: Includes timestamps foroldestIngestionTime,newestIngestionTime,oldestEventTime, andnewestEventTime.
Enhanced platform and visual indicators:
- Alerts and rule details: A new visual indicator in the Detection Type column provides granular details on hover.
- Filter facets: The Alerts lister page now includes detection timing details as a filterable facet.
- SOAR integration: In the Case Overview, the Composite Detections table now carries through the same iconography for a consistent investigation experience.
February 04, 2026
The re.capture_all function is now available
The new re.capture_all YARA-L 2.0 function is available in Rules, Search, and Dashboards.
Use the re.capture_all() function to extract every non-overlapping match of a regular expression from a string. While the standard re.capture function stops after the first match it finds, the re.capture_all() function continues through the entire string to identify every instance that matches your pattern.
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect ForgeRock OpenIDM logs
- Collect Forseti Open Source logs
- Collect Fortinet FortiClient logs
- Collect Fortinet FortiDDoS logs
- Collect Fortinet FortiEDR logs
- Collect Fortinet FortiManager logs
- Collect Fortinet Switch logs
- Collect Fortra Powertech SIEM Agent logs
- Collect Google App Engine logs
- Collect Google Cloud DNS Threat Detector logs
- Collect Google Cloud Monitoring alerting activity logs
- Collect Google Cloud Network Connectivity Center logs
- Collect Google Cloud Secure Web Proxy logs
- Collect Gmail logs
- Collect H3C Comware Platform Switch logs
- Collect HackerOne logs
- Collect Hillstone Firewall logs
- Collect Hitachi Content Platform logs
- Collect HYPR MFA logs
- Collect IBM Guardium logs
February 03, 2026
Share custom column sets
Google SecOps now lets you share custom sets of columns in the Events table for consistent analysis across teams.
For more details, see Search for events and alerts
Data RBAC global scope changes for ATI
To enhance data security, several features related to Indicators of Compromise (IOCs) and Emerging Threats now require global scope data RBAC permissions. Users without global scope will see restricted information in the following areas:
Emerging threats page: IOC match counts per campaign are no longer visible.
Entity widget overlay: The Indicators table is hidden or appears empty.
Threat details page: The related entities, IOC matches, and GTI IOC tables are no longer visible.
Entity summary widget: GTI scores are excluded from the overlay.
IOC details page: The Indicator Details tab doesn't populate.
API impact: API calls to IocService and ThreatCollectionService now
require global scope. Direct calls made with the CLI or client libraries fail
without this permission.
Required: Google SecOps administrators should review user roles and grant global scope to those who require continued access to these threat intelligence features.
Mute an IoC deprecated
The Mute an IoC feature is deprecated, and the IOC details page no longer displays the Mute indicator.
February 02, 2026
Google SecOps has updated the list of supported default parsers. Updates propagate gradually; changes typically appear in your region within one to four business days. For more information, see Supported log types and default parsers.
The following supported default parsers have been updated. Each parser is listed
by product name and log_type value, where applicable. This list includes both
released default parsers and pending parser updates.
- A10 Load Balancer (
A10_LOAD_BALANCER) - AIX system (
AIX_SYSTEM) - Akamai Cloud Monitor (
AKAMAI_CLOUD_MONITOR) - AlgoSec Security Management (
ALGOSEC) - Amazon API Gateway (
AWS_API_GATEWAY) - Apache (
APACHE) - Apple macOS (
MACOS) - AppOmni (
APPOMNI) - Arcsight CEF (
ARCSIGHT_CEF) - Arista Switch (
ARISTA_SWITCH) - Aruba (
ARUBA_WIRELESS) - Aruba Airwave (
ARUBA_AIRWAVE) - Aruba EdgeConnect SD-WAN (
ARUBA_EDGECONNECT_SDWAN) - Aruba Switch (
ARUBA_SWITCH) - Attivo Networks (
ATTIVO) - Auth0 (
AUTH_ZERO) - Automation Anywhere (
AUTOMATION_ANYWHERE) - Avanan Email Security (
AVANAN_EMAIL) - AWS Aurora (
AWS_AURORA) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS Elastic Load Balancer (
AWS_ELB) - AWS GuardDuty (
GUARDDUTY) - AWS RDS (
AWS_RDS) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS WAF (
AWS_WAF) - Azure AD (
AZURE_AD) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Azure AD Sign-In (
AZURE_AD_SIGNIN) - Azure Front Door (
AZURE_FRONT_DOOR) - Barracuda Email (
BARRACUDA_EMAIL) - Barracuda WAF (
BARRACUDA_WAF) - BeyondTrust (
BOMGAR) - BeyondTrust BeyondInsight (
BEYONDTRUST_BEYONDINSIGHT) - BeyondTrust Endpoint Privilege Management (
BEYONDTRUST_ENDPOINT) - BeyondTrust Secure Remote Access (
BEYONDTRUST_REMOTE_ACCESS) - BIND (
BIND_DNS) - Bindplane Agent (
BINDPLANE_AGENT) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Box (
BOX) - Carbon Black (
CB_EDR) - Cato Networks (
CATO_NETWORKS) - Check Point (
CHECKPOINT_FIREWALL) - CipherTrust Manager (
CIPHERTRUST_MANAGER) - Cisco Application Centric Infrastructure (
CISCO_ACI) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco PIX Firewall (
CISCO_PIX_FIREWALL) - Cisco Router (
CISCO_ROUTER) - Cisco Stealthwatch (
CISCO_STEALTHWATCH) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Cisco Umbrella DNS (
UMBRELLA_DNS) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco WLC/WCS (
CISCO_WIRELESS) - Cisco WSA (
CISCO_WSA) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Continuous Threat Detection (
CLAROTY_CTD) - Claroty Xdome (
CLAROTY_XDOME) - Cloud SQL (
GCP_CLOUDSQL) - Cloudflare (
CLOUDFLARE) - Cloudflare Audit (
CLOUDFLARE_AUDIT) - Compute Engine (
GCP_COMPUTE) - Corelight (
CORELIGHT) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - CyberArk (
CYBERARK) - CyberArk Endpoint Privilege Manager (EPM) (
CYBERARK_EPM) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Cyolo Secure Remote Access for OT (
CYOLO_OT) - Darktrace (
DARKTRACE) - Delinea Secret Server (
DELINEA_SECRET_SERVER) - Dell ECS Enterprise Object Storage (
DELL_ECS) - Dell Switch (
DELL_SWITCH) - Duo Auth (
DUO_AUTH) - ExtraHop RevealX (
EXTRAHOP) - Extreme Wireless (
EXTREME_WIRELESS) - F5 Advanced Firewall Management (
F5_AFM) - F5 ASM (
F5_ASM) - F5 BIGIP Access Policy Manager (
F5_BIGIP_APM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - F5 Distributed Cloud Services (
F5_DCS) - Fastly CDN (
FASTLY_CDN) - FireEye ETP (
FIREEYE_ETP) - FireEye NX (
FIREEYE_NX) - Forcepoint Email Security (
FORCEPOINT_EMAILSECURITY) - Forescout eyeInspect (
FORESCOUT_EYEINSPECT) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet Fortimanager (
FORTINET_FORTIMANAGER) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GCP_APP_ENGINE (
GCP_APP_ENGINE) - GCP_MODEL_ARMOR (
GCP_MODEL_ARMOR) - GitHub (
GITHUB) - GitHub Dependabot (
GITHUB_DEPENDABOT) - Google Cloud Audit (
GCP_CLOUDAUDIT) - Google Threat Intelligence (
GCP_THREATINTEL) - H3C Comware Platform Switch (
H3C_SWITCH) - Hashicorp Vault (
HASHICORP) - HP Aruba (ClearPass) (
CLEARPASS) - Huawei Switches (
HUAWEI_SWITCH) - IBM DataPower Gateway (
IBM_DATAPOWER) - IBM DB2 (
DB2_DB) - Illumio Core (
ILLUMIO_CORE) - Imperva (
IMPERVA_WAF) - Imperva DRA (
IMPERVA_DRA) - Island Browser logs (
ISLAND_BROWSER) - Jamf pro context (
JAMF_PRO_CONTEXT) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS) - Juniper MX Router (
JUNIPER_MX) - Keycloak (
KEYCLOAK) - KnowBe4 PhishER (
KNOWBE4_PHISHER) - Kolide Endpoint Security (
KOLIDE) - Kubernetes Node (
KUBERNETES_NODE) - Linux Auditing System (AuditD) (
AUDITD) - McAfee DLP (
MCAFEE_DLP) - McAfee ePolicy Orchestrator (
MCAFEE_EPO) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Microsoft AD FS (
ADFS) - Microsoft Defender For Cloud (
MICROSOFT_DEFENDER_CLOUD_ALERTS) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Microsoft Intune (
AZURE_MDM_INTUNE) - Microsoft PowerShell (
POWERSHELL) - Microsoft SQL Server (
MICROSOFT_SQL) - Mimecast Mail V2 (
MIMECAST_MAIL_V2) - MISP Threat Intelligence (
MISP_IOC) - Mobileiron (
MOBILEIRON) - MySQL (
MYSQL) - NetApp ONTAP (
NETAPP_ONTAP) - Netfilter IPtables (
NETFILTER_IPTABLES) - NetIQ Access Manager (
NETIQ_ACCESS_MANAGER) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Network Policy Server (
MICROSOFT_NPS) - NGINX (
NGINX) - Nozomi Networks Scada Guardian (
NOZOMI_GUARDIAN) - Nutanix Prism (
NUTANIX_PRISM) - Obsidian (
OBSIDIAN) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Onapsis (
ONAPSIS) - One Identity TPAM (
ONEIDENTITY_TPAM) - OneLogin (
ONELOGIN_SSO) - Open Cybersecurity Schema Framework (OCSF) (
OCSF) - Oracle (
ORACLE_DB) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Ping Identity (
PING) - PostFix Mail (
POSTFIX_MAIL) - PostgreSQL (
POSTGRESQL) - Proofpoint CASB (
PROOFPOINT_CASB) - Proofpoint Email Filter (
PROOFPOINT_MAIL_FILTER) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Pulse Secure (
PULSE_SECURE_VPN) - QNAP Systems NAS (
QNAP_NAS) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Recorded Future (
RECORDED_FUTURE_IOC) - Red Hat OpenShift (
REDHAT_OPENSHIFT) - Salesforce (
SALESFORCE) - SAP Sybase Adaptive Server Enterprise Database (
SAP_ASE) - Security Command Center Chokepoint (
GCP_SECURITYCENTER_CHOKEPOINT) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
GCP_SECURITYCENTER_THREAT) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - ServiceNow Audit (
SERVICENOW_AUDIT) - Snare System Diagnostic Logs (
SNARE_SOLUTIONS) - Snyk Group level audit/issues logs (
SNYK_ISSUES) - Solaris system (
SOLARIS_SYSTEM) - Sophos Central (
SOPHOS_CENTRAL) - STIX Threat Intelligence (
STIX) - Stormshield Firewall (
STORMSHIELD_FIREWALL) - Sublime Security (
SUBLIMESECURITY) - Suricata EVE (
SURICATA_EVE) - Swift Alliance Messaging Hub (
SWIFT_AMH) - Symantec DLP (
SYMANTEC_DLP) - Symantec Endpoint Protection (
SEP) - Symantec Messaging Gateway (
SYMANTEC_MAIL) - Tableau (
TABLEAU) - TCPWave DDI (
TCPWAVE_DDI) - TeamViewer (
TEAMVIEWER) - Tenable Active Directory Security (
TENABLE_ADS) - Tenable OT (
TENABLE_OT) - Tenable.io (
TENABLE_IO) - Thinkst Canary (
THINKST_CANARY) - ThreatConnect IOC V3 (
THREATCONNECT_IOC_V3) - Trellix HX Event Streamer (
TRELLIX_HX_ES) - Trend Micro (
TIPPING_POINT) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - Trend Micro Vision One Workbench (
TRENDMICRO_VISION_ONE_WORKBENCH) - TrendMicro Deep Discovery Inspector (
TRENDMICRO_DDI) - TXOne Stellar (
TRENDMICRO_STELLAR) - Unifi AP (
UNIFI_AP) - Unix system (
NIX_SYSTEM) - Vectra Detect (
VECTRA_DETECT) - Vectra XDR (
VECTRA_XDR) - Veritas NetBackup (
VERITAS_NETBACKUP) - Versa Firewall (
VERSA_FIREWALL) - VMware ESXi (
VMWARE_ESX) - VMware NSX (
VMWARE_NSX) - VMware vCenter (
VMWARE_VCENTER) - WatchGuard (
WATCHGUARD) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Wiz.io (
WIZ_IO) - Workday Audit Logs (
WORKDAY_AUDIT) - Workspace Activities (
WORKSPACE_ACTIVITY) - Workspace Alerts (
WORKSPACE_ALERTS) - Zimperium (
ZIMPERIUM) - Zscaler (
ZSCALER_WEBPROXY) - Zscaler CASB (
ZSCALER_CASB) - Zscaler DLP (
ZSCALER_DLP) - ZScaler DNS (
ZSCALER_DNS) - Zscaler Internet Access Audit Logs (
ZSCALER_INTERNET_ACCESS) - ZScaler NGFW (
ZSCALER_FIREWALL) - Zscaler Private Access (
ZSCALER_ZPA) - Zscaler Secure Private Access Audit Logs (
ZSCALER_ZPA_AUDIT) - Zscaler Tunnel (
ZSCALER_TUNNEL) - Zywall (
ZYWALL)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Aikido (
AIKIDO) - Akamai API Security (
AKAMAI_API_SECURITY) - Alkira IP Flow (
ALKIRA_IP_FLOW) - Atlassian Guard Detect (
ATLASSIAN_GUARD_DETECT) - BlinkOps (
BLINKOPS) - Canvas LMS (
CANVAS_LMS) - Cisco Secure Email Threat Defense (
CISCO_SECURE_EMAIL_THREAT_DEFENSE) - Cisco StarOS (
CISCO_STAR_OS) - Citadel Identity360 (
CITADEL_IDENTITY360) - Cyware Threat Intelligence Exchange (
CTIX) - Cyberark Identity Audit (
CYBERARK_IDENTITY_AUDIT) - CyCognito ASM (
CYCOGNITO_ASM) - Dell VxRail (
DELL_VXRAIL) - Gene6 FTP Server (
GENE6_FTP) - IBM Copy Services Manager (
IBM_CSM) - LangSmith Audit (
LANGSMITH_AUDIT) - Mellanox Switch (
MELLANOX_SWITCH) - Microsoft Entra ID Protection (
MICROSOFT_ENTRA_ID_PROTECTION) - NSFOCUS Next Generation Intrusion Prevention System (
NSFOCUS_NGIPS) - Perplexity (
PERPLEXITY) - Pleasant Password Server (
PLEASANT_PASSWORD_SERVER) - Prompt Security (
PROMPT_SECURITY) - Qualtrics Audit (
QUALTRICS_AUDIT) - Rancher API Audit Log (
RANCHER_API_AUDIT_LOG) - Rubrik Security Cloud (
RUBRIK_SECURITY_CLOUD) - SAP Business Warehouse (
SAP_BW) - SAP Change Document (
SAP_CHANGE_DOCUMENT) - SAP Gateway (
SAP_GATEWAY) - SAP Hana Audit (
SAP_HANA_AUDIT) - Scale Computing (
SCALE_COMPUTING) - Slack API (
SLACK_API) - Snowplow (
SNOWPLOW) - Sterling Order Management System Data (
STERLING_OMS_DATA) - Strivacity (
STRIVACITY) - Tencent CloudAudit (
TENCENT_CLOUD_AUDIT) - Trellix EX (
TRELLIX_EX) - Unifi System (
UNIFI_SYSTEM) - Windows Bindplane (
WINDOWS_BINDPLANE) - Witness AI Control (
WITNESS_AI_CONTROL) - Zendesk Advanced Data Privacy and Protection (
ZENDESK_ADPP)
January 30, 2026
The following v2 feed types, which utilize Google Storage Transfer Service (STS), are now in General Availability:
- Google Cloud Storage v2
- Amazon S3 v2
- Google Cloud Storage (Event Driven)
- Amazon SQS v2
- Azure Blobstore v2
January 29, 2026
Enhanced rule observability for detections
Google SecOps now provides increased visibility into detection timing to help
improve dashboard and reporting accuracy. You can now easily distinguish whether
a detection was generated during a primary rule run or through a
rule replay. This data is available
in dashboards and as a filter in the Alerts lister page using the field
collection.detection_timing_details.
January 21, 2026
Direct ingestion for Google Cloud Model Armor logs
You can now ingest Google Cloud Model Armor logs (GCP_MODEL_ARMOR) directly into Google
SecOps. Use an export filter for direct ingestion and access the logs through
Google Cloud logging. Model Armor logs provide a unified window into AI-specific
threats, such as prompt injection and sensitive data leakage.
For more information, see Model Armor Documentation to Configure Logging.
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect Active Countermeasures AI-Hunter logs
- Collect ADVA Fiber Service Platform logs
- Collect AIX system logs
- Collect Akamai SIEM Connector logs
- Collect AMD Pensando DSS firewall logs
- Collect Azure NSG Flow logs
- Collect Cloudflare Page Shield logs
- Collect FingerprintJS logs
- Collect FireEye eMPS logs
- Collect Forcepoint Email Security logs
- Collect Forcepoint NGFW logs
- Collect Fortinet FortiSASE logs
- Collect IBM DB2 logs
- Collect ManageEngine ADManager Plus logs
- Collect Microsoft Azure Resource logs
- Collect Microsoft Intune Context logs
- Collect Ubiquiti Unifi switch logs
- Collect Vectra Detect logs
- Collect Vectra Stream logs
- Collect Voltage SecureMail logs
- Collect Wallix Bastion logs
January 16, 2026
Perform all-time searches
You can now run searches over your full retention period by clicking the Time Picker on the Search editor panel and selecting All Time. This functionality is supported for event searches, and results remain limited to a maximum of 1M events.
For more information, see Search for events and alerts.
January 13, 2026
Auto extraction general availability
As part of the GA release for the auto extraction feature, customers now need to opt-in and choose which fields to extract. (Full auto extraction is no longer supported.) The opt-in functionality does not impact the extracted fields that are already in use (in saved searches and rules), because those fields have been automatically opted-in as part of the GA migration.
For more information, see Auto Extraction overview.
Self-service deprovisioning general availability
The self-service deprovisioning feature is now GA.
For more information, see Self-service deprovisioning for Google SecOps.
January 07, 2026
Expanded capabilities for Gemini in SecOps
You can now use the Gemini assistant in Google SecOps to answer questions beyond the scope of security or the product. You can integrate the full power of Gemini (for example, general knowledge, coding, and data analysis) without switching tabs or leaving your workflow.
For more information, see Gemini in Google SecOps.
December 24, 2025
ThreatConnect IOC V3 Connector
Google SecOps now supports the ingestion of Indicators of Compromise (IOCs) from ThreatConnect using the v3 REST API. This updated connector replaces the existing v2-based integration and introduces several enhancements:
- Advanced Filtering with TQL: Use ThreatConnect Query Language (TQL) to perform highly targeted searches based on complex criteria like confidence scores, tags, or specific timeframes.
- Efficient Single-Call Data Ingestion: Ingest complete indicator objects—including attributes, tags, and security labels—in a single API call to reduce overhead and improve performance.
- Synchronization Gaps: Changes in ThreatConnect (for example, ThreatAssessmentScore, confidence, tags) are now replicated into the platform every 30 minutes.
Data ingested through this connector is identified by the new log type THREATCONNECT_IOC_V3.
For more information, see Collect ThreatConnect IOC logs using the v3 API.
Understand your Google SecOps billing components
A new document is available that helps you understand your Google Security Operations billing components. The document provides information about how to track your usage and the related cost. For more information, see Understand your Google SecOps billing.
December 18, 2025
Understand how to view your billed ingestion volume
A new document is available that helps you understand your billed ingestion volume. The document provides instructions on how to view and monitor the ingestion volume for the various tenants that you manage. For more information, see View your billed ingestion volume.
December 10, 2025
Learn key differences between SPL and YARA-L 2.0
A new guide is available to explain the key differences between Splunk Search Processing Language (SPL) and Google Security Operations YARA-L 2.0. The guide provides examples for converting common SPL queries and aims to accelerate the onboarding process for security professionals who transition to YARA-L 2.0. For more information, see Transition from SPL to YARA-L.
December 08, 2025
N OF and OR syntax updates
You can now use the N OF syntax and the or operator to write flexible and
conditional logic within the condition section of your query. These features
let you combine multiple conditions, reducing the overall complexity of your
query syntax.
For more information, see Use or in the condition section and Use N OF syntax with event variables.
December 03, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- 1Password (
ONEPASSWORD) - A10 Load Balancer (
A10_LOAD_BALANCER) - Abnormal Security (
ABNORMAL_SECURITY) - AIX system (
AIX_SYSTEM) - Akamai SIEM Connector (
AKAMAI_SIEM_CONNECTOR) - AlgoSec Security Management (
ALGOSEC) - Amazon API Gateway (
AWS_API_GATEWAY) - Amazon VPC Transit Gateway Flow Logs (
AWS_VPC_TRANSIT_GATEWAY) - Apache (
APACHE) - Arcsight CEF (
ARCSIGHT_CEF) - Arista Switch (
ARISTA_SWITCH) - Armis Activities (
ARMIS_ACTIVITIES) - Aruba (
ARUBA_WIRELESS) - Aruba Switch (
ARUBA_SWITCH) - Attivo Networks (
ATTIVO) - Auth0 (
AUTH_ZERO) - AWS Aurora (
AWS_AURORA) - AWS CloudFront (
AWS_CLOUDFRONT) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS Config (
AWS_CONFIG) - AWS GuardDuty (
GUARDDUTY) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS Session Manager (
AWS_SESSION_MANAGER) - AWS VPC Flow (
AWS_VPC_FLOW) - Azure AD (
AZURE_AD) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Firewall (
AZURE_FIREWALL) - Azure Storage Audit (
AZURE_STORAGE_AUDIT) - Barracuda Firewall (
BARRACUDA_FIREWALL) - BeyondTrust (
BOMGAR) - BeyondTrust BeyondInsight (
BEYONDTRUST_BEYONDINSIGHT) - BeyondTrust Secure Remote Access (
BEYONDTRUST_REMOTE_ACCESS) - Bindplane Agent (
BINDPLANE_AGENT) - Bitdefender (
BITDEFENDER) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Cambium Networks (
CAMBIUM_NETWORKS) - Carbon Black (
CB_EDR) - Carbon Black App Control (
CB_APP_CONTROL) - Cequence Bot Defense (
CEQUENCE_BOT_DEFENSE) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Sandblast (
CHECKPOINT_EDR) - Chrome Management (
CHROME_MANAGEMENT) - CipherTrust Manager (
CIPHERTRUST_MANAGER) - Cisco AMP (
CISCO_AMP) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Firewall Services Module (
CISCO_FWSM) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco Router (
CISCO_ROUTER) - Cisco Secure Access (
CISCO_SECURE_ACCESS) - Cisco Stealthwatch (
CISCO_STEALTHWATCH) - Cisco Switch (
CISCO_SWITCH) - Cisco UCM (
CISCO_UCM) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Cisco Umbrella Cloud Firewall (
UMBRELLA_FIREWALL) - Cisco Umbrella DNS (
UMBRELLA_DNS) - Cisco Umbrella IP (
UMBRELLA_IP) - Cisco Umbrella SWG DLP (
CISCO_UMBRELLA_SWG_DLP) - Cisco Umbrella Web Proxy (
UMBRELLA_WEBPROXY) - Cisco WSA (
CISCO_WSA) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Continuous Threat Detection (
CLAROTY_CTD) - Claroty Xdome (
CLAROTY_XDOME) - Cloudflare (
CLOUDFLARE) - Cloudflare Network Analytics (
CLOUDFLARE_NETWORK_ANALYTICS) - Cloudflare WAF (
CLOUDFLARE_WAF) - Cloudflare Warp (
CLOUDFLARE_WARP) - Code42 Incydr (
CODE42_INCYDR) - Corelight (
CORELIGHT) - CoSoSys Protector (
ENDPOINT_PROTECTOR_DLP) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - Cyber 2.0 IDS (
CYBER_2_IDS) - CyberArk Endpoint Privilege Manager (EPM) (
CYBERARK_EPM) - Cyberark Privilege Cloud (
CYBERARK_PRIVILEGE_CLOUD) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Cybereason EDR (
CYBEREASON_EDR) - Cynet 360 AutoXDR (
CYNET_360_AUTOXDR) - Cyolo Secure Remote Access for OT (
CYOLO_OT) - Darktrace (
DARKTRACE) - Delinea Secret Server (
DELINEA_SECRET_SERVER) - Digital Guardian DLP (
DIGITALGUARDIAN_DLP) - Digital Guardian EDR (
DIGITALGUARDIAN_EDR) - DigitalArts i-Filter (
DIGITALARTS_IFILTER) - Dummy LogType (
DUMMY_LOGTYPE) - EfficientIP DDI (
EFFICIENTIP_DDI) - ESET AV (
ESET_AV) - ESET Threat Intelligence (
ESET_IOC) - Extreme Networks Switch (
EXTREME_SWITCH) - F5 Advanced Firewall Management (
F5_AFM) - F5 ASM (
F5_ASM) - F5 BIGIP Access Policy Manager (
F5_BIGIP_APM) - F5 Silverline (
F5_SILVERLINE) - FireEye ETP (
FIREEYE_ETP) - Fluentd Logs (
FLUENTD) - Forcepoint NGFW (
FORCEPOINT_FIREWALL) - Forcepoint DLP (
FORCEPOINT_DLP) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - Forescout NAC (
FORESCOUT_NAC) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet FortiEDR (
FORTINET_FORTIEDR) - GCP Abuse Events Logs (
GCP_ABUSE_EVENTS) - GitHub (
GITHUB) - GMV Checker ATM Security (
GMV_CHECKER) - Google Cloud Apigee (
GCP_APIGEE) - Google Cloud Audit (
GCP_CLOUDAUDIT) - Google Cloud Security Center Threat (
GCP_SECURITYCENTER_THREAT) - Google Threat Intelligence IOC (
GTI_IOC) - GTB Technologies DLP (
GTB_DLP) - H3C Comware Platform Switch (
H3C_SWITCH) - Halcyon Anti Ransomware (
HALCYON) - HP Aruba (ClearPass) (
CLEARPASS) - HP Linux (
HP_LINUX) - HP Procurve Switch (
HP_PROCURVE) - IBM AS/400 (
IBM_AS400) - IBM Security Verify Access (
IBM_SVA) - IBM WebSEAL (
IBM_WEBSEAL) - IBM Websphere Application Server (
IBM_WEBSPHERE_APP_SERVER) - IBM z/OS (
IBM_ZOS) - Imperva (
IMPERVA_WAF) - Imperva DRA (
IMPERVA_DRA) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox (
INFOBLOX) - Infoblox DHCP (
INFOBLOX_DHCP) - Infoblox DNS (
INFOBLOX_DNS) - ION Spectrum (
ION_SPECTRUM) - Ionix (
IONIX) - Ipswitch MOVEit Transfer (
IPSWITCH_MOVEIT_TRANSFER) - Island Browser logs (
ISLAND_BROWSER) - JAMF Pro (
JAMF_PRO) - Jamf Protect Telemetry V2 (
JAMF_TELEMETRY_V2) - JFrog Artifactory (
JFROG_ARTIFACTORY) - Journald (
JOURNALD) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS) - Juniper (
JUNIPER_FIREWALL) - Juniper Junos (
JUNIPER_JUNOS) - Kaspersky AV (
KASPERSKY_AV) - Kaspersky Endpoint (
KASPERSKY_ENDPOINT) - Keycloak (
KEYCLOAK) - Kiteworks (
KITEWORKS) - Kubernetes Node (
KUBERNETES_NODE) - Linux Auditing System (AuditD) (
AUDITD) - Linux Sysmon (
LINUX_SYSMON) - McAfee ePolicy Orchestrator (
MCAFEE_EPO) - Microsoft AD FS (
ADFS) - Microsoft Azure NSG Flow (
AZURE_NSG_FLOW) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft Exchange (
EXCHANGE_MAIL) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Microsoft Intune (
AZURE_MDM_INTUNE) - Microsoft PowerShell (
POWERSHELL) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft SQL Server (
MICROSOFT_SQL) - Mikrotik Router (
MIKROTIK_ROUTER) - Mimecast Mail V2 (
MIMECAST_MAIL_V2) - MISP Threat Intelligence (
MISP_IOC) - Mobileiron (
MOBILEIRON) - NetApp ONTAP (
NETAPP_ONTAP) - Netscout (
ARBOR_EDGE_DEFENSE) - Netskope CASB (
NETSKOPE_CASB) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Nexus Sonatype (
NEXUS_SONATYPE) - Nozomi Networks Scada Guardian (
NOZOMI_GUARDIAN) - Obsidian (
OBSIDIAN) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Open Cybersecurity Schema Framework (OCSF) (
OCSF) - Open LDAP (
OPENLDAP) - Opnsense (
OPNSENSE) - Opswat Metadefender (
OPSWAT_METADEFENDER) - Oracle (
ORACLE_DB) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT) - Oracle Cloud Infrastructure VCN Flow Logs (
OCI_FLOW) - Orca Cloud Security Platform (
ORCA) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - Palo Alto Cortex XDR Events (
PAN_CORTEX_XDR_EVENTS) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Passwordstate (
PASSWORDSTATE) - Ping Federate (
PING_FEDERATE) - Ping Identity (
PING) - Ping One (
PING_ONE) - PingIdentity Directory Server Logs (
PING_DIRECTORY) - PostFix Mail (
POSTFIX_MAIL) - PostgreSQL (
POSTGRESQL) - Proofpoint Observeit (
OBSERVEIT) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Radware Web Application Firewall (
RADWARE_FIREWALL) - RSA (
RSA_AUTH_MANAGER) - Ruckus Networks (
RUCKUS_WIRELESS) - SailPoint IAM (
SAILPOINT_IAM) - Salesforce (
SALESFORCE) - Sangfor Next Generation Firewall (
SANGFOR_NGAF) - Security Command Center Chokepoint (
GCP_SECURITYCENTER_CHOKEPOINT) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Semperis DSP (
SEMPERIS_DSP) - Sentinelone Activity (
SENTINELONE_ACTIVITY) - SentinelOne Deep Visibility (
SENTINEL_DV) - ServiceNow Audit (
SERVICENOW_AUDIT) - Solaris system (
SOLARIS_SYSTEM) - SonicWall (
SONIC_FIREWALL) - Squid Web Proxy (
SQUID_WEBPROXY) - STIX Threat Intelligence (
STIX) - Swift Alliance Messaging Hub (
SWIFT_AMH) - Symantec Endpoint Protection (
SEP) - Tanium Audit (
TANIUM_AUDIT) - Tanium Integrity Monitor (
TANIUM_INTEGRITY_MONITOR) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Teleport Access Plane (
TELEPORT_ACCESS_PLANE) - Tenable Active Directory Security (
TENABLE_ADS) - Tenable OT (
TENABLE_OT) - tenable.io (
TENABLE_IO) - Thales Luna Hardware Security Module (
THALES_LUNA_HSM) - Thales MFA (
THALES_MFA) - Trellix HX Event Streamer (
TRELLIX_HX_ES) - Trend Micro (
TIPPING_POINT) - Trend Micro Apex one (
TRENDMICRO_APEX_ONE) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - Trend Micro Vision One Audit (
TRENDMICRO_VISION_ONE_AUDIT) - Trend Micro Vision One Detections (
TRENDMICRO_VISION_ONE_DETECTIONS) - Trend Micro Vision One Observerd Attack Techniques (
TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES) - TXOne Stellar (
TRENDMICRO_STELLAR) - Ubika Waf (
UBIKA_WAF) - Unix system (
NIX_SYSTEM) - Upstream Vehicle SOC Alerts (
UPSTREAM_VSOC_ALERTS) - Varonis (
VARONIS) - Vectra Stream (
VECTRA_STREAM) - Venafi ZTPKI (
VENAFI_ZTPKI) - Veritas NetBackup (
VERITAS_NETBACKUP) - Versa Firewall (
VERSA_FIREWALL) - Vmware Avinetworks iWAF (
VMWARE_AVINETWORKS_IWAF) - VMware ESXi (
VMWARE_ESX) - VMware NSX (
VMWARE_NSX) - VMware vCenter (
VMWARE_VCENTER) - WatchGuard (
WATCHGUARD) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Windows Sysmon (
WINDOWS_SYSMON) - wiz.io (
WIZ_IO) - Workday User Activity (
WORKDAY_USER_ACTIVITY) - Workspace Activities (
WORKSPACE_ACTIVITY) - Workspace Alerts (
WORKSPACE_ALERTS) - Workspace Users (
WORKSPACE_USERS) - Zendesk CRM (
ZENDESK_CRM) - Zoom Operation Logs (
ZOOM_OPERATION_LOGS) - Zscaler (
ZSCALER_WEBPROXY) - ZScaler NGFW (
ZSCALER_FIREWALL) - Zscaler Private Access (
ZSCALER_ZPA) - Zscaler Secure Private Access Audit Logs (
ZSCALER_ZPA_AUDIT)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Absolute Secure Endpoint (
ABSOLUTE_SECURE_ENDPOINT) - Airbus Security Logging (ACD AISD) (
AIRBUS_SECURITY_LOG) - Azure Recovery Services Vaults (
AZURE_RECOVERY_SERVICES_VAULTS) - Boeing Onboard Network System Logging (
BOEING_ONS) - Cisco Firepower Threat Defense (
CISCO_FIREPOWER_THREAT_DEFENSE) - Cisco Security Cloud Control (
CISCO_SECURITY_CLOUD_CONTROL) - Pico Corvilnet Engine (
CORVILNET_ENGINE) - CrowdStrike Falcon Shield (
CROWDSTRIKE_FALCON_SHIELD) - Easy NAC (
EASY_NAC) - FairXchange Horizon (
FAIRXCHANGE_HORIZON) - Google Threat Intelligence (
GCP_THREATINTEL) - HPE Alletra (
HPE_ALLETRA) - Huawei Cloud Trace Service Audit (
HUAWEI_CTS_AUDIT) - Huawei SecMaster (
HUAWEI_SECMASTER) - IBM ILO (
IBM_ILO) - Infisical (
INFISICAL) - JSCAPE SFTP (
JSCAPE_SFTP) - Juniper Edge (
JUNIPER_EDGE) - Kaspersky for Microsoft Office 365 (
KASPERSKY_O365_EVENTS) - Microsoft Defender for Cloud Apps (
MICROSOFT_DEFENDER_CLOUD_APPS) - Oracle Cloud Infrastructure Network Firewall (
OCI_FIREWALL) - Okta Workflows (
OKTA_WORKFLOWS) - Phosphorus (
PHOSPHORUS) - Rapid7 Cloud Security (
RAPID7_CLOUDSEC) - Research and Education Networks Information Sharing and Analysis Center (
REN_ISAC) - Risk Resecurity (
RISK_RESECURITY) - Sangfor Network Detection and Response (
SANGFOR_NDR) - SAP Enterprise Threat Detection (
SAP_ETD) - SAP IAS Context (
SAP_IAS_CONTEXT) - Sectigo SCM (
SECTIGO_SCM) - ServiceNow Node (
SERVICENOW_NODE) - ServiceNow Outbound HTTP (
SERVICENOW_OUTBOUNDHTTP) - ServiceNow System log (
SERVICENOW_SYSLOG) - ServiceNow Transaction (
SERVICENOW_TRANSACTION) - Seti S4 (
SETI_S4) - ThousandEyes (
THOUSAND_EYES) - Transmit Security Mosaic CIAM (
TRANSMIT_MOSAIC_CIAM) - Transmit Security Mosaic Fraud Prevention (
TRANSMIT_MOSAIC_FRAUD_PREVENTION) - Transmit Security Mosaic Identity Verification (
TRANSMIT_MOSAIC_IDENTITY_VERIFICATION) - Transmit Security Mosaic Management (
TRANSMIT_MOSAIC_MANAGEMENT) - Tripwire Security Configuration Management (
TRIPWIRE_SCM) - Valimail (
VALIMAIL) - WSO2 IS AM (
WSO2_IS_AM) - XDR.Net Digital Twin (
XDRNET_DIGITALTWIN) - Zimbra Mail (
ZIMBRA_MAIL) - Zscaler Email DLP (
ZSCALER_EMAIL_DLP)
November 13, 2025
Raw log search enhancements
Google SecOps now includes enhancements to raw log search to boost usability, performance, and data analysis:
New filtering options: Filter raw log results by their parsing status or by one or more log sources.
Optimized results view: Expand or collapse the Trend over time graph, providing more space for results.
Download raw log results: Download raw log results to a CSV file. By default, the Timestamp, Event Type, and Raw log columns are included. You can select additional columns through Column Manager.
Enhanced search visibility: The search query and applied filters are now displayed on the Search page.
New API for raw log search: Use the legacySearchRawLogsV2 API to search for raw logs within a specified Google SecOps instance.
For more details, see the following topics:
November 12, 2025
Use the Triage Agent to investigate alerts
You can now use Triage Agent, an AI-powered investigation assistant, to analyze alerts in Google SecOps. Triage Agent determines if an alert is a true or false positive, provides a summarized explanation for its conclusion, and suggests next steps for further investigation.
You can trigger investigations manually or have them run automatically on supported alert types. Each investigation produces a detailed report that includes the agent's disposition, a summary of its findings, and a timeline of the analysis.
For more details, see Use Triage Agent to investigate alerts.
Enhance threat visibility and detection with Emerging Threats
The new Emerging Threats page provides AI-powered threat intelligence to help you understand how current threat campaigns might affect your organization. Powered by Google Threat Intelligence (GTI) and Gemini models, this page offers a curated view of critical global threats relevant to your environment.
Emerging Threats continuously aligns intelligence from GTI with your organization's telemetry to highlight detection coverage and identify gaps. When it finds a gap, it uses Gemini to automatically draft new detection rules to accelerate your response.
For more details, see Emerging Threats overview, Emerging Threats feed,and Emerging Threats detailed view.
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect Absolute Secure Endpoint logs
- Collect AIDE (Advanced Intrusion Detection Environment) logs
- Collect Akamai Enterprise Application Access logs
- Collect Apache Hadoop logs
- Collect Armis Vulnerabilities logs
- Collect Array Networks SSL VPN logs
- Collect Aruba IPS logs
- Collect Atlassian Confluence logs
- Collect Cisco AMP for Endpoints logs
- Collect Cisco APIC logs
- Collect Cisco Application Centric Infrastructure (ACI) logs
- Collect Cisco CallManager logs
- Collect Cisco CloudLock CASB logs
- Collect Cisco DNA Center Platform logs
- Collect Cisco eStreamer logs
- Collect Cribl Stream logs
- Collect CrowdStrike FileVantage logs
- Collect CrowdStrike IDP Services logs
- Collect Cynet 360 AutoXDR logs
- Collect Digital Shadows SearchLight logs
- Collect Duo Telephony logs
- Collect Edgio WAF logs
- Collect Elastic Auditbeat logs
- Collect Elastic Packet Beats logs
- Collect Elasticsearch logs
- Collect Entrust nShield HSM audit logs
- Collect Imperva Advanced Bot Protection logs
- Collect Imperva Attack Analytics logs
- Collect Imperva Audit Trail logs
- Collect Imperva CEF logs
- Collect Imperva Data Risk Analytics (DRA) logs
- Collect Imperva Database logs
- Collect Imperva FlexProtect logs
- Collect Imperva SecureSphere Management logs
- Collect Kiteworks (formally Accellion) logs
- Collect Proofpoint Emerging Threats Pro IOC logs
- Collect ServiceNow audit logs
- Collect Team Cymru Scout Threat Intelligence data
- Collect URLScan IO logs
- Collect Uptycs EDR logs
- Collect VanDyke VShell SFTP logs
- Collect Zendesk CRM logs
- Collect ZeroFox Platform logs
November 10, 2025
Nested if
You can now use if statements in both the outcome and events sections and
also within the then else clauses of another if statement. This capability
lets you introduce more complicated logic to your query and is supported in
Rules, Search, and Dashboards.
For more information, see Use nested if statements for more complex logic.
November 07, 2025
MITRE ATT&CK coverage dashboard is now available
The new MITRE ATT&CK coverage dashboard lets you measure your security posture against the MITRE ATT&CK framework, helping you:
- Assess threat coverage
- Identify gaps
- Prioritize security efforts
October 31, 2025
Search usability enhancements
Google SecOps has introduced the following capabilities to improve usability, performance, and customization in search results:
Improved performance for large result sets: For broad queries, Google SecOps now provides paginated search results. You can select the number of rows to display per page. This pagination applies to the 10,000 results displayed in the table.
Optimized results view: The search editor now automatically collapses after a query runs, providing more space for results. You can also hide or show the Charts and Aggregations panels with the View Options list.
Customizable column views: You can now create, save, and share custom sets of columns in the Events table for consistent analysis across teams.
All-time search: A new All Time option lets you run a search over the entire data retention period.
For more details, see Search for events and alerts.
Custom log type rename
From now on, all custom log types will be renamed with the custom suffix to prevent confusion with prebuilt log types. The following custom log types already reflect the new naming convention:
- HUAWEI_SECMASTER_CUSTOM
- GTI_THREAT_FEED_CUSTOM
- GTI_IOC_STREAM_CUSTOM
- ABSOLUTE_SECURE_ENDPOINT_CUSTOM
- GTI_IOC_CUSTOM
- IBM_ILO_CUSTOM
- GCP_THREATINTEL_CUSTOM
- SAP_ETD_CUSTOM
October 30, 2025
YARA-L functions
The following new YARA-L functions are now generally available:
strings.ends_with: Takes two strings (value, suffix) and returns true if the suffix is non-empty and at end-of-value.
strings.split: Splits string value using a delimiter argument (by default, a comma).
window.range: Returns the range of the values input values found.
Upgraded Chronicle API ingestion methods from alpha to beta
We've upgraded the Chronicle API ingestion methods from alpha to beta. This upgrade signals API stability and functional completeness, unblocking customer and partner adoption for production integrations.
For more information, see Ingestion methods.
October 29, 2025
Improved support for Chrome Enterprise Premium
This feature is currently in Preview.
An improved integration for Chrome Enterprise Premium is now available that includes:
- Streamlined connection to Google SecOps, using recommended security defaults
- Enhanced log events with Google Safe Browsing context
- Updated parser and integration documentation: Collect Google Chrome logs
- Curated dashboards for Chrome Enterprise Premium
- Google Workspace SOAR actions to manage Chrome extension blocklist policies (Block Extension and Delete Extension)
October 28, 2025
Risk-based alerting with entity-only rules
With the new ENTITY_RISK_CHANGE UDM event type, you can now write YARA-L
detection rules that trigger independently of ingested events. This capability
lets you focus specifically on changes in an entity's risk score, significantly
decreasing the time required for Google Security Operations to detect and alert
on shifting entity risk levels.
For more information, see Risk-based alerting with entity-only rules.
October 27, 2025
New rules for Chrome Enterprise Premium
Curated Detections has been enhanced with additional Chrome Enterprise Premium Browser Threat detections. The following rules have been added to the rulepack:
- Archive Exfiltration Event to Non-Google Websites
- Google Chrome Navigation Event to Shortened URLs
- Suspicious Download from Filehosting or Chat Platform in Chrome Management
- Chrome Suspicious Download Event from Newly Observed Domain in Environment
October 22, 2025
Integration of GTI score in Applied Threat Intelligence (ATI)
Google SecOps now uses Google Threat Intelligence (GTI) score for prioritization in Applied Threat Intelligence (ATI) instead of the IC-score. The GTI score delivers a unified verdict for potential Indicators of Compromise (IoCs) and aggregates a wealth of threat intelligence data.
For details, see Applied Threat Intelligence priority overview and Google Threat Intelligence (GTI) score overview.
October 15, 2025
The Netskope v1 API feed has been deprecated by Netskope. If you are using the Netskope REST API v1 with Google SecOps, you must switch to the Netskope REST API v2.
October 08, 2025
Multi-stage queries in YARA-L
This feature is currently in Preview.
Multi-stage queries in YARA-L are now available as a Preview feature. Multi-stage queries in YARA-L let you feed the output of one query stage directly into the input of a subsequent stage. This process gives you greater control over data transformation than single, monolithic query. They are supported in both Dashboards and Search. Multi-stage queries can contain between 1 and 4 named stages, in addition to a root stage.
For more information, see Create multi-stage queries in YARA-L.
October 07, 2025
Manage parser versions
This feature is in preview.
You now have granular control over how new pre-built parser versions are deployed within your environment.
This feature lets you manage parser updates by taking the following actions:
Opt in or opt out of automatic parser updates.
Review and compare the processing logic between different parser versions.
Manually update a parser to a newer version.
Revert to a previously deployed, stable parser version.
For details, see Manage prebuilt parser versions.
Azure AD Organizational Context default parser rollback
The recent update to the pre-built Azure AD Organizational Context (AZURE_AD_CONTEXT) parser has been rolled back. This action was necessary to resolve a performance degradation issue that was introduced in the latest parser version. For more information about the exact changes and rollback timeline, see the change log for the pre-built parser.
October 05, 2025
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect AlphaSOC alert logs
- Collect AlphaSOC alert logs
- Collect Cisco vManage SD-WAN logs
- Collect Citrix Analytics logs
- Collect Citrix Monitor Service logs
- Collect Citrix StoreFront logs
- Collect Delinea SSO logs
- Collect SailPoint IAM logs
- Collect Sentry logs
- Collect Snipe-IT logs
- Collect Sophos AV logs
- Collect Sophos Capsule8 logs
- Collect Sophos DHCP logs
- Collect Sophos Intercept EDR logs
- Collect Swimlane Platform logs
- Collect Symantec WSS logs
- Collect Tailscale logs
- Collect Tanium Asset logs
- Collect Tanium audit logs
- Collect Tanium Comply logs
- Collect Tanium Discover logs
- Collect Tanium Insight logs
- Collect Tanium Integrity Monitor logs
- Collect Tanium Patch logs
- Collect Tanium Question logs
- Collect Tanium Reveal logs
- Collect Tanium Stream logs
- Collect Tanium Threat Response logs
- Collect TeamViewer logs
- Collect Tines audit logs
October 03, 2025
Customer-managed encryption key compliance now includes support for data tables
Google SecOps has expanded its coverage of Customer-Managed Encryption Key (CMEK) compliance to now include support for data tables.
For more information, see CMEK for Google SecOps.
September 30, 2025
Customize Events table columns in Search
You can now specify which columns appear in the Events table on the
Search page and in tables within your dashboard widgets. Use the select
and unselect keywords to define the displayed columns.
For more information, see Control columns using select and unselect keywords.
September 28, 2025
Forwarder component: end-of-life and migration
The forwarder component is being phased out of the Google SecOps platform and will reach end-of-life (EOL) in January 2027. This impact will change all any data collection pipelines that currently use the forwarder.
Action required: If you're currently using the forwarder component, you must migrate your data collection workflows to an alternative mechanism before April 1, 2027. You'll need to use another data pipeline management application for log ingestion.
We recommend that you migrate to the Bindplane OpenTelemetry (OTel) collector, which provides a scalable, open-standard solution for log and metric ingestion.
The following are key dates to note:
- Apr 1, 2026: New Google SecOps customers cannot use the forwarder component.
- Jan 1, 2027: The forwarder is officially EOL. No further patches, including security patches, will be released.
- Apr 1, 2027: Data is no longer allowed to be ingested from the forwarder component.
Update CrowdStrike API permissions before decommission
CrowdStrike is decommissioning its Detects API on September 30, 2025. This API has been replaced by the Alerts API. To ensure that your data feeds continue without interruption, you may need to update your API permissions.
This change impacts you if your Google SecOps tenant meets both of the following conditions:
- You use the CrowdStrike Detection Monitoring API connector, which ingests the
CS_DETECTSlog type. - The CrowdStrike API client configured for that feed lacks the permissions to read alerts Read.
To prevent disruption to your CrowdStrike data ingestion, you must update your API client permissions before September 30, 2025. Follow the instructions in Migrate from CrowdStrike Detects API to Alerts API to migrate your configuration to use the Alerts API.
For more details, see CrowdStrike’s official decommissioning notice.
September 27, 2025
Use joins in YARA-L Search queries
These changes are currently in Preview.
You can now use joins in statistical Search queries that include a match section
to correlate data from multiple sources. This feature lets you link related
sources directly within a single query.
For more information, see Use joins in Search.
September 23, 2025
Transport-layer migration for third-party API feeds
Google SecOps is migrating the transport layer for third-party API feeds to a new platform to improve performance and reliability. This migration will be completed in phases and is expected to finish by the end of October 2025. The migration should not impact any existing or new, third-party API feeds. If you experience any unexpected issues with your feeds during the migration, contact your Google SecOps representative.
September 10, 2025
View data retention start date
You can now view the start date for your account's data retention period. A new, read-only page, Data Retention, is available under SIEM Settings. This page also shows the start date for your Google SecOps account's data retention period.
For more information, see View data retention in your Google SecOps account.
September 08, 2025
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
Collect Akamai Cloud Monitor logs
Collect Akamai DataStream 2 logs
Collect Aware audit logs
Collect AWS API Gateway access logs
Collect AWS VPC Transit Gateway flow logs
Collect Bitwarden Enterprise event logs
Collect Box Collaboration JSON logs
Collect Censys logs
Collect Code42 Incydr core datasets
Collect CSV Custom IOC files
Collect Deep Instinct EDR logs
Collect DigiCert audit logs
Collect DomainTools Iris Investigate results
Collect Duo administrator logs
Collect Duo authentication logs
Collect Duo entity context logs
Collect Google Cloud Abuse Events logs
Collect Harness IO audit logs
Collect HPE Aruba Networking Central logs
Collect Jamf Pro context logs
Collect PingOne Advanced Identity Cloud logs
Collect Slack audit logs
Collect Snyk group-level audit logs
Collect Snyk group-level audit and issues logs
Collect Venafi Zero Touch PKI logs
Collect Veritas NetBackup logs
Collect VMware AirWatch logs
Collect VMware Avi Load Balancer WAF logs
Collect VMware Horizon logs
Collect VMware VeloCloud SD-WAN logs
Collect Zoom operation logs
September 05, 2025
Advanced filtering in alerts and search results
You can now filter alerts and search results by any field in the detection object. This update provides more granular control over your queries, letting you filter by nested fields from events and entities within a detection.
September 04, 2025
Improved Okta and Symantec Endpoint Protection parsers
These changes are currently in Preview.
The Okta and Symantec Endpoint Protection parsers are now more efficient, with increased log-field coverage and more-accurate log-field mappings. These changes include new UDM fields and updated field mappings. We advise you to opt-in and get these new versions.
For details on the Okta parser, see UDM mapping table and UDM mapping delta reference.
For details on the Symantec Endpoint Protection parser, see Collect Symantec Endpoint Protection logs and UDM mapping delta reference.
Time zone override for forwarder logs
Google SecOps now lets you override the default time zone for your logs when you create or configure a forwarder.
For details, see Add collector configuration.
CBN alerts functionality removed from all prebuilt parsers
As part of deprecating the Configuration Based Normalization (CBN) alerts functionality, all prebuilt parsers that included the CBN alerts functionality were updated, and the functionality was removed.
September 03, 2025
Extended match window for multi-event rules
You can now configure rules to analyze data over a longer period. The maximum match window for these rules has been extended to 14 days. The run frequency for multi-event rules is automatically set based on the rule's match window:
For a window size of 1 to 48 hours, the run frequency is 1 hour.
For a window size greater than 48 hours, the run frequency is 24 hours.
August 29, 2025
MITRE ATT&CK coverage dashboard is now available
This feature is currently in Preview.
The new MITRE ATT&CK coverage dashboard lets you measure your security posture against the MITRE ATT&CK framework, helping you:
- Assess threat coverage
- Identify gaps
- Prioritize security efforts
August 28, 2025
Composite detections for MITRE ATT&CK
The Curated Detections feature has been enhanced with new composite rules that define chains of MITRE ATT&CK tactics and techniques.
These powerful new rule packs are now in public preview for customers with a Google SecOps Enterprise or Enterprise Plus license.
To learn more, a companion blog post will be published on the Google Security Cloud Community on September 9, 2025.
August 27, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- A10 Load Balancer (
A10_LOAD_BALANCER) - AIX system (
AIX_SYSTEM) - Apache (
APACHE) - Arcsight CEF (
ARCSIGHT_CEF) - Aruba Switch (
ARUBA_SWITCH) - Aruba (
ARUBA_WIRELESS) - Attivo Networks (
ATTIVO) - Auth0 (
AUTH_ZERO) - Amazon VPC Transit Gateway Flow Logs (
AWS_VPC_TRANSIT_GATEWAY) - AWS WAF (
AWS_WAF) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Firewall (
AZURE_FIREWALL) - Azure Front Door (
AZURE_FRONT_DOOR) - Carbon Black App Control (
CB_APP_CONTROL) - None (
CHROME_MANAGEMENT) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco DNA Center Platform (
CISCO_DNAC) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco Router (
CISCO_ROUTER) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Audit (
CISCO_UMBRELLA_AUDIT) - Cisco VCS Expressway (
CISCO_VCS) - Cisco WSA (
CISCO_WSA) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Xdome (
CLAROTY_XDOME) - HP Aruba (ClearPass) (
CLEARPASS) - Cloudflare (
CLOUDFLARE) - Cloudflare WAF (
CLOUDFLARE_WAF) - Corelight (
CORELIGHT) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - Cyberark Privilege Cloud (
CYBERARK_PRIVILEGE_CLOUD) - Darktrace (
DARKTRACE) - Datadog (
DATADOG) - Elastic Defend (
ELASTIC_DEFEND) - F5 ASM (
F5_ASM) - F5 Distributed Cloud Services (
F5_DCS) - F5 Silverline (
F5_SILVERLINE) - Fidelis Network (
FIDELIS_NETWORK) - FireEye (
FIREEYE_ALERT) - FireEye NX (
FIREEYE_NX) - Forcepoint DLP (
FORCEPOINT_DLP) - ForgeRock Identity Cloud (
FORGEROCK_IDENTITY_CLOUD) - FortiGate (
FORTINET_FIREWALL) - Cloud SQL (
GCP_CLOUDSQL) - Google Cloud DNS Threat Detector (
GCP_DNS_ATD) - Cloud Load Balancing (
GCP_LOADBALANCING) - None (
GCP_SECURITYCENTER_THREAT) - VPC Flow Logs (
GCP_VPC_FLOW) - AWS GuardDuty (
GUARDDUTY) - IBM-i Operating System (
IBM_I) - Imperva (
IMPERVA_WAF) - Infoblox DHCP (
INFOBLOX_DHCP) - Jamf Protect Telemetry V2 (
JAMF_TELEMETRY_V2) - Kemp Load Balancer (
KEMP_LOADBALANCER) - Kubernetes Node (
KUBERNETES_NODE) - ManageEngine AD360 (
MANAGE_ENGINE_AD360) - McAfee ePolicy Orchestrator (
MCAFEE_EPO) - McAfee IPS (
MCAFEE_IPS) - Medigate IoT (
MEDIGATE_IOT) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft SQL Server (
MICROSOFT_SQL) - Mikrotik Router (
MIKROTIK_ROUTER) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Unix system (
NIX_SYSTEM) - Oracle Cloud Infrastructure VCN Flow Logs (
OCI_FLOW) - Office 365 (
OFFICE_365) - Office 365 Message Trace (
OFFICE_365_MESSAGETRACE) - Okta (
OKTA) - Okta Scaleft (
OKTA_SCALEFT) - Oracle (
ORACLE_DB) - Orca Cloud Security Platform (
ORCA) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Quest Active Directory (
QUEST_AD) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Red Hat OpenShift (
REDHAT_OPENSHIFT) - Symantec Endpoint Protection (
SEP) - Silverfort Authentication Platform (
SILVERFORT) - Squid Web Proxy (
SQUID_WEBPROXY) - STIX Threat Intelligence (
STIX) - Symantec DLP (
SYMANTEC_DLP) - Sysdig (
SYSDIG) - Tenable Security Center (
TENABLE_SC) - Trend Micro (
TIPPING_POINT) - Trellix HX Event Streamer (
TRELLIX_HX_ES) - Trend Micro Apex one (
TRENDMICRO_APEX_ONE) - Trend Micro Vision One Activity (
TRENDMICRO_VISION_ONE_ACTIVITY) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - Trend Micro Vision One Workbench (
TRENDMICRO_VISION_ONE_WORKBENCH) - Ubiquiti UniFi Switch (
UBIQUITI_SWITCH) - Cisco Umbrella DNS (
UMBRELLA_DNS) - Cisco Umbrella IP (
UMBRELLA_IP) - Varonis (
VARONIS) - Vectra XDR (
VECTRA_XDR) - VMware vCenter (
VMWARE_VCENTER) - VMware vRealize Suite (VMware Aria) (
VMWARE_VREALIZE) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Zscaler CASB (
ZSCALER_CASB) - ZScaler Deception (
ZSCALER_DECEPTION) - Zscaler DLP (
ZSCALER_DLP) - ZScaler DNS (
ZSCALER_DNS) - ZScaler NGFW (
ZSCALER_FIREWALL) - Zscaler Internet Access Audit Logs (
ZSCALER_INTERNET_ACCESS) - Zscaler Tunnel (
ZSCALER_TUNNEL) - Zscaler (
ZSCALER_WEBPROXY) - Zscaler Secure Private Access Audit Logs (
ZSCALER_ZPA_AUDIT) - Zscaler Private Access (
ZSCALER_ZPA)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Alicloud ApsaraDB (
ALICLOUD_APSARADB) - AliCloud Firewall (
ALICLOUD_FIREWALL) - AuthMind (
AUTHMIND) - Microsoft Entra Recommendations (
MS_ENTRA_RECOMMENDATIONS) - Palo Alto Networks Prisma Access (
PAN_PRISMA_ACCESS) - Trellix Malware Analysis (
TRELLIX_AX) - Everfox ULTRA (
ULTRA) - ZScaler NSS VM (
ZSCALER_NSS_VM)
August 21, 2025
Enhanced curated detections has been enhanced with composite detection content for Mandiant Hunt Cloud Classification, including AWS, GCP, and Azure. This rule pack is available for Mandiant Threat Defense (MTD) customers with a Google Security Operations Enterprise or Enterprise Plus license.
August 20, 2025
New rules added to rule pack
Curated Detections has been enhanced with additional Chrome Enterprise Premium Browser Threat detections. The following rules have been added to the rule pack:
Dangerous Download with Matching Hashes by multiple users in Chrome Management
GTI High Severity File Download Event in Chrome Management
GTI Medium Severity File Download Event in Chrome Management
GTI Low Severity File Download Event in Chrome Management
Safe-browsing High Severity File Download Event in Chrome Management
Multiple Dangerous Download Events by same user in Chrome Management
Url Event to Newly Created Domain in Chrome Management
Composite detections are now generally available
The composite detections feature is now in General Availability. Composite detections lets you link multiple YARA-L rules to detect complex, multistage threats. This capability enhances detection by correlating alerts that individual rules might not detect.
For more information, see Overview of composite detections.
August 19, 2025
Reference lists retiring
The reference list functionality is being phased out of the Google SecOps platform.
October 2025: You'll no longer be able to create new reference lists. Instead, use data tables to provide expanded functionality.
Migration period: All existing reference lists will be automatically migrated to data tables. During this migration period, you can continue to use your existing reference lists without changes.
September 2026: The legacy reference list functionality will be fully retired from the platform. After that date, all data will be available only through the data table interface.
August 13, 2025
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
- Collect Anomali ThreatStream IOC logs
- Collect Cisco Application Control Engine (ACE)
- Collect Cisco Firepower NGFW logs
- Collect Cisco Firewall Service Module (FWSM)
- Collect Cisco IronPort logs
- Collect Cisco PIX logs
- Collect Cisco Prime logs
- Collect Cisco Wireless Intrusion Prevention System (WIPS) logs
- Collect Cisco Wireless LAN Controller (WLC) logs
- Collect Cisco Wireless Security Management (WiSM) logs
- Collect Cloudian HyperStore logs
- Collect CrushFTP logs
- Collect Delinea Distributed Engine logs
- Collect Duo User context logs
- Collect ExtraHop DNS logs
- Collect ExtraHop RevealX logs
- Collect Extreme Networks switch logs
- Collect Extreme Networks Wireless logs
- Collect MuleSoft Anypoint logs
- Collect Palo Alto Prisma SD-WAN logs
- Collect Recorded Future IOC logs
- Collect Veeam logs
- Collect Veridium ID logs
- Collect VMware Tanzu logs
- Collect VMware vCenter logs
- Collect VMware vRealize logs
- Collect VMware vSphere logs
- Collect VSFTPD logs
- Collect VyOS logs
- Collect Workday audit logs
- Collect Yamaha router logs
August 12, 2025
Data RBAC self-service enablement
Data RBAC now includes a self-service option for direct enablement. This makes the initial onboarding process faster and simpler. For details, see Configure data RBAC for users.
August 10, 2025
Updated permissions for accessing product-centric feeds
If you have assigned Custom IAM Roles, you can now grant access to the product-centric feeds by adding the following permissions to the role:
chronicle.feedPacks.getchronicle.feedPacks.list
To learn more about how to configure feeds using the product-centric feeds UI, see Configure feeds by product.
August 08, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- 1Password (
ONEPASSWORD) - A10 Load Balancer (
A10_LOAD_BALANCER) - AIX system (
AIX_SYSTEM) - Akamai Enterprise Application Access (
AKAMAI_EAA) - Akamai WAF (
AKAMAI_WAF) - Apache (
APACHE) - Aqua Security (
AQUA_SECURITY) - Aruba (
ARUBA_WIRELESS) - Attivo Networks (
ATTIVO) - Auth0 (
AUTH_ZERO) - AWS Config (
AWS_CONFIG) - AWS GuardDuty (
GUARDDUTY) - AWS Lambda Function (
AWS_LAMBDA_FUNCTION) - AWS RDS (
AWS_RDS) - AWS VPC Flow (
AWS_VPC_FLOW) - Azure AD (
AZURE_AD) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Azure AD Sign-In (
AZURE_AD_SIGNIN) - Azure Key Vault logging (
AZURE_KEYVAULT_AUDIT) - Azure VNET Flow (
AZURE_VNET_FLOW) - Barracuda Email (
BARRACUDA_EMAIL) - Barracuda WAF (
BARRACUDA_WAF) - BeyondTrust BeyondInsight (
BEYONDTRUST_BEYONDINSIGHT) - Bitdefender (
BITDEFENDER) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Sandblast (
CHECKPOINT_EDR) - Chrome Management (
N/A) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco Meraki (
CISCO_MERAKI) - Cisco NX-OS (
CISCO_NX_OS) - Cisco Router (
CISCO_ROUTER) - Cisco Stealthwatch (
CISCO_STEALTHWATCH) - Cisco Umbrella SWG DLP (
CISCO_UMBRELLA_SWG_DLP) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco WLC/WCS (
CISCO_WIRELESS) - Cisco WSA (
CISCO_WSA) - Citrix Netscaler (
CITRIX_NETSCALER) - Cloud Audit Logs (
N/A) - Cloud DNS (
N/A) - Cloud Load Balancing (
GCP_LOADBALANCING) - Cloudflare (
CLOUDFLARE) - Corelight (
CORELIGHT) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - CSV Custom IOC (
CSV_CUSTOM_IOC) - CyberArk (
CYBERARK) - Cybereason EDR (
CYBEREASON_EDR) - Darktrace (
DARKTRACE) - EfficientIP DDI (
EFFICIENTIP_DDI) - Elastic Defend (
ELASTIC_DEFEND) - EPIC Systems (
EPIC) - ExtraHop RevealX (
EXTRAHOP) - F5 Advanced Firewall Management (
F5_AFM) - F5 ASM (
F5_ASM) - F5 BIGIP Access Policy Manager (
F5_BIGIP_APM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - F5 DNS (
F5_DNS) - F5 Silverline (
F5_SILVERLINE) - Fidelis Network (
FIDELIS_NETWORK) - FireEye ETP (
FIREEYE_ETP) - ForgeRock Identity Cloud (
FORGEROCK_IDENTITY_CLOUD) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet Proxy (
FORTINET_WEBPROXY) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GitHub (
GITHUB) - Halcyon Anti Ransomware (
HALCYON) - HAProxy (
HAPROXY) - HP Aruba (ClearPass) (
CLEARPASS) - IBM DataPower Gateway (
IBM_DATAPOWER) - Imperva (
IMPERVA_WAF) - Imperva SecureSphere Management (
IMPERVA_SECURESPHERE) - Infoblox DHCP (
INFOBLOX_DHCP) - Jamf pro context (
JAMF_PRO_CONTEXT) - Kubernetes Node (
KUBERNETES_NODE) - Lacework Cloud Security (
LACEWORK) - Linux Auditing System (AuditD) (
AUDITD) - Linux Sysmon (
LINUX_SYSMON) - McAfee IPS (
MCAFEE_IPS) - Menlo Security (
MENLO_SECURITY) - Microsoft AD (
WINDOWS_AD) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Defender for Identity (
MICROSOFT_DEFENDER_IDENTITY) - Microsoft IIS (
IIS) - Mimecast (
MIMECAST_MAIL) - Mimecast Mail V2 (
MIMECAST_MAIL_V2) - MISP Threat Intelligence (
MISP_IOC) - NetApp ONTAP (
NETAPP_ONTAP) - Netskope V2 (
NETSKOPE_ALERT_V2) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - NGINX (
NGINX) - One Identity Identity Manager (
ONE_IDENTITY_IDENTITY_MANAGER) - Opnsense (
OPNSENSE) - Orca Cloud Security Platform (
ORCA) - Palo Alto Cortex XDR Events (
PAN_CORTEX_XDR_EVENTS) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Access (
PAN_CASB) - pfSense (
PFSENSE) - Ping Federate (
PING_FEDERATE) - Proofpoint Observeit (
OBSERVEIT) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Qualys VM (
QUALYS_VM) - Remediant SecureONE (
REMEDIANT_SECUREONE) - SAP SM20 (
SAP_SM20) - SecureAuth (
SECUREAUTH_SSO) - SentinelOne EDR (
SENTINEL_EDR) - Silverfort Authentication Platform (
SILVERFORT) - Sophos Central (
SOPHOS_CENTRAL) - Sophos UTM (
SOPHOS_UTM) - Squid Web Proxy (
SQUID_WEBPROXY) - Symantec DLP (
SYMANTEC_DLP) - Symantec Web Security Service (
SYMANTEC_WSS) - Tenable Active Directory Security (
TENABLE_ADS) - Tenable Security Center (
TENABLE_SC) - Thinkst Canary (
THINKST_CANARY) - Trellix HX Event Streamer (
TRELLIX_HX_ES) - Trend Micro Apex one (
TRENDMICRO_APEX_ONE) - Trend Micro Cloud one (
TRENDMICRO_CLOUDONE) - Trend Micro Vision One Activity (
TRENDMICRO_VISION_ONE_ACTIVITY) - Trend Micro Vision One Observerd Attack Techniques (
TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES) - Trend Micro Vision One Workbench (
TRENDMICRO_VISION_ONE_WORKBENCH) - Tripwire (
TRIPWIRE_FIM) - Unix system (
NIX_SYSTEM) - VMware Horizon (
VMWARE_HORIZON) - VMware vCenter (
VMWARE_VCENTER) - VMware vRealize Suite (VMware Aria) (
VMWARE_VREALIZE) - WatchGuard (
WATCHGUARD) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Workday Audit Logs (
WORKDAY_AUDIT) - Workspace Activities (
WORKSPACE_ACTIVITY) - Workspace Users (
WORKSPACE_USERS) - ZScaler Deception (
ZSCALER_DECEPTION)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Akamai MFA (
AKAMAI_MFA) - Azure Org Context (
AZURE_ORG_CONTEXT) - Cisco Remote Access VPN (
CISCO_RAVPN) - CoreView Audit-log SIEM integration (
COREVIEW) - Fortinet Network Detection and Response (
FORTINET_FORTINDR) - GCP Security Command Center Chokepoint (
GCP_SECURITYCENTER_CHOKEPOINT) - Imperva Cloud WAF (
IMPERVA_CLOUD_WAF) - Lumu Universal SIEM (
LUMU) - Microsoft Azure Databricks (
MICROSOFT_DATABRICKS_WORKSPACES) - Microsoft Insights/Components (
MICROSOFT_INSIGHTS_COMPONENTS) - Microsoft ServiceBus/Namespaces (
MICROSOFT_SERVICEBUS_NAMESPACES) - Microsoft Azure SQL Managed Instances (
MICROSOFT_SQL_MANAGED_INSTANCES) - Moveworks (
MOVEWORKS) - Network Box Unified Threat Management+ (
NETWORKBOX_UTM) - Oracle Cloud Infrastructure Identity Cloud Service (
OCI_IDENTITY_CLOUD_SERVICE) - SAP Commerce Cloud (
SAP_HAC) - Sonatype Lifecycle (
SONATYPE_LIFECYCLE) - TeamViewer Tensor (
TEAMVIEWER_TENSOR) - Torq Audit Logs (
TORQ_AUDIT_LOGS) - Velociraptor - digital forensic & incident response tool (
VELOCIRAPTOR) - Zoom Activity Logs (
ZOOM_ACTIVITY)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
August 05, 2025
New YARA-L features
The following capabilities have been added to YARA-L 2.0 to enhance search precision, data analysis, and investigative workflows:
Conditions in UDM search and dashboards
You can now filter aggregates defined in the
outcomesection using the newconditionclause. This gives you more precise control over your results and supports more targeted investigations.New functionality includes support for
ORandnof[a, b, c.. z]expressions.General availability for search and dashboards.
Deduplicate events in searches and dashboards
The new
dedupsection lets you remove duplicate events after thematchclause in both standard UDM searches and YARA-L 2.0 queries.General availability for search and dashboards.
Use metrics functions in UDM searches
You can now apply
metricsfunctions in theoutcomesection of your search to access aggregated historical data directly in your search queries.- Uses the same syntax as
metricsin rules. - General availability for search.
- Uses the same syntax as
Increased limits for array and array_distinct
The element limit for
arrayandarray_distinctaggregation functions in YARA-L has increased from 25 to 1,000.- General availability for search and dashboards.
- Private preview for rules.
Restrict search results using limit
The
limitkeyword now lets you restrict the number of results returned by a search. Use this to quickly preview data, optimize performance, or focus on a subset of results.General availability for search and dashboards.
earliestandlatesttimestampsNew
earliestandlatesttimestamps let you extract the time range of your data (within microseconds) during aggregation.General availability for search.
Layer aggregations and analytics across multi-stage queries
Recent updates to multi-stage queries let you:
Layer aggregations and data statistical functions. Calculate baselines, deviations, and trends across multiple stages of data processing.
Conduct joins both within and across stages.
Private preview for search and dashboards. Contact your Google SecOps representative to enroll.
Join events, the entity graph, and data tables
You can now perform Inner joins between events, the entity graph, and data tables. These queries require a
matchclause for these joins and return results as statistics.Private preview for search and dashboards. Contact your Google SecOps representative to enroll.
August 04, 2025
New rules added to rule pack
Curated detections has been enhanced with additional Chrome Enterprise Premium Browser Threat detections. The following rules have been added to the rule pack:
Malware Transfer Event in Chrome Management
Password Breach Event By Admin User
Phishing Navigation Event Containing Suspicious Parameters In Chrome Management
Chrome Password Event on Newly Observed Domain in Environment
Auto Extraction supports XML formatted logs in addition to JSON formatted logs. This enhancement will be available starting this week.
July 22, 2025
Silent Host Monitoring
New configuration options are now available for Silent Host Monitoring. You can now define detection rule-based Silent Host Monitoring in SecOps using UDM fields or labels, configurable within a specified time window.
For more information, see Silent host monitoring.
July 21, 2025
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
Collect Aruba EdgeConnect SD-WAN logs
Collect Atlassian Cloud Admin Audit logs
Collect Avigilon Access Control Manager logs
Collect Barracuda CloudGen Firewall logs
Collect Barracuda Web Filter logs
Collect Check Point Harmony logs
Collect CipherTrust Manager logs
Collect CyberArk Privilege Cloud logs
July 07, 2025
Dashboards for enhanced visualizations and threat hunting
You can now use the Google SecOps Dashboards to enhance data visualization, investigations, and threat hunting.
Key capabilities include:
- SOAR data availability
- Downloadable reports
- Custom drilldowns
- Markdown widgets
- 51 curated dashboards covering a broad range of security categories and use cases.
For more information, see Dashboards.
July 02, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.
- 1Password (
ONEPASSWORD) - Apache (
APACHE) - Arcsight CEF (
ARCSIGHT_CEF) - Aruba Switch (
ARUBA_SWITCH) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS GuardDuty (
GUARDDUTY) - AWS Lambda Function (
AWS_LAMBDA_FUNCTION) - AWS S3 Server Access (
AWS_S3_SERVER_ACCESS) - AWS VPC Flow (
AWS_VPC_FLOW) - AWS VPC Flow (CSV) (
AWS_VPC_FLOW_CSV) - Azure AD (
AZURE_AD) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Firewall (
AZURE_FIREWALL) - Azure Storage Audit (
AZURE_STORAGE_AUDIT) - Azure VNET Flow (
AZURE_VNET_FLOW) - BIND (
BIND_DNS) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Brocade Switch (
BROCADE_SWITCH) - Carbon Black (
CB_EDR) - Carbon Black App Control (
CB_APP_CONTROL) - Check Point (
CHECKPOINT_FIREWALL) - Chronicle SOAR Audit (
CHRONICLE_SOAR_AUDIT) - Cisco Application Centric Infrastructure (
CISCO_ACI) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco NX-OS (
CISCO_NX_OS) - Cisco Router (
CISCO_ROUTER) - Cisco Umbrella Web Proxy (
UMBRELLA_WEBPROXY) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Continuous Threat Detection (
CLAROTY_CTD) - Cloudflare (
CLOUDFLARE) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - Crowdstrike IOC (
CROWDSTRIKE_IOC) - Custom Security Data Analytics (
CUSTOM_SECURITY_DATA_ANALYTICS) - CyberArk Endpoint Privilege Manager (EPM) (
CYBERARK_EPM) - Cyberark Privilege Cloud (
CYBERARK_PRIVILEGE_CLOUD) - Darktrace (
DARKTRACE) - Datadog (
DATADOG) - Dell Switch (
DELL_SWITCH) - Elastic Defend (
ELASTIC_DEFEND) - ESET AV (
ESET_AV) - ExtraHop RevealX (
EXTRAHOP) - F5 Advanced Firewall Management (
F5_AFM) - F5 ASM (
F5_ASM) - FireEye ETP (
FIREEYE_ETP) - FireEye NX (
FIREEYE_NX) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GitHub (
GITHUB) - Guardicore Centra (
GUARDICORE_CENTRA) - H3C Comware Platform Switch (
H3C_SWITCH) - IBM Cloud Activity Tracker (
IBM_CLOUD_ACTIVITY_TRACKER) - IBM Security Verify Access (
IBM_SVA) - IBM zSecure Alert (
IBM_ZSECURE_ALERT) - Imperva (
IMPERVA_WAF) - Infoblox (
INFOBLOX) - Infoblox DHCP (
INFOBLOX_DHCP) - KnowBe4 PhishER (
KNOWBE4_PHISHER) - LastPass Password Management (
LASTPASS) - Linux Auditing System (AuditD) (
AUDITD) - Microsoft AD (
WINDOWS_AD) - Microsoft AD FS (
ADFS) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft IIS (
IIS) - Netskope V2 (
NETSKOPE_ALERT_V2) - NGINX (
NGINX) - Nozomi Networks Scada Guardian (
NOZOMI_GUARDIAN) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Openpath (
OPENPATH) - Opnsense (
OPNSENSE) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - Palo Alto Cortex XDR Events (
PAN_CORTEX_XDR_EVENTS) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Access (
PAN_CASB) - Ping Federate (
PING_FEDERATE) - Ping Identity (
PING) - PostgreSQL (
POSTGRESQL) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Radware Web Application Firewall (
RADWARE_FIREWALL) - Red Hat OpenShift (
REDHAT_OPENSHIFT) - Remediant SecureONE (
REMEDIANT_SECUREONE) - Riverbed Steelhead (
STEELHEAD) - SailPoint IAM (
SAILPOINT_IAM) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
N/A) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - Symantec DLP (
SYMANTEC_DLP) - Sysdig (
SYSDIG) - Teradata DB (
TERADATA_DB) - Terraform Enterprise Audit (
TERRAFORM_ENTERPRISE) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - Tripwire (
TRIPWIRE_FIM) - Vectra Detect (
VECTRA_DETECT) - Vectra Stream (
VECTRA_STREAM) - Versa Firewall (
VERSA_FIREWALL) - VMware AirWatch (
AIRWATCH) - VMware ESXi (
VMWARE_ESX) - Voltage (
VOLTAGE) - WatchGuard (
WATCHGUARD) - Windows DHCP (
WINDOWS_DHCP) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Windows Hyper-V (
WINDOWS_HYPERV) - wiz.io (
WIZ_IO) - Workday (
WORKDAY) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zscaler (
ZSCALER_WEBPROXY) - Zscaler CASB (
ZSCALER_CASB) - ZScaler Deception (
ZSCALER_DECEPTION) - Zscaler DLP (
ZSCALER_DLP) - Zscaler Tunnel (
ZSCALER_TUNNEL)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.
- Akamai Kona Edge Grid (
AKAMAI_KONA_EDGE_GRID) - Azure Compute (
AZURE_COMPUTE) - Bluecat Micetro IP Address Management (
BLUECAT_MICETRO_IPAM) - Cloudera Ranger (
CLOUDERA_RANGER) - Cyberark Identity (
CYBERARK_IDENTITY) - Fortinet FortiDLP (
FORTINET_FORTIDLP) - IBM Cognos Analytics (
IBM_COGNOS) - IBM Planning Analytics (
IBM_PA) - Ironclad (
IRONCLAD) - Ivanti Endpoint Manager Mobile (
IVANTI_ENDPOINT_MANAGER_MOBILE) - Mimecast Mail V2 (
MIMECAST_MAIL_V2) - Minsait Sigefi (
MINSAIT_SIGEFI) - Netskope One Secure SD-WAN (
NETSKOPE_SDWAN) - Proxmox (
PROXMOX) - Radware Bot (
RADWARE_BOT) - ScaleFusion for Windows MDM (
SCALEFUSION) - Titan SFTP Server (
TITAN_SFTP) - ZoomInfo (
ZOOMINFO) - Zscaler Email DLP Insights (
ZSCALER_EMAIL_DLP_INSIGHTS)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
June 30, 2025
Data tables are multicolumn constructs that let you input your own data into Google SecOps. You can create or import data tables to your Google SecOps account using the Google SecOps UI, the Data Tables API, or by using YARA-L queries in rules. This feature is now available to all customers.
What's new for this release:
- Multiple web interface enhancements have been made, including a new default table view for data table management.
- Support for the
numberdata type is now available for data table columns. - Support for repeated fields in data table columns.
- The Limitations section has additional details.
June 23, 2025
New parser documentation now available
New parser documentation is available to help you ingest and normalize logs from the following sources:
Collect BeyondTrust BeyondInsight logs
Collect BloxOne Threat Defense logs
Collect BlueCat Edge DNS Resolver logs
Collect Check Point Audit logs
Collect Check Point SmartDefense logs
Collect Dell EMC Data Domain logs
Collect Dell EMC Isilon NAS logs
Collect Dell EMC PowerStore logs
Collect Endpoint Protector DLP logs
Collect Kaseya Datto File Protection logs
Collect ManageEngine AD360 logs
Collect Palo Alto Cortex XDR Events logs
Collect Trend Micro Email Security logs
Collect Trend Micro Vision One Activity logs
Collect Trend Micro Vision One Audit logs
Collect Trend Micro Vision One Container Vulnerability logs
Collect Trend Micro Vision One Detections logs
Collect Trend Micro Vision One Observed Attack Techniques logs
June 19, 2025
Product Centric Feed Management
This feature is currently in Preview.
You can now configure multiple log-type feeds for the same product type on a single page. This new product-led experience simplifies the feed configuration flow and provides additional in-product guidance. For more information, see Configure feeds by product.
June 18, 2025
New data ingestion and health dashboard widgets are now available.
- Silent host monitoring: displays hosts that were active in the last 7 days, but haven't reported recently, including a count of days since their last ingestion.
- BindPlane agent logging and health: visualizes logging activity and agent health. Requires Bindplane agent logs to be ingested into Google SecOps.
- Throughput in bytes: shows ingestion volume over time.
- Improved log type distribution charts: updates charts for better readability and usability.
You can now remove existing UDM field mappings by using parser extensions in Google SecOps.
For more information, see Remove UDM field mappings using parser extensions and Code snippet - Remove existing mappings
June 16, 2025
The Release Candidate period of the following premium parsers has been extended from the end of May to the week of July 21, 2025:
- Crowdstrike Detection Monitoring (CS_DETECTS)
- Crowdstrike Falcon (CS_EDR)
- Microsoft Defender for Endpoint
We recommend that you opt-in early and make any necessary adjustments before these updates become the default.
June 04, 2025
The following parser documentation is now available:
Collect Abnormal Security logs
Collect Nix Systems Ubuntu Server (Unix System) logs
Collect Symantec Endpoint Protection logs
Collect Symantec VIP Authentication Hub logs
Collect Symantec VIP Enterprise Gateway logs
Collect Symantec Web Isolation logs
Collect Attivo Networks BOTsink logs
Collect BeyondTrust Endpoint Privilege Management logs
Collect BeyondTrust Privileged Identity logs
Collect Blue Coat ProxySG logs
Collect Microsoft Exchange logs
June 03, 2025
User interface fixes
There was an issue with highlighting regular expressions in Search and Rules Editor. Once you entered a regular expression, all subsequent text on the line would be highlighted as if it was also a regular expression (whether it was or wasn't). This issue has been fixed. Note that both string literals (specified with back ticks) and regular expressions are highlighted in the same color.
There was an issue with uppercase keywords in Search and Rules Editor. They weren't being highlighted correctly. This issue has been fixed.
May 29, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have changed. Each parser is listed by product name and log_type value, if applicable. This list now includes both released default parsers and pending parser updates.
- AIX system (
AIX_SYSTEM) - Akamai WAF (
AKAMAI_WAF) - Apache (
APACHE) - Appian Cloud (
APPIAN_CLOUD) - Auth0 (
AUTH_ZERO) - AWS CloudFront (
AWS_CLOUDFRONT) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS GuardDuty (
GUARDDUTY) - AWS Macie (
AWS_MACIE) - AWS Session Manager (
AWS_SESSION_MANAGER) - AWS VPC Flow (
AWS_VPC_FLOW) - AWS VPC Flow (CSV) (
AWS_VPC_FLOW_CSV) - Azure AD (
AZURE_AD) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Firewall (
AZURE_FIREWALL) - Azure Storage Audit (
AZURE_STORAGE_AUDIT) - Barracuda Firewall (
BARRACUDA_FIREWALL) - BeyondTrust BeyondInsight (
BEYONDTRUST_BEYONDINSIGHT) - BIND (
BIND_DNS) - Bitdefender (
BITDEFENDER) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Brocade Switch (
BROCADE_SWITCH) - Carbon Black (
CB_EDR) - CircleCI (
CIRCLECI) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco ISE (
CISCO_ISE) - Cisco NX-OS (
CISCO_NX_OS) - Cisco Prime (
CISCO_PRIME) - Cisco Switch (
CISCO_SWITCH) - Cisco Unity Connection (
CISCO_UNITY_CONNECTION) - Cloud Audit Logs (
N/A) - CrowdStrike Alerts API (
CS_ALERTS) - CrowdStrike Falcon (
CS_EDR) - CyberArk Endpoint Privilege Manager (EPM) (
CYBERARK_EPM) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Cylance Protect (
CYLANCE_PROTECT) - Darktrace (
DARKTRACE) - Dell OpenManage (
DELL_OPENMANAGE) - EfficientIP DDI (
EFFICIENTIP_DDI) - Elastic Defend (
ELASTIC_DEFEND) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT) - ExtraHop RevealX (
EXTRAHOP) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - F5 DNS (
F5_DNS) - Fastly WAF (
FASTLY_WAF) - FireEye HX (
FIREEYE_HX) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet FortiAuthenticator (
FORTINET_FORTIAUTHENTICATOR) - Fortinet FortiNAC (
FORTINET_FORTINAC) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GitHub (
GITHUB) - Gitlab (
GITLAB) - HP Aruba (ClearPass) (
CLEARPASS) - Ipswitch SFTP (
IPSWITCH_SFTP) - Juniper (
JUNIPER_FIREWALL) - Linux Auditing System (AuditD) (
AUDITD) - ManageEngine ADManager Plus (
ADMANAGER_PLUS) - McAfee ePolicy Orchestrator (
MCAFEE_EPO) - Microsoft AD FS (
ADFS) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Identity (
MICROSOFT_DEFENDER_IDENTITY) - Microsoft IIS (
IIS) - Microsoft PowerShell (
POWERSHELL) - Netskope Web Proxy (
NETSKOPE_WEBPROXY) - Nokia Router (
NOKIA_ROUTER) - Office 365 (
OFFICE_365) - Oracle (
ORACLE_DB) - Palo Alto Cortex XDR Events (
PAN_CORTEX_XDR_EVENTS) - Palo Alto Prisma Access (
PAN_CASB) - Ping Federate (
PING_FEDERATE) - Ping Identity (
PING) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Radware Web Application Firewall (
RADWARE_FIREWALL) - ServiceNow Audit (
SERVICENOW_AUDIT) - Snare System Diagnostic Logs (
SNARE_SOLUTIONS) - Symantec DLP (
SYMANTEC_DLP) - Symantec Security Analytics (
SYMANTEC_SA) - Sysdig (
SYSDIG) - Tanium Question (
TANIUM_QUESTION) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - Trend Micro Vision One Workbench (
TRENDMICRO_VISION_ONE_WORKBENCH) - TrendMicro Deep Discovery Inspector (
TRENDMICRO_DDI) - VanDyke SFTP (
VANDYKE_SFTP) - Vectra Detect (
VECTRA_DETECT) - Vectra Stream (
VECTRA_STREAM) - Vectra XDR (
VECTRA_XDR) - VMware ESXi (
VMWARE_ESX) - VMWare VSphere (
VMWARE_VSPHERE) - WatchGuard (
WATCHGUARD) - Windows Event (XML) (
WINEVTLOG_XML) - Workspace Activities (
WORKSPACE_ACTIVITY) - Zscaler (
ZSCALER_WEBPROXY) - Zscaler CASB (
ZSCALER_CASB) - Zscaler DLP (
ZSCALER_DLP) - ZScaler DNS (
ZSCALER_DNS) - Zscaler Internet Access Audit Logs (
ZSCALER_INTERNET_ACCESS) - ZScaler NGFW (
ZSCALER_FIREWALL) - Zscaler Private Access (
ZSCALER_ZPA) - Zscaler Secure Private Access Audit Logs (
ZSCALER_ZPA_AUDIT) - Zscaler Tunnel (
ZSCALER_TUNNEL)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, if applicable.
- Azure App Configuration (
AZURE_APPCONFIGURATION) - Azure App Platform (
AZURE_APPPLATFORM) - Azure ArcData (
AZURE_ARCDATA) - Azure Authorization (
AZURE_AUTHORIZATION) - Azure Change Analysis (
AZURE_CHANGEANALYSIS) - Azure DataFactory (
AZURE_DATAFACTORY) - Doppel (
DOPPEL) - Genian NAC (
GENIAN_NAC) - Penta Security Wapples (
PENTA_WAPPLES) - Redmine (
REDMINE) - S2W Quaxar (
S2W_QUAXAR) - SecurityBridge Dev (
SECURITYBRIDGE_DEV) - TeamT5 ThreatSonar EDR (
TEAMT5_THREATSONAR_EDR) - WorkDay User Sign In (
WORKDAY_USER_SIGNIN)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
May 26, 2025
New Storage Transfer Service (STS) based feeds
This feature is currently in Preview.
Existing tenants are now able to create new feeds using STS, whereas existing feeds will remain unaffected. Customers will be separately notified about the required steps and timelines for the migration of existing feeds to STS. The following new feeds are available:
- GOOGLE_CLOUD_STORAGE_V2
- GOOGLE_CLOUD_STORAGE_EVENT_DRIVEN
- AMAZON_S3_V2
- AMAZON_SQS_V2
- AZURE_BLOBSTORE_V2
The following feed types are replaced by the new STS-based feeds:
- GOOGLE_CLOUD_STORAGE replaced by GOOGLE_CLOUD_STORAGE_V2
- AMAZON_S3 replaced by AMAZON_S3_V2
- AMAZON_SQS replaced by AMAZON_SQS_V2
- AZURE_BLOBSTORE replaced by AZURE_BLOBSTORE_V2
For more information, see Storage Transfer Service and its benefits and Configuration by source type.
May 21, 2025
The following parser documentation is now available.
Collect Automation Anywhere logs
Collect ManageEngine ADAudit Plus logs
Collect Nasuni File Services Platform logs
Collect McAfee Web Gateway logs
Collect Microsoft Defender for Identity logs
May 14, 2025
New premium versions of the following parsers are now available:
- ZSCALER_WEBPROXY
- ZSCALER_FIREWALL
- ZSCALER_DNS
- ZSCALER_INTERNET_ACCESS
- ZSCALER_VPN
- ZSCALER_ZPA
- ZSCALER_TUNNEL
- ZSCALER_CASB
- ZSCALER_DLP
- ZSCALER_ADMIN_AUDIT
We recommend using the documented topology for each parser.
May 12, 2025
YARA-L search with data tables updates
- Data tables are now accessible from the Investigation menu, instead of Detection, in the web interface.
- Data tables can now be used as a data source in search queries.
- Role-based access control (RBAC) has been added to manage access to data tables.
A feature rollout on May 8, 2025, introduced new APIs that may require updated permissions for custom roles to access the detection UI page.
If you encounter access errors, update your permissions, as needed, or select Revert to Previous Detection Table on the detection page to revert to the previous UI.
May 09, 2025
Google SecOps supports Self Service creation of custom log types. Self service custom log types let you create custom log types instantly instead of going through SecOps support, allowing quicker data onboarding. This feature will be available as a public preview starting the week of May 12, 2025.
May 07, 2025
We are moving service health updates for Google Cloud Security products from the Cloud Status Dashboard to a new security-specific status dashboard.
This dashboard displays service status and incident history for the following products:
- Google SecOps
- Google Threat Intelligence
- Mandiant Advantage Threat Intelligence
- Mandiant Attack Surface Management
- Mandiant Digital Threat Monitoring
- Mandiant Hunt
- Mandiant Managed Defense
- Mandiant Security Validation
May 05, 2025
New Light Theme
Google SecOps has introduced a new light theme option in the platform. The light theme includes a color palette for visual clarity.
May 02, 2025
Auto extraction of JSON logs
Google SecOps supports Auto Extraction of JSON logs. The auto extraction feature lets you use raw log fields directly in search, detection rules, and Native Dashboards, with or without a parser. Public preview for this feature begins the week of May 5, 2025.
April 28, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so changes may take one-to-four days to appear in your region.
The following supported default parsers have been updated. Each parser is listed by product name and log_type value, if applicable. This list now includes both released default parsers and pending parser updates.
- 1Password Audit Events (
ONEPASSWORD_AUDIT_EVENTS) - AIX system (
AIX_SYSTEM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Alveo Risk Data Management (
ALVEO_RDM) - Amazon API Gateway (
AWS_API_GATEWAY) - Apache Tomcat (
TOMCAT) - Appian Cloud (
APPIAN_CLOUD) - Arcsight CEF (
ARCSIGHT_CEF) - Asset Panda (
ASSET_PANDA) - Aware Audit (
AWARE_AUDIT) - Aware Signals (
AWARE_SIGNALS) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS ECS Metrics (
AWS_ECS_METRICS) - AWS Elastic Load Balancer (
AWS_ELB) - AWS GuardDuty (
GUARDDUTY) - AWS Inspector (
AWS_INSPECTOR) - AWS Lambda Function (
AWS_LAMBDA_FUNCTION) - AWS RDS (
AWS_RDS) - AWS Redshift (
AWS_REDSHIFT) - AWS Route 53 DNS (
AWS_ROUTE_53) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS VPC Flow (
AWS_VPC_FLOW) - AWS WAF (
AWS_WAF) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Firewall (
AZURE_FIREWALL) - Azure Key Vault logging (
AZURE_KEYVAULT_AUDIT) - Barracuda CloudGen Firewall (
BARRACUDA_CLOUDGEN_FIREWALL) - Barracuda WAF (
BARRACUDA_WAF) - BeyondTrust BeyondInsight (
BEYONDTRUST_BEYONDINSIGHT) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Broadcom Support Portal Audit Logs (
BROADCOM_SUPPORT_PORTAL) - Cato Networks (
CATO_NETWORKS) - Cequence Bot Defense (
CEQUENCE_BOT_DEFENSE) - Check Point (
CHECKPOINT_FIREWALL) - ChromeOS XDR (
CHROMEOS_XDR) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco EStreamer (
CISCO_ESTREAMER) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco NX-OS (
CISCO_NX_OS) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Cloud Firewall (
UMBRELLA_FIREWALL) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco VPN (
CISCO_VPN) - Citrix Netscaler (
CITRIX_NETSCALER) - Citrix Storefront (
CITRIX_STOREFRONT) - Claroty Xdome (
CLAROTY_XDOME) - Cloud Audit Logs (
N/A) - Cloud Data Loss Prevention (
N/A) - Cloudflare Network Analytics (
CLOUDFLARE_NETWORK_ANALYTICS) - Cloudflare WAF (
CLOUDFLARE_WAF) - Cloudflare Warp (
CLOUDFLARE_WARP) - CommVault (
COMMVAULT) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - CrowdStrike Identity Protection Services (
CS_IDP) - CrushFTP (
CRUSHFTP) - Custom Application Access Logs (
CUSTOM_APPLICATION_ACCESS) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Cybereason EDR (
CYBEREASON_EDR) - Cyolo Secure Remote Access for OT (
CYOLO_OT) - Datadog (
DATADOG) - Delinea Secret Server (
DELINEA_SECRET_SERVER) - Dell CyberSense (
DELL_CYBERSENSE) - Digicert (
DIGICERT) - Edgio WAF (
EDGIO_WAF) - Elastic Packet Beats (
ELASTIC_PACKETBEATS) - F5 ASM (
F5_ASM) - F5 DNS (
F5_DNS) - Forcepoint DLP (
FORCEPOINT_DLP) - Forcepoint NGFW (
FORCEPOINT_FIREWALL) - Forgerock OpenIdM (
FORGEROCK_OPENIDM) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet Fortimanager (
FORTINET_FORTIMANAGER) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GitHub (
GITHUB) - Gitlab (
GITLAB) - Harness IO (
HARNESS_IO) - Hashicorp Vault (
HASHICORP) - Hillstone Firewall (
HILLSTONE_NGFW) - Huawei Switches (
HUAWEI_SWITCH) - IBM Guardium (
GUARDIUM) - Imperva Database (
IMPERVA_DB) - Intel Endpoint Management Assistant (
INTEL_EMA) - JAMF Security Cloud (
JAMF_SECURITY_CLOUD) - JFrog Artifactory (
JFROG_ARTIFACTORY) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS) - Juniper (
JUNIPER_FIREWALL) - Kaspersky AV (
KASPERSKY_AV) - Kaspersky Endpoint (
KASPERSKY_ENDPOINT) - Kolide Endpoint Security (
KOLIDE) - Kubernetes Audit (
KUBERNETES_AUDIT) - Layer7 SiteMinder (
SITEMINDER_SSO) - Linux Auditing System (AuditD) (
AUDITD) - Looker Audit (
LOOKER_AUDIT) - ManageEngine ADAudit Plus (
ADAUDIT_PLUS) - ManageEngine ADManager Plus (
ADMANAGER_PLUS) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Metabase (
METABASE) - Microsoft AD FS (
ADFS) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Azure NSG Flow (
AZURE_NSG_FLOW) - Microsoft CyberX (
CYBERX) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Identity (
MICROSOFT_DEFENDER_IDENTITY) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft IIS (
IIS) - Microsoft PowerShell (
POWERSHELL) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft System Center Endpoint Protection (
MICROSOFT_SCEP) - Mikrotik Router (
MIKROTIK_ROUTER) - Mimecast (
MIMECAST_MAIL) - MISP Threat Intelligence (
MISP_IOC) - NetIQ eDirectory (
NETIQ_EDIRECTORY) - Netskope V2 (
NETSKOPE_ALERT_V2) - Nozomi Networks Scada Guardian (
NOZOMI_GUARDIAN) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Okta User Context (
OKTA_USER_CONTEXT) - One Identity Identity Manager (
ONE_IDENTITY_IDENTITY_MANAGER) - Oort Security Tool (
OORT) - Open Cybersecurity Schema Framework (OCSF) (
OCSF) - Open LDAP (
OPENLDAP) - Opnsense (
OPNSENSE) - Ops Genie (
OPS_GENIE) - Oracle (
ORACLE_DB) - Oracle Cloud Guard (
OCI_CLOUDGUARD) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT) - Orca Cloud Security Platform (
ORCA) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Access (
PAN_CASB) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Pharos (
PHAROS) - Privacy-I (
PRIVACY_I) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Radware Web Application Firewall (
RADWARE_FIREWALL) - ReviveSec (
REVIVESEC) - Rubrik (
RUBRIK) - Salesforce (
SALESFORCE) - Sangfor Proxy (
SANGFOR_PROXY) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
N/A) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - ServiceNow CMDB (
SERVICENOW_CMDB) - Snare System Diagnostic Logs (
SNARE_SOLUTIONS) - Snipe-IT (
SNIPE_IT) - Snyk Group level audit/issues logs (
SNYK_ISSUES) - SonicWall (
SONIC_FIREWALL) - Sophos Central (
SOPHOS_CENTRAL) - Swimlane Platform (
SWIMLANE) - Symantec DLP (
SYMANTEC_DLP) - Symantec Event export (
SYMANTEC_EVENT_EXPORT) - Symantec Web Security Service (
SYMANTEC_WSS) - Tanium Question (
TANIUM_QUESTION) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Teleport Access Plane (
TELEPORT_ACCESS_PLANE) - Tenable Active Directory Security (
TENABLE_ADS) - Tenable CSPM (
TENABLE_CSPM) - tenable.io (
TENABLE_IO) - Terraform Enterprise Audit (
TERRAFORM_ENTERPRISE) - Thinkst Canary (
THINKST_CANARY) - ThreatX WAF (
THREATX_WAF) - Trend Micro Email Security Advanced (
TRENDMICRO_EMAIL_SECURITY) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - TrendMicro Apex Central (
TRENDMICRO_APEX_CENTRAL) - TXOne Stellar (
TRENDMICRO_STELLAR) - UKG (
UKG) - Unix system (
NIX_SYSTEM) - UPX AntiDDoS (
UPX_ANTIDDOS) - VanDyke SFTP (
VANDYKE_SFTP) - Varonis (
VARONIS) - Vectra Alerts (
VECTRA_ALERTS) - Vectra Stream (
VECTRA_STREAM) - VMware AirWatch (
AIRWATCH) - Vmware Avinetworks iWAF (
VMWARE_AVINETWORKS_IWAF) - VMware ESXi (
VMWARE_ESX) - VMware Horizon (
VMWARE_HORIZON) - Watchguard EDR (
WATCHGUARD_EDR) - Windows Defender AV (
WINDOWS_DEFENDER_AV) - Windows DHCP (
WINDOWS_DHCP) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Windows Sysmon (
WINDOWS_SYSMON) - Workday Audit Logs (
WORKDAY_AUDIT) - Workday User Activity (
WORKDAY_USER_ACTIVITY) - WPEngine (
WPENGINE) - Zimperium (
ZIMPERIUM) - Zscaler (
ZSCALER_WEBPROXY) - ZScaler DNS (
ZSCALER_DNS) - Zscaler Internet Access Audit Logs (
ZSCALER_INTERNET_ACCESS) - ZScaler NGFW (
ZSCALER_FIREWALL)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, if applicable.
- Accenture Synthetic (
ACCENTURE_SYNTHETIC) - Adyen Platform (
ADYEN) - AliCloud ActionTrail (
ALICLOUD_ACTIONTRAIL) - Apache LOG4J Java Application Log (
LOG4J) - AppSmith Audit (
APPSMITH_AUDIT) - Arctic Security Arctic Node (
ARCTIC_NODE) - Arista CorvilNet DANZ Integration (
ARISTA_CORVILNET) - Arista Extensible Operating System (
ARISTA_EOS) - AvePoint EnPower (
AVEPOINT_ENPOWER) - Avigilon Alta Cloud Security (
AVIGILON_ALTA_CLOUD_SECURITY) - Avigilon Ava Security Camera (
AVIGILON_AVA_SECURITY_CAMERA) - AWS Dasha (
AWS_DASHA) - AWS Elastic Kubernetes Service (
AWS_EKS) - Azure Network Security Group Event (
AZURE_NSG_EVENT) - Azure Windows Virtual Desktop Connections Logs (
AZURE_WVD_CONNECTIONS) - Azure Windows Virtual Desktop Management Logs (
AZURE_WVD_MANAGEMENT) - Barracuda Load Balancer ADC (
BARRACUDA_LOAD_BALANCER) - Broadcom Edge Secure Web Gateway (
BROADCOM_EDGE_SWG) - Celonis Audit Logs (
CELONIS) - Chopin PrePay Solutions (
CHOPIN_PPS) - Cisco Duo Authentication Proxy (
DUO_AUTH_PROXY) - Cloudflare CASB Findings (
CLOUDFLARE_CASB_FINDINGS) - Cloudflare Device posture results (
CLOUDFLARE_DEVICE_POSTURE_RESULTS) - Cloudflare DLP Forensic Copies (
CLOUDFLARE_DLP_FORENSIC_COPIES) - Cloudflare DNS Firewall Logs (
CLOUDFLARE_DNS_FIREWALL_LOGS) - Cloudflare DNS logs (
CLOUDFLARE_DNS_LOGS) - Cloudflare Email Security Alerts (
CLOUDFLARE_EMAIL_SECURITY_ALERTS) - Cloudflare Firewall Events (
CLOUDFLARE_FIREWALL_EVENTS) - Cloudflare Gateway DNS (
CLOUDFLARE_GATEWAY_DNS) - Cloudflare Gateway HTTP (
CLOUDFLARE_GATEWAY_HTTP) - Cloudflare Gateway Network (
CLOUDFLARE_GATEWAY_NETWORK) - Cloudflare HTTP requests (
CLOUDFLARE_HTTP_REQUESTS) - Cloudflare Magic IDS Detections (
CLOUDFLARE_MAGIC_IDS_DETECTIONS) - Cloudflare NEL reports (
CLOUDFLARE_NEL_REPORTS) - Cloudflare Sinkhole HTTP Logs (
CLOUDFLARE_SINKHOLE_HTTP_LOGS) - Cloudflare SSH Logs (
CLOUDFLARE_SSH_LOGS) - Cloudflare Workers Trace Events (
CLOUDFLARE_WORKERS_TRACE_EVENTS) - Cloudflare Zero Trust Network Session (
CLOUDFLARE_ZERO_TRUST_NETWORK_SESSION) - CloudWave Honeypot (
CLOUDWAVE_HONEYPOT) - ColorTokens (
COLORTOKENS) - Contrast Security (
CONTRAST_SECURITY) - Conversational Agents and Dialogflow (
CONVERSATIONAL_AGENT) - Corero SmartWall One (
CORERO_SMARTWALL_ONE) - Cytracom Control One (
CYTRACOM_CONTROL_ONE) - Datadog Application Security Management (
DATADOG_ASM) - Express NodeJS (
EXPRESS_NODEJS) - F5 Distributed Cloud WAF (
F5_DCS_WAF) - Figma Developers (
FIGMA) - FIS Trax Payment Factory (
TRAX) - Fortinet FortiDeceptor (
FORTINET_FORTIDECEPTOR) - Fortinet FortiSASE (
FORTINET_FORTISASE) - Gemini Code Assist (
GEMINI_CODE_ASSIST) - Genea Access Control (
GENEA_ACCESS_CONTROL) - Genetec Synergis (
GENETEC_SYNERGIS) - GL TRADE (
GL_TRADE) - HP Inc MFP (
HP_INC_MFP) - HP Tandem (
HP_TANDEM) - Huawei Versatile Routing Platform (
HUAWEI_VRP) - Human Security (
HUMAN_SECURITY) - iManage Threat Manager (
IMANAGE_THREAT_MANAGER) - Indefend DLP (
INDEFEND_DLP) - Invicti (
INVICTI) - Isonline ISL Light (
ISL_LIGHT) - Itential Pronghorn (
ITENTIAL_PRONGHORN) - Jit (
JIT) - Kodem Security (
KODEM_SECURITY) - Konica Minolta YSoft SafeQ (
YSOFT_SAFEQ) - LayerX (
LAYERX) - LinOTP (
LIN_OTP) - Magento Cloud (
MAGENTO_CLOUD) - Mandiant Advantage Security Validation (
MA_SV) - NetApp ONTAP Audit (
NETAPP_ONTAP_AUDIT) - Netscout Arbor Threat Mitigation System (
NETSCOUT_TMS) - Netwrix Privilege Secure (
NETWRIX_PRIVILEGE_SECURE) - NeuVector SUSE (
NEUVECTOR) - Novidea Insurance Management System (
NOVIDEA_CLAIM_HISTORY) - OneTrust (
ONETRUST) - Openpath Context (
OPENPATH_CONTEXT) - Oracle Audit Vault Database Firewall (
ORACLE_AVDF) - Oracle CPQ (
ORACLE_CPQ) - Oracle Exadata Database Machine (
ORACLE_EXADATA) - Palo Alto Prisma Cloud Workload Protection (
PAN_PRISMA_CWP) - Palo Alto Prisma Dig Cloud DSPM (
PAN_PRISMA_DIG_CLOUD_DSPM) - Panorays (
PANORAYS) - Pathlock Identity Security Platform (
PATHLOCK) - Procore (
PROCORE) - ProofPoint Email Protection (
PROOFPOINT_EMAIL_PROTECTION) - Radiantone (
RADIANTONE) - Radware Cloud WAF Service Access (
RADWARE_ACCESS) - Reblaze Web Application Firewall (
REBLAZE_WAF) - Red Access Browsing Security (
RED_ACCESS) - SafeNet Network HSM (
SAFENET_HSM) - Salesforce Marketing Cloud Audit (
SALESFORCE_MARKETING_CLOUD_AUDIT) - Salesforce Shield (
SALESFORCE_SHIELD) - Sangfor IAG (
SANGFOR_IAG) - SAP Leasing (
SAP_LEASING) - SAS Institute (
SAS_INSTITUTE) - Securden (
SECURDEN) - SecurEnvoy SecurAccess (
SECURENVOY_MFA) - Securesoft Sniper IPS (
SECURESOFT_SNIPER_IPS) - Sentra Data Loss Prevention (
SENTRA_DLP) - Shield IoT (
SHIELD_IOT) - Siemens Simatic S7 PLC SNMP (
SIEMENS_S7_PLC_SNMP) - Siemens Simatic S7 PLC SYSLOG (
SIEMENS_S7_PLC_SYSLOG) - Smartsheet User Context (
SMARTSHEET_USER_CONTEXT) - Snowflake Access (
SNOWFLAKE_ACCESS) - SOCRadar Incidents (
SOCRADAR_INCIDENTS) - Strata Maverics Identity Orchestration Platform (
STRATA_MAVERICS) - Stripe Payments (
STRIPE) - Suridata (
SURIDATA) - Teradata Access (
TERADATA_ACCESS) - Thales payShield 10K HSM (
THALES_PS10K_HSM) - Trend Micro TippingPoint Security Management System (
TREND_MICRO_TIPPING_POINT) - Valence Security (
VALENCE) - Vertica Audit (
VERTICA_AUDIT) - Windows NTP (
WINDOWS_NTP) - Winget Autoupdate (
WINGET_AUTOUPDATE) - Wiz Runtime Execution Data (
WIZ_RUNTIME_EXECUTION_DATA) - Workiva Wdesk (
WORKIVA_WDESK) - XL Release (
XLR) - Yugabyte Database (
YUGABYTE_DATABASE)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
April 25, 2025
Google SecOps now supports native integration with Azure Event Hub through the feed management API or web interface. This enhancement enables real-time log ingestion without requiring Azure blob storage. For more information, see Create an Azure Event Hub feed.
April 23, 2025
This feature is currently in Preview. Google SecOps now supports composite detections. Composite detections lets users link multiple YARA-L rules to detect complex, multistage threats. This capability enhances detection by correlating alerts that individual rules might not detect.
April 22, 2025
The following parser documentation is now available:
Collect Barracuda Email Security Gateway logs
Collect CrowdStrike Falcon logs in CEF
Collect Juniper NetScreen Firewall logs
Collect Micro Focus NetIQ Access Manager logs
Collect Aruba Wireless Controller and Access Point logs
Collect BeyondTrust Secure Remote Access logs
Collect CyberArk Privileged Threat Analytics logs
Collect Fortinet FortiMail logs
Collect Sophos XG Firewall logs
Collect Cisco Stealthwatch logs
Collect Cisco Umbrella audit logs
Collect Cisco Umbrella DNS logs
Collect Cisco Umbrella Web Proxy logs
Collect CommVault Backup and Recovery logs
Collect Fortinet FortiAnalyzer logs
Collect Fortinet FortiAuthenticator logs
Collect Fortinet Firewall logs
Collect Palo Alto Networks Traps logs
Collect SecureAuth Identity Platform logs
Collect A10 Network Load Balancer logs
Collect AlgoSec Security Management logs
Collect Arbor Edge Defense logs
Collect Fortra Digital Guardian DLP logs
April 21, 2025
Curated Detections has been enhanced with new detection content for Cloud Threats to include rule packs covering Office 365 and Okta. These rule packs are in public preview for customers with a Google Security Operations or Enterprise Plus license.
April 18, 2025
Chrome Enterprise Threats Category
This feature is currently in Preview.
Google SecOps has introduced a new detection category, Chrome Enterprise Threats, as part of the Curated Detections feature. This category provides rule sets for extension and browser threats. For more information, see Overview of Chrome Enterprise Threats Category.
April 17, 2025
Entity Context in Search
This feature enhances security investigations and incident response by letting users search for and view context events related to entities. It incorporates UDM entity context data to provide deeper insights into security incidents.
This feature is currently in Preview.
April 15, 2025
We are releasing updated versions of the following premium parsers:
- Crowdstrike Detection Monitoring (CS_DETECTS)
- Crowdstrike Falcon (CS_EDR)
- Microsoft Defender for Endpoint
These updates include significant improvements to parser mappings. For a detailed list of all mapping changes, contact your Google SecOps representative.
The new versions will remain in an extended Release Candidate period through the end of May 2025. We recommend that you opt-in early and make any necessary adjustments before these updates become the default.
April 07, 2025
Premium parsers
Specific high-volume parsers are now categorized as premium. Google aims to address customer issues related to premium parsers as quickly as possible, typically within a few days.
For a complete list of different types of parsers and the level of support that Google provides for each, see Manage prebuilt and custom parsers.
For a complete list of premium parsers, see Default parser configuration and ingestion.
April 04, 2025
Optimize log management using extractors
This feature is currently in Preview.
You can now optimize log management by creating extractors to pull specific fields from high-volume log sources. For more information, see Work with extractors.
April 02, 2025
Medium Priority rule set
Google SecOps has introduced a new rule set, Medium Priority, in Applied Threat Intelligence (ATI). This rule set extends the capabilities of the ATI indicator prioritization model and expands prioritization logic to include commodity malware. For more information, see Applied Threat Intelligence priority overview.
March 27, 2025
Google SecOps is renaming Applied Threat Intelligence (ATI) rules to improve clarity and better reflect the associated UDM fields with each rule detection.
Currently, multiple underlying ATI rules with the same name can appear in the Google SecOps console, even though the rules apply to different UDM fields.
This change modifies the rule_name field in the customer metadata to specify the relevant UDM field for each rule.
For example:
Old rule name: ATI Active Breach Rule Match for File IoCs (SHA256)
New rule name: ATI Active Breach Rule Match for File IoCs (about.file.sha256)
March 26, 2025
The managed BigQuery resources and API keys associated with the chronicle-tla Google Cloud project will be fully deprecated by April 30, 2025. This applies to non-Enterprise+ customers only.
March 24, 2025
Updated retention logic for raw logs and UDM events
Google SecOps now retains raw logs based on the ingestion timestamp and UDM events based on the UDM event time.
March 18, 2025
Statistics and aggregations in UDM search using YARA-L 2.0
You can now run statistical queries on UDM events and group the results for analysis using YARA-L 2.0. You can use the statistical queries to track critical metrics, detect anomalous behavior, and analyze trends over time. For more information on how to run statistical queries on UDM events, see Statistics and aggregations in UDM search using YARA-L 2.0.
March 11, 2025
Within Curated Detections, the following rules have been added to the Cloud Hacktool rule pack for Google Cloud data in the "Broad" category. These rules are intended to detect the behavior of common open source hacktools.
- Collection: Set GCP Cloud Storage Bucket to Public
- Discovery: Cloud Run Enumeration
- Discovery: CloudFunctions Enumeration of GCP Cloud Functions
- Discovery: CloudKMS Enumeration of GCP Cloud KMS
- Discovery: CloudResourceManager Resource Manager Enumeration
- Discovery: Compute Enumeration
- Discovery: GCP Cloud IAM Enumeration
- Discovery: Secret Manager Cloud Secrets Enumeration
- Discovery: Storage Cloud Storage Enumeration
- Exfiltration: Download Cloud Function Code
- Exfiltration: Export a Compute Image Instance
- Persistence: Generate Signed URL for Modifying Cloud Function Code
- Privilege Escalation: Compute Set Instance or Project Metadata to Enable OS Login
URL indicators are now available for matching as part of Applied Threat Intelligence. For more information about Applied Threat Intelligence, see Applied Threat Intelligence overview.
March 10, 2025
The following rule has been removed from its associated rule pack in Curated Detections due to high alert volume across the Google SecOps customer base:
- Serverless Threats
- Potential Cryptomining Payload running in Cloud Run Service or Cloud Run Job
March 09, 2025
The session timeout duration is being extended from 3 hours to 8 hours. After 8 hours of activity, you are automatically logged out and required to sign in again. To prevent data loss, we recommend that you manually log out in advance if you anticipate being away from the platform for an extended period of time. This feature will be gradually rolled out starting March 17, 2025.
March 05, 2025
Gemini documentation summaries
You can use Gemini to answer questions about Google SecOps based on the documentation. Enter a prompt in the Gemini pane to request information about any aspect of how to use Google SecOps. Gemini generates a summary based on relevant documentation. This feature is in public preview.
For more information, see Gemini documentation summaries.
February 28, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have changed. Each parser is listed by product name and log_type value, if applicable. This list now includes both released default parsers and pending parser updates.
- 1Password Audit Events (
ONEPASSWORD_AUDIT_EVENTS) - AIX system (
AIX_SYSTEM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Alveo Risk Data Management (
ALVEO_RDM) - Amazon API Gateway (
AWS_API_GATEWAY) - Apache Tomcat (
TOMCAT) - Appian Cloud (
APPIAN_CLOUD) - Arcsight CEF (
ARCSIGHT_CEF) - Asset Panda (
ASSET_PANDA) - Aware Audit (
AWARE_AUDIT) - Aware Signals (
AWARE_SIGNALS) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS CloudWatch (
AWS_CLOUDWATCH) - AWS ECS Metrics (
AWS_ECS_METRICS) - AWS Elastic Load Balancer (
AWS_ELB) - AWS GuardDuty (
GUARDDUTY) - AWS Inspector (
AWS_INSPECTOR) - AWS Lambda Function (
AWS_LAMBDA_FUNCTION) - AWS RDS (
AWS_RDS) - AWS Redshift (
AWS_REDSHIFT) - AWS Route 53 DNS (
AWS_ROUTE_53) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS VPC Flow (
AWS_VPC_FLOW) - AWS WAF (
AWS_WAF) - Azure AD Directory Audit (
AZURE_AD_AUDIT) - Azure AD Organizational Context (
AZURE_AD_CONTEXT) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Firewall (
AZURE_FIREWALL) - Azure Key Vault logging (
AZURE_KEYVAULT_AUDIT) - Barracuda CloudGen Firewall (
BARRACUDA_CLOUDGEN_FIREWALL) - Barracuda WAF (
BARRACUDA_WAF) - BeyondTrust BeyondInsight (
BEYONDTRUST_BEYONDINSIGHT) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Broadcom Support Portal Audit Logs (
BROADCOM_SUPPORT_PORTAL) - Cato Networks (
CATO_NETWORKS) - Cequence Bot Defense (
CEQUENCE_BOT_DEFENSE) - Check Point (
CHECKPOINT_FIREWALL) - ChromeOS XDR (
CHROMEOS_XDR) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco EStreamer (
CISCO_ESTREAMER) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco FireSIGHT Management Center (
CISCO_FIRESIGHT) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco IronPort (
CISCO_IRONPORT) - Cisco ISE (
CISCO_ISE) - Cisco NX-OS (
CISCO_NX_OS) - Cisco Switch (
CISCO_SWITCH) - Cisco Umbrella Cloud Firewall (
UMBRELLA_FIREWALL) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco VPN (
CISCO_VPN) - Citrix Netscaler (
CITRIX_NETSCALER) - Citrix Storefront (
CITRIX_STOREFRONT) - Claroty Xdome (
CLAROTY_XDOME) - Cloud Audit Logs (
N/A) - Cloud Data Loss Prevention (
N/A) - Cloudflare Network Analytics (
CLOUDFLARE_NETWORK_ANALYTICS) - Cloudflare WAF (
CLOUDFLARE_WAF) - Cloudflare Warp (
CLOUDFLARE_WARP) - CommVault (
COMMVAULT) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - Crowdstrike Identity Protection Services (
CS_IDP) - CrushFTP (
CRUSHFTP) - Custom Application Access Logs (
CUSTOM_APPLICATION_ACCESS) - CyberArk Privileged Access Manager (PAM) (
CYBERARK_PAM) - Cybereason EDR (
CYBEREASON_EDR) - Cyolo Secure Remote Access for OT (
CYOLO_OT) - Datadog (
DATADOG) - Delinea Secret Server (
DELINEA_SECRET_SERVER) - Dell CyberSense (
DELL_CYBERSENSE) - Digicert (
DIGICERT) - Edgio WAF (
EDGIO_WAF) - Elastic Packet Beats (
ELASTIC_PACKETBEATS) - F5 ASM (
F5_ASM) - F5 DNS (
F5_DNS) - Forcepoint DLP (
FORCEPOINT_DLP) - Forcepoint NGFW (
FORCEPOINT_FIREWALL) - Forgerock OpenIdM (
FORGEROCK_OPENIDM) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet Fortimanager (
FORTINET_FORTIMANAGER) - Fortinet Web Application Firewall (
FORTINET_FORTIWEB) - GitHub (
GITHUB) - Gitlab (
GITLAB) - Harness IO (
HARNESS_IO) - Hashicorp Vault (
HASHICORP) - Hillstone Firewall (
HILLSTONE_NGFW) - Huawei Switches (
HUAWEI_SWITCH) - IBM Guardium (
GUARDIUM) - Imperva Database (
IMPERVA_DB) - Intel Endpoint Management Assistant (
INTEL_EMA) - JAMF Security Cloud (
JAMF_SECURITY_CLOUD) - JFrog Artifactory (
JFROG_ARTIFACTORY) - JumpCloud Directory Insights (
JUMPCLOUD_DIRECTORY_INSIGHTS) - Juniper (
JUNIPER_FIREWALL) - Kaspersky AV (
KASPERSKY_AV) - Kaspersky Endpoint (
KASPERSKY_ENDPOINT) - Kolide Endpoint Security (
KOLIDE) - Kubernetes Audit (
KUBERNETES_AUDIT) - Layer7 SiteMinder (
SITEMINDER_SSO) - Linux Auditing System (AuditD) (
AUDITD) - Looker Audit (
LOOKER_AUDIT) - ManageEngine ADAudit Plus (
ADAUDIT_PLUS) - ManageEngine ADManager Plus (
ADMANAGER_PLUS) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - Metabase (
METABASE) - Microsoft AD FS (
ADFS) - Microsoft Azure Activity (
AZURE_ACTIVITY) - Microsoft Azure NSG Flow (
AZURE_NSG_FLOW) - Microsoft CyberX (
CYBERX) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Defender for Identity (
MICROSOFT_DEFENDER_IDENTITY) - Microsoft Defender for Office 365 (
MICROSOFT_DEFENDER_MAIL) - Microsoft IIS (
IIS) - Microsoft PowerShell (
POWERSHELL) - Microsoft Sentinel (
MICROSOFT_SENTINEL) - Microsoft System Center Endpoint Protection (
MICROSOFT_SCEP) - Mikrotik Router (
MIKROTIK_ROUTER) - Mimecast (
MIMECAST_MAIL) - MISP Threat Intelligence (
MISP_IOC) - NetIQ eDirectory (
NETIQ_EDIRECTORY) - Netskope V2 (
NETSKOPE_ALERT_V2) - Nozomi Networks Scada Guardian (
NOZOMI_GUARDIAN) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Okta User Context (
OKTA_USER_CONTEXT) - One Identity Identity Manager (
ONE_IDENTITY_IDENTITY_MANAGER) - Oort Security Tool (
OORT) - Open Cybersecurity Schema Framework (OCSF) (
OCSF) - Open LDAP (
OPENLDAP) - Opnsense (
OPNSENSE) - Ops Genie (
OPS_GENIE) - Oracle (
ORACLE_DB) - Oracle Cloud Guard (
OCI_CLOUDGUARD) - Oracle Cloud Infrastructure Audit Logs (
OCI_AUDIT) - Orca Cloud Security Platform (
ORCA) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Access (
PAN_CASB) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Pharos (
PHAROS) - Privacy-I (
PRIVACY_I) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - Radware Web Application Firewall (
RADWARE_FIREWALL) - ReviveSec (
REVIVESEC) - Rubrik (
RUBRIK) - Salesforce (
SALESFORCE) - Sangfor Proxy (
SANGFOR_PROXY) - Security Command Center Posture Violation (
GCP_SECURITYCENTER_POSTURE_VIOLATION) - Security Command Center Threat (
N/A) - Security Command Center Toxic Combination (
GCP_SECURITYCENTER_TOXIC_COMBINATION) - ServiceNow CMDB (
SERVICENOW_CMDB) - Snare System Diagnostic Logs (
SNARE_SOLUTIONS) - Snipe-IT (
SNIPE_IT) - Snyk Group level audit/issues logs (
SNYK_ISSUES) - SonicWall (
SONIC_FIREWALL) - Sophos Central (
SOPHOS_CENTRAL) - Swimlane Platform (
SWIMLANE) - Symantec DLP (
SYMANTEC_DLP) - Symantec Event export (
SYMANTEC_EVENT_EXPORT) - Symantec Web Security Service (
SYMANTEC_WSS) - Tanium Question (
TANIUM_QUESTION) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - Teleport Access Plane (
TELEPORT_ACCESS_PLANE) - Tenable Active Directory Security (
TENABLE_ADS) - Tenable CSPM (
TENABLE_CSPM) - tenable.io (
TENABLE_IO) - Terraform Enterprise Audit (
TERRAFORM_ENTERPRISE) - Thinkst Canary (
THINKST_CANARY) - ThreatX WAF (
THREATX_WAF) - Trend Micro Email Security Advanced (
TRENDMICRO_EMAIL_SECURITY) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - TrendMicro Apex Central (
TRENDMICRO_APEX_CENTRAL) - TXOne Stellar (
TRENDMICRO_STELLAR) - UKG (
UKG) - Unix system (
NIX_SYSTEM) - UPX AntiDDoS (
UPX_ANTIDDOS) - VanDyke SFTP (
VANDYKE_SFTP) - Varonis (
VARONIS) - Vectra Alerts (
VECTRA_ALERTS) - Vectra Stream (
VECTRA_STREAM) - VMware AirWatch (
AIRWATCH) - Vmware Avinetworks iWAF (
VMWARE_AVINETWORKS_IWAF) - VMware ESXi (
VMWARE_ESX) - VMware Horizon (
VMWARE_HORIZON) - Watchguard EDR (
WATCHGUARD_EDR) - Windows Defender AV (
WINDOWS_DEFENDER_AV) - Windows DHCP (
WINDOWS_DHCP) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Windows Sysmon (
WINDOWS_SYSMON) - Workday Audit Logs (
WORKDAY_AUDIT) - Workday User Activity (
WORKDAY_USER_ACTIVITY) - WPEngine (
WPENGINE) - Zimperium (
ZIMPERIUM) - Zscaler (
ZSCALER_WEBPROXY) - ZScaler DNS (
ZSCALER_DNS) - Zscaler Internet Access Audit Logs (
ZSCALER_INTERNET_ACCESS) - ZScaler NGFW (
ZSCALER_FIREWALL)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, if applicable.
- Autodesk Cad Cam (
AUTODESK_CAD_CAM) - Azure Risk Events (
AZURE_RISK_EVENTS) - Azure Risky Users (
AZURE_RISKY_USERS) - Azure Service Principal Logins (
AZURE_SERVICE_PRINCIPAL_LOGINS) - Belden Switch (
BELDEN_SWITCH) - Blue Voyant (
BLUE_VOYANT) - Cisco NetFlow (
CISCO_NETFLOW) - Citrix Receiver (
CSG_CITRIX_RX) - Clavistier Firewall (
CLAVISTER_FIREWALL) - ClickHouse (
CLICKHOUSE) - Cloudflare Pageshield (
CLOUDFLARE_PAGESHIELD) - CrowdStrike DLP (
CROWDSTRIKE_DLP) - Crowdstrike Recon (TI) (
CROWDSTRIKE_RECON) - Cynerio Healthcare NDR (
CYNERIO_NDR_H) - Exterro FTK Central (
EXTERRO_FTK_CENTRAL) - Fortra Vulnerability Management (
FORTRA_VM) - GCP Cloud Asset Inventory (
GCP_CLOUD_ASSET_INVENTORY) - Health ISAC (
H_ISAC) - HP Router (
HP_ROUTER) - Huawei Wireless (
HUAWEI_WIRELESS) - IBM Sense (
IBM_SENSE) - IIJ_LanScope (
IIJ_LANSCOPE) - Joblogic (
JOBLOGIC) - OneIdentity Safeguard (
ONEIDENTITY_SAFEGUARD) - OpenText Cordy (
OPENTEXT_CORDY) - Pave (
PAVE) - Proofpoint Identity Threat Platform (
PROOFPOINT_IDENTITY_THREAT_PLATFORM) - Rapid Identity (
RAPID_IDENTITY) - Raven DB (
RAVEN_DB) - SolidServer (
SOLIDSERVER) - Spacelift (
SPACELIFT) - Trend Micro Vision One Activity (
TRENDMICRO_VISION_ONE_ACTIVITY) - Trend Micro Vision One Container Vulnerabilities (
TRENDMICRO_VISION_ONE_CONTAINER_VULNERABILITIES) - Trend Micro Vision One Detections (
TRENDMICRO_VISION_ONE_DETECTIONS) - Vectra XDR (
VECTRA_XDR) - Vicarious VRX Events (
VICARIUS_VRX_EVENTS) - WireGuard VPN Logs (
WIREGUARD_VPN) - Zero Networks (
ZERO_NETWORKS) - Zoho Assist (
ZOHO_ASSIST)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
February 20, 2025
Data tables are multicolumn data constructs that let you input your own data into Google SecOps. They can act as lookup tables with defined columns and the data stored in rows. You can create or import a data table to your Google SecOps account using the Google SecOps UI, the data tables API, or by using a YARA-L query in rules. This feature is in public preview.
Enhanced Cloud Threat Detections by adding three new rules to the AWS - GuardDuty rule set.
February 16, 2025
Manage user preferences
The ability to manage platform time zones has been relocated to the new User Preferences dialog, accessible from your avatar. In addition, a new accessibility option in the User Preferences dialog lets you define how long feedback messages remain on the screen.
For more information, refer to Configure user preferences (SIEM only).
February 12, 2025
The following parser documentation is now available:
Collect Proofpoint On-Demand logs
Collect Qualys asset context logs
Collect Qualys Continuous Monitoring logs
Collect Qualys Vulnerability Management logs
Collect Qualys Virtual Scanner logs
Collect ThreatConnect IOC logs
Collect Microsoft SQL Server logs
Collect Microsoft Azure Key Vault logging logs
Collect BeyondTrust Remote Support logs
Collect BMC Helix Discovery logs
Collect Brocade ServerIron logs
Collect Check Point firewall logs
Collect IBM Security Verify Access logs
Collect McAfee Firewall Enterprise logs
Collect Trend Micro Apex One logs
Collect Trend Micro Deep Security logs
Collect Versa Networks Secure Access Service Edge (SASE) logs
Collect VMware Networking and Security Virtualization (NSX) Manager logs
Collect Zscaler Cloud Access Security Broker (CASB) alert logs
February 11, 2025
The following is a correction to the release note published on December 22, 2024.
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have changed. Each parser is listed by product name and log_type value, if applicable. This list now includes both released default parsers and pending parser updates.
- Absolute Mobile Device Management (
ABSOLUTE) - Atlassian Cloud Admin Audit (
ATLASSIAN_AUDIT) - AWS VPC Flow (
AWS_VPC_FLOW) - Azure AD (
AZURE_AD) - Azure Application Gateway (
AZURE_GATEWAY) - Azure SQL (
AZURE_SQL) - Azure Storage Audit (
AZURE_STORAGE_AUDIT) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Check Point Harmony (
CHECKPOINT_HARMONY) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Meraki (
CISCO_MERAKI) - Cisco Router (
CISCO_ROUTER) - Cisco Umbrella SWG DLP (
CISCO_UMBRELLA_SWG_DLP) - Cisco VPN (
CISCO_VPN) - Citrix Netscaler (
CITRIX_NETSCALER) - Claroty Continuous Threat Detection (
CLAROTY_CTD) - Cloud Audit Logs (
N/A) - Cloud DNS (
N/A) - Code42 Incydr (
CODE42_INCYDR) - Colinet Trotta GAUS SEGUROS (
CT_GAUS_SEGUROS) - CrowdStrike Falcon (
CS_EDR) - Delinea Distributed Engine (
DELINEA_DISTRIBUTED_ENGINE) - Druva Backup (
DRUVA_BACKUP) - Duo Administrator Logs (
DUO_ADMIN) - Elastic Audit Beats (
ELASTIC_AUDITBEAT) - F5 BIGIP LTM (
F5_BIGIP_LTM) - Forcepoint NGFW (
FORCEPOINT_FIREWALL) - FortiGate (
FORTINET_FIREWALL) - GitHub (
GITHUB) - Google Cloud Identity Context (
CLOUD_IDENTITY_CONTEXT) - Guardicore Centra (
GUARDICORE_CENTRA) - HPE Aruba Networking Central (
ARUBA_CENTRAL) - Imperva Advanced Bot Protection (
IMPERVA_ABP) - Kubernetes Audit Azure (
KUBERNETES_AUDIT_AZURE) - Linux Auditing System (AuditD) (
AUDITD) - Maria Database (
MARIA_DB) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Opnsense (
OPNSENSE) - Oracle NetSuite (
ORACLE_NETSUITE) - Palo Alto Panorama (
PAN_PANORAMA) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - Ping One (
PING_ONE) - Proofpoint Observeit (
OBSERVEIT) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - QNAP Systems NAS (
QNAP_NAS) - Reserved LogType2 (
RESERVED_LOG_TYPE_2) - Salesforce (
SALESFORCE) - SAP Sybase Adaptive Server Enterprise Database (
SAP_ASE) - Sentinelone Alerts (
SENTINELONE_ALERT) - Snort (
SNORT_IDS) - Solaris system (
SOLARIS_SYSTEM) - Sourcefire (
SOURCEFIRE_IDS) - Suricata IDS (
SURICATA_IDS) - Symantec DLP (
SYMANTEC_DLP) - Symantec Event export (
SYMANTEC_EVENT_EXPORT) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - TrendMicro Apex Central (
TRENDMICRO_APEX_CENTRAL) - Twingate (
TWINGATE) - Wazuh (
WAZUH) - Windows DHCP (
WINDOWS_DHCP) - Windows Event (
WINEVTLOG) - Windows Network Policy Server (
WINDOWS_NET_POLICY_SERVER) - Windows Sysmon (
WINDOWS_SYSMON)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, if applicable.
- Addigy MDM (
ADDIGY_MDM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Anzenna (
ANZENNA) - AWS ECS Metrics (
AWS_ECS_METRICS) - Azure Log Analytics Workspace (
AZURE_LOG_ANALYTICS_WORKSPACE) - Blockdaemon API (
BLOCKDAEMON_API) - Chronicle Feed (
CHRONICLE_FEED) - Claroty xDome Secure Access (
CLAROTY_XDOME_SECURE_ACCESS) - Cloudflare Spectrum (
CLOUDFLARE_SPECTRUM) - Cloudsek Alerts (
CLOUDSEK_ALERTS) - CloudWaves Sensato Nightingale Honeypot (
SENSATO_HONEYPOT) - Docker Hub Activity (
DOCKER_HUB_ACTIVITY) - Fortinet FortiDDoS (
FORTINET_FORTIDDOS) - Honeywell Cyber Insights (
HONEYWELL_CYBERINSIGHTS) - IPFire (
IPFIRE) - Jamf Connect (
JAMF_CONNECT) - KnowBe4 Audit Log (
KNOWBE4) - LogicGate (
LOGICGATE) - ManageEngine NCM (
MANAGEENGINE_NCM) - Microsoft Dotnet Log Files (
MICROSOFT_DOTNET) - Nessus Network Monitor (
NESSUS_NETWORK_MONITOR) - Netography Fusion (
NETOGRAPHY_FUSION) - Netwrix StealthAudit (
NETWRIX_STEALTHAUDIT) - Oomnitza (
OOMNITZA) - Open CTI Platform (
OPENCTI) - Oracle EBS (
ORACLE_EBS) - Oracle Zero Data Loss Recovery Appliance (
ORACLE_ZDLRA) - PhishAlarm (
PHISHALARM) - Savvy Security (
SAVVY_SECURITY) - Symantec Security Analytics (
SYMANTEC_SA) - Venafi ZTPKI (
VENAFI_ZTPKI)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
February 06, 2025
The collector ID representing Google Cloud direct ingestion in the Cloud Monitoring metrics and BigQuery has changed from dddddddd-dddd-dddd-dddd-dddddddddddd to aaaa3333-aaaa-3333-aaaa-3333aaaa3333.
For a complete list of updated collector IDs used for ingestion metrics, see Use Cloud Monitoring for ingestion notifications.
February 05, 2025
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have changed. Each parser is listed by product name and log_type value, if applicable. This list now includes both released default parsers and pending parser updates.
- A10 Load Balancer (
A10_LOAD_BALANCER) - Akamai Enterprise Application Access (
AKAMAI_EAA) - Akamai WAF (
AKAMAI_WAF) - Apache (
APACHE) - Apache Tomcat (
TOMCAT) - AppOmni (
APPOMNI) - Arcsight CEF (
ARCSIGHT_CEF) - Aruba (
ARUBA_WIRELESS) - Aruba Airwave (
ARUBA_AIRWAVE) - Atlassian Cloud Admin Audit (
ATLASSIAN_AUDIT) - Attivo Networks (
ATTIVO) - Auth0 (
AUTH_ZERO) - Avigilon Access Logs (
AVIGILON_ACCESS_LOGS) - AWS Cloudtrail (
AWS_CLOUDTRAIL) - AWS GuardDuty (
GUARDDUTY) - AWS RDS (
AWS_RDS) - AWS Security Hub (
AWS_SECURITY_HUB) - AWS VPC Flow (
AWS_VPC_FLOW) - Azure AD (
AZURE_AD) - Azure Application Gateway (
AZURE_GATEWAY) - Azure Cosmos DB (
AZURE_COSMOS_DB) - Azure Firewall (
AZURE_FIREWALL) - Azure Front Door (
AZURE_FRONT_DOOR) - Bindplane Agent (
BINDPLANE_AGENT) - BloxOne Threat Defense (
BLOXONE) - Blue Coat Proxy (
BLUECOAT_WEBPROXY) - Cato Networks (
CATO_NETWORKS) - Check Point (
CHECKPOINT_FIREWALL) - Check Point Harmony (
CHECKPOINT_HARMONY) - CircleCI (
CIRCLECI) - Cisco AMP (
CISCO_AMP) - Cisco Application Centric Infrastructure (
CISCO_ACI) - Cisco ASA (
CISCO_ASA_FIREWALL) - Cisco Email Security (
CISCO_EMAIL_SECURITY) - Cisco Firepower NGFW (
CISCO_FIREPOWER_FIREWALL) - Cisco Internetwork Operating System (
CISCO_IOS) - Cisco ISE (
CISCO_ISE) - Cisco NX-OS (
CISCO_NX_OS) - Cisco Umbrella DNS (
UMBRELLA_DNS) - Cisco Umbrella Web Proxy (
UMBRELLA_WEBPROXY) - Cisco vManage SD-WAN (
CISCO_SDWAN) - Cisco VPN (
CISCO_VPN) - Citrix Netscaler (
CITRIX_NETSCALER) - Cloudflare (
CLOUDFLARE) - Cloudflare Warp (
CLOUDFLARE_WARP) - CrowdStrike Detection Monitoring (
CS_DETECTS) - CrowdStrike Falcon (
CS_EDR) - CrowdStrike Falcon Stream (
CS_STREAM) - Crowdstrike Identity Protection Services (
CS_IDP) - Dell CyberSense (
DELL_CYBERSENSE) - Duo Administrator Logs (
DUO_ADMIN) - Elastic Packet Beats (
ELASTIC_PACKETBEATS) - Elastic Windows Event Log Beats (
ELASTIC_WINLOGBEAT) - ExtraHop RevealX (
EXTRAHOP) - F5 ASM (
F5_ASM) - F5 BIGIP LTM (
F5_BIGIP_LTM) - F5 Distributed Cloud Services (
F5_DCS) - Fastly CDN (
FASTLY_CDN) - Forcepoint DLP (
FORCEPOINT_DLP) - Forcepoint Proxy (
FORCEPOINT_WEBPROXY) - FortiGate (
FORTINET_FIREWALL) - Fortinet FortiAnalyzer (
FORTINET_FORTIANALYZER) - Fortinet FortiClient (
FORTINET_FORTICLIENT) - Fortinet FortiDDoS (
FORTINET_FORTIDDOS) - Fortinet FortiEDR (
FORTINET_FORTIEDR) - Fortinet Proxy (
FORTINET_WEBPROXY) - GitHub (
GITHUB) - Gitlab (
GITLAB) - HP Linux (
HP_LINUX) - IBM Guardium (
GUARDIUM) - Imperva (
IMPERVA_WAF) - Juniper MX Router (
JUNIPER_MX) - Kemp Load Balancer (
KEMP_LOADBALANCER) - Linkshadow NDR (
LINKSHADOW_NDR) - Linux Auditing System (AuditD) (
AUDITD) - McAfee Web Gateway (
MCAFEE_WEBPROXY) - McAfee Web Protection (
MCAFEE_WEB_PROTECTION) - Micro Focus iManager (
MICROFOCUS_IMANAGER) - Microsoft Azure NSG Flow (
AZURE_NSG_FLOW) - Microsoft Azure Resource (
AZURE_RESOURCE_LOGS) - Microsoft CyberX (
CYBERX) - Microsoft Defender for Endpoint (
MICROSOFT_DEFENDER_ENDPOINT) - Microsoft Dynamics 365 User Activity (
MICROSOFT_DYNAMICS_365) - Microsoft Graph API Alerts (
MICROSOFT_GRAPH_ALERT) - Microsoft Netlogon (
MICROSOFT_NETLOGON) - Microsoft PowerShell (
POWERSHELL) - Microsoft System Center Endpoint Protection (
MICROSOFT_SCEP) - Mikrotik Router (
MIKROTIK_ROUTER) - Mimecast URL Logs (
MIMECAST_URL_LOGS) - Office 365 (
OFFICE_365) - Okta (
OKTA) - Okta User Context (
OKTA_USER_CONTEXT) - Open LDAP (
OPENLDAP) - Open Policy Agent (
OPA) - Oracle (
ORACLE_DB) - Oracle Cloud Guard (
OCI_CLOUDGUARD) - Orca Cloud Security Platform (
ORCA) - Palo Alto Cortex XDR Alerts (
CORTEX_XDR) - Palo Alto Networks Firewall (
PAN_FIREWALL) - Palo Alto Networks IoT Security (
PAN_IOT) - Palo Alto Prisma Cloud Alert payload (
PAN_PRISMA_CA) - ProFTPD (
PROFTPD) - Proofpoint Observeit (
OBSERVEIT) - Proofpoint On Demand (
PROOFPOINT_ON_DEMAND) - ProofPoint Secure Email Relay (
PROOFPOINT_SER) - Proofpoint Tap Alerts (
PROOFPOINT_MAIL) - Proofpoint Threat Response (
PROOFPOINT_TRAP) - RSA SecurID Access Identity Router (
RSA_SECURID) - Rubrik (
RUBRIK) - Salesforce (
SALESFORCE) - Security Command Center Threat (
N/A) - Sentry (
SENTRY) - ServiceNow Audit (
SERVICENOW_AUDIT) - ServiceNow CMDB (
SERVICENOW_CMDB) - Smartsheet (
SMARTSHEET) - Snare System Diagnostic Logs (
SNARE_SOLUTIONS) - Snowflake (
SNOWFLAKE) - Solaris system (
SOLARIS_SYSTEM) - SonicWall (
SONIC_FIREWALL) - Sophos Central (
SOPHOS_CENTRAL) - Sophos UTM (
SOPHOS_UTM) - Sourcefire (
SOURCEFIRE_IDS) - Suricata EVE (
SURICATA_EVE) - Symantec DLP (
SYMANTEC_DLP) - Symantec Endpoint Protection (
SEP) - Symantec Event export (
SYMANTEC_EVENT_EXPORT) - Symantec Web Security Service (
SYMANTEC_WSS) - Sysdig (
SYSDIG) - Tableau (
TABLEAU) - Tanium Asset (
TANIUM_ASSET) - Tanium Threat Response (
TANIUM_THREAT_RESPONSE) - tenable.io (
TENABLE_IO) - Trend Micro (
TIPPING_POINT) - Trend Micro Deep Security (
TRENDMICRO_DEEP_SECURITY) - Trend Micro Vision One (
TRENDMICRO_VISION_ONE) - TrendMicro Deep Discovery Inspector (
TRENDMICRO_DDI) - UberAgent (
UBERAGENT) - Unix system (
NIX_SYSTEM) - Vectra Detect (
VECTRA_DETECT) - Vectra Stream (
VECTRA_STREAM) - Venafi ZTPKI (
VENAFI_ZTPKI) - Vercel WAF (
VERCEL_WAF) - Virtru Email Encryption (
VIRTRU_EMAIL_ENCRYPTION) - WatchGuard (
WATCHGUARD) - Wazuh (
WAZUH) - Windows DNS (
WINDOWS_DNS) - Windows Event (
WINEVTLOG) - Windows Event (XML) (
WINEVTLOG_XML) - Windows Network Policy Server (
WINDOWS_NET_POLICY_SERVER) - Zendesk CRM (
ZENDESK_CRM) - ZeroFox Platform (
ZEROFOX_PLATFORM) - Zimperium (
ZIMPERIUM) - Zoom Operation Logs (
ZOOM_OPERATION_LOGS) - Zscaler (
ZSCALER_WEBPROXY) - Zscaler Internet Access Audit Logs (
ZSCALER_INTERNET_ACCESS) - Zscaler Secure Private Access Audit Logs (
ZSCALER_ZPA_AUDIT)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, if applicable.
- Arcon PAM (
ARCON_PAM) - Azure VNET Flow (
AZURE_VNET_FLOW) - Cameyo Activity Logs (
CAMEYO_ACTIVITY_LOGS) - ChromeOS XDR (
CHROMEOS_XDR) - Cisco Vulnerability Management (
CISCO_VULNERABILITY_MANAGEMENT) - Cloudflare Network Analytics (
CLOUDFLARE_NETWORK_ANALYTICS) - Draytek Router (
DRAYTEK_ROUTER) - FA Solutions (
FA_SOLUTIONS) - Files dot com (
FILES_DOT_COM) - Fortinet ADC (
FORTINET_ADC) - FoxPass Audit Logs (
FOXPASS_AUDIT_LOGS) - Front (
FRONT) - Ghangor DLP (
GHANGOR_DLP) - Hillstone Firewall (
HILLSTONE_NGFW) - Hoxhunt (
HOXHUNT) - Huawei NextGen Firewall (
HUAWEI_FIREWALL) - Huawei Fusion Sphere Hypervisor (
HUAWEI_FUSIONSPHERE) - IBM Security Verify Access (
IBM_SVA) - Indusface WAF (
INDUSFACE_WAF) - Informatica (
INFORMATICA) - Informatica Powercenter (
INFORMATICA_POWERCENTER) - Intel Endpoint Management Assistant (
INTEL_EMA) - Jamf Protect Telemetry V2 (
JAMF_TELEMETRY_V2) - JiranSecurity MailScreen (
JIRANSECURITY_MAILSCREEN) - Juniper SSR Conductor (
JUNIPER_SSR_CONDUCTOR) - Metabase (
METABASE) - Netlify Log Drains (
NETLIFY_LOGDRAINS) - Pingcap TIDB (
PINGCAP_TIDB) - PingOne Advanced Identity Cloud (
PINGONE_AIC) - PingOne Protect (
PINGONE_PROTECT) - Privacy-I (
PRIVACY_I) - ReviveSec (
REVIVESEC) - Sangfor Proxy (
SANGFOR_PROXY) - SoftEther VPN (
SOFTETHER_VPN) - Tehtris EDR (
TEHTRIS_EDR) - TrendMicro Cloud Email Gateway Protection (
TRENDMICRO_CLOUD_EMAIL_GATEWAY_PROTECTION) - VMware VeloCloud SD-WAN (
VELOCLOUD_SDWAN) - Wing Security (
WING_SECURITY)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
January 28, 2025
Environment groups
This feature lets you group environments into logical categories, making it easier to manage your company or your customers as an MSSP.
You can use environment groups for adding users, mapping IdP user groups, creating new playbooks, and applying case filters on the platform.
For more information about how to create groups of environments, see Create environment groups.
Adding individual emails to IdP group mapping page
Customers who use Cloud Identity Provider can map individual user emails on the IdP group mapping page.
Added instructions on how to add SIEM-only or SOAR-only users to Google SecOps
For details about how to grant permission to specific users to use only the SIEM features in Google SecOps or only the SOAR features of Google SecOps, see Add SIEM or SOAR users.
January 26, 2025
Security Enhancement
As of February 10, 2025, concurrent logins to Google SecOps with multiple user accounts using the same browser profile will no longer be supported. Use separate browser profiles or an incognito/private window for each account.
January 21, 2025
The following rules have been moved from "Precise" to "Broad" in their associated rule packs due to high alert volume across the Google SecOps customer base.
- GCP Workspace Data Exfil Drive:
- Suspicious Workspace Actions Observed after a Successful Suspicious Login
- GCP Suspicious Infrastructure Change:
- Replacement of Existing Compute Machine Image
- Replacement of Existing Compute Disk
- GCP Cloud SQL Ransom:
- Base64 Encoded Cloud SQL Command
- CIDR SCC Persistence:
- SCC: Persistence: New API Method
- SCC: Persistence: IAM Anomalous Grant
- SCC: Persistence: GCE Admin Added SSH Key
- CIDR SCC Malware:
- SCC: Added Library Loaded
- SCC: Added Binary Executed
- CIDR SCC Cloud IDS Low:
- SCC: Cloud IDS: Low Threat Finding
- CIDR SCC Cloud Armor Medium:
- SCC: Cloud Armor: Medium - Increasing Deny Ratio
- SCC: Cloud Armor: Medium - Allowed Traffic Spike
- Azure Identity:
- Azure External User Invitation
- Azure Defender for Cloud Windows and Linux VM:
- Azure Defender for Cloud: Anonymous IP access
- AWS GuardDuty Discovery:
- AWS GuardDuty: Recon:EC2/PortProbeUnprotectedPort
January 19, 2025
The individual parser documents have been put into one page with an easy-to-use search bar. This reorganization helps you find all the information you need in one place.
January 14, 2025
The following rules have been removed from their associated rule packs in Curated Detections due to high alert volume across the Google SecOps customer base:
- Cloud Threats - CDIR SCC Enhanced Defense Evasion Alerts:
- SCC: Modify VPC Service Control with GCE Activity from the Restricted Resource
- SCC: Modify VPC Service Control with Activity from the Restricted Service
- Linux Threats - OS Privilege Escalation Tools:
- Sensitive File Discovery
- Last Login Users
- Whoami Commands
- Windows Threats - Initial Access:
- NetLogon AD System Event
- Risk Analytics for UEBA - Login to an Application Never Before Seen for a User Group:
- First Time User Login Activity to Application for Manager Peer Group
- Risk Analytics for UEBA - Login from Country Never Before Seen for a User Group:
- First Time User Login Activity from Country for Manager Peer Group
The rule "SCC: Unexpected Child Shell" has been moved from the rule pack "Cloud Threats - CDIR SCC Enhanced Malware Alerts" to "Cloud Threats - CDIR SCC Enhanced Execution Alerts"
January 07, 2025
The following parser documentation is now available:
Collect Microsoft Defender for Endpoint logs
Collect Zscaler Internet Access logs
Collect Linux auditd and AIX systems logs
Collect CloudPassage Halo logs
Collect JFrog Artifactory logs
Collect Apple macOS syslog data
Collect Netskope web proxy logs
Collect OPNsense firewall logs
Collect Rapid7 InsightIDR logs
December 27, 2024
Google SecOps has added a new rule set to Applied Threat Intelligence (ATI), called Inbound IP Address Authentication, that identifies IP addresses that are authenticating to local infrastructure in an inbound network direction. For more information, see Applied Threat Intelligence priority overview.
December 23, 2024
The following parser documentation is now available:
Collect CrowdStrike Detection logs
Collect Microsoft Azure AD Audit logs
Collect Microsoft Azure AD Context logs
Ingest Chrome Enterprise Premium data to Google Security Operations
Collect Atlassian Bitbucket logs
Collect Azure DevOps audit logs
Collect Microsoft Defender for Cloud alert logs
Collect Microsoft Graph activity logs
Collect Microsoft Sentinel logs
Collect Palo Alto Networks IOC logs
Collect Palo Alto Prisma Cloud alert logs
Collect ServiceNow Security logs
Collect Lacework Cloud Security logs
Collect Netskope alert logs v1
Collect Netskope alert logs v2
December 22, 2024
This release note has been updated. Refer to the entry for February 11, 2025 for the latest information.
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have changed. Each parser is listed by product name and log_type value, if applicable. This list now includes both released default parsers and pending parser updates.
- Absolute Mobile Device Management (
Mobile Device Management) - Atlassian Cloud Admin Audit (
Audit) - AWS VPC Flow (
AWS Specific) - Azure AD (
LDAP) - Azure Application Gateway (
GATEWAY) - Azure SQL (
Database) - Azure Storage Audit (
Storage) - Blue Coat Proxy (
Web Proxy) - Check Point Harmony (
Remote Access Tools) - Cisco ASA (
firewall) - Cisco Firepower NGFW (
Firewall) - Cisco Meraki (
Wireless) - Cisco Router (
Switches, Routers) - Cisco Umbrella SWG DLP (
DLP) - Cisco VPN (
VPN) - Citrix Netscaler (
Load Balancer, Traffic Shaper, ADC) - Claroty Continuous Threat Detection (
IoT) - Cloud Audit Logs (
Google Cloud Specific) - Cloud DNS (
Google Cloud Specific) - Code42 Incydr (
Data loss prevention (DLP)) - Colinet Trotta GAUS SEGUROS (
Alert) - CrowdStrike Falcon (
EDR) - Delinea Distributed Engine (
Application server logs) - Druva Backup (
Security) - Duo Administrator Logs (
Authentication) - Elastic Audit Beats (
ALERTING) - F5 BIGIP LTM (
Load Balancer, Traffic Shaper, ADC) - Forcepoint NGFW (
Network) - FortiGate (
Firewall) - GitHub (
SaaS Application) - Google Cloud Identity Context (
Identity and Access Management) - Guardicore Centra (
Deception Software) - HPE Aruba Networking Central (
Data Security) - Imperva Advanced Bot Protection (
Bot Protection) - Kubernetes Audit Azure (
Log Aggregator) - Linux Auditing System (AuditD) (
OS) - Maria Database (
Database) - Microsoft Defender for Endpoint (
EDR) - Opnsense (
Firewall and Routing Platform) - Oracle NetSuite (
CASB) - Palo Alto Panorama (
Firewall) - Palo Alto Prisma Cloud Alert payload (
Cloud Security) - Ping One (
NA) - Proofpoint Observeit (
Email Server) - Proofpoint Threat Response (
Email Server) - QNAP Systems NAS (
Storage solutions) - Reserved LogType2 (
LDAP) - Salesforce (
SaaS Application) - SAP Sybase Adaptive Server Enterprise Database (
Database) - Sentinelone Alerts (
Endpoint Security) - Snort (
IDS/IPS) - Solaris system (
OS) - Sourcefire (
IDS/IPS) - Suricata IDS (
IDS/IPS) - Symantec DLP (
DLP) - Symantec Event export (
SEP) - Trend Micro Vision One (
AV and endpoint logs) - TrendMicro Apex Central (
Endpoint) - Twingate (
VPN) - Wazuh (
Log Aggregator) - Windows DHCP (
DHCP) - Windows Event (
Endpoint) - Windows Network Policy Server (
Authentication) - Windows Sysmon (
DNS)
The following log types were added without a default parser. Each parser is listed by product name and log_type value, if applicable.
- Addigy MDM (
ADDIGY_MDM) - Akamai DataStream 2 (
AKAMAI_DATASTREAM_2) - Anzenna (
ANZENNA) - AWS ECS Metrics (
AWS_ECS_METRICS) - Azure Log Analytics Workspace (
AZURE_LOG_ANALYTICS_WORKSPACE) - Blockdaemon API (
BLOCKDAEMON_API) - Chronicle Feed (
CHRONICLE_FEED) - Claroty xDome Secure Access (
CLAROTY_XDOME_SECURE_ACCESS) - Cloudflare Spectrum (
CLOUDFLARE_SPECTRUM) - Cloudsek Alerts (
CLOUDSEK_ALERTS) - CloudWaves Sensato Nightingale Honeypot (
SENSATO_HONEYPOT) - Docker Hub Activity (
DOCKER_HUB_ACTIVITY) - Fortinet FortiDDoS (
FORTINET_FORTIDDOS) - Honeywell Cyber Insights (
HONEYWELL_CYBERINSIGHTS) - IPFire (
IPFIRE) - Jamf Connect (
JAMF_CONNECT) - KnowBe4 Audit Log (
KNOWBE4) - LogicGate (
LOGICGATE) - ManageEngine NCM (
MANAGEENGINE_NCM) - Microsoft Dotnet Log Files (
MICROSOFT_DOTNET) - Nessus Network Monitor (
NESSUS_NETWORK_MONITOR) - Netography Fusion (
NETOGRAPHY_FUSION) - Netwrix StealthAudit (
NETWRIX_STEALTHAUDIT) - Oomnitza (
OOMNITZA) - Open CTI Platform (
OPENCTI) - Oracle EBS (
ORACLE_EBS) - Oracle Zero Data Loss Recovery Appliance (
ORACLE_ZDLRA) - PhishAlarm (
PHISHALARM) - Savvy Security (
SAVVY_SECURITY) - Symantec Security Analytics (
SYMANTEC_SA) - Venafi ZTPKI (
VENAFI_ZTPKI)
For a list of supported log types and details about default parser changes, see Supported log types and default parsers.
December 17, 2024
Looker dashboard updates
The following changes have been made to the Looker dashboards in Google SecOps:
All dashboards have been moved to the
ingestion_metrics_connectorexplore.The
ingestion_stats,ingestion_metric_with_ingestion_statsandingestion_metricsexplores are no longer supported.The
total_entry_numberandtotal_size_bytesfields are defined in the new explore and used to query the log count and log volume for the Google SecOps Ingestion API. For more information, see the Ingestion metrics field reference for dashboards.The default dashboards for Context aware detections risk and Cloud detection and response overview have been updated to use a different field for the risk score. It was
rule_detections.outcomes['risk_score']and is nowrule_detections.risk_score. This change aligns the risk score in the Google SecOps dashboards to the risk score used in the Google SecOps user interface.The
severityfield in the Rules and detections default Dashboard has been updated so that it would show the severity for both Curated Detections and custom rules.
December 09, 2024
Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.
The following supported default parsers have changed. Each parser is listed by product name and log_type value, if applicable. This list now includes both released default parsers and pending parser updates.
- 1Password Audit Events (
Identity and Access Management) - Advanced Intrusion Detection Environment (
Alert) - Airlock Digital Application Allowlisting (
Application Whitelisting) - Akamai DNS (
DNS) - Amazon VPC Transit Gateway Flow Logs (
Network) - Apache Tomcat (
Web server) - Appian Cloud (
Collaboration log types) - AppOmni (
SAAS Security Application) - Aruba Switch (
Network Infrastructure) - Auth0 (
Authentication log) - AWS Cloudtrail (
Cloud Log Aggregator) - AWS CloudWatch (
Cloud service monitoring) - AWS Elastic Load Balancer (
AWS Specific) - AWS GuardDuty (
IDS/IPS) - AWS Network Firewall (
Firewall) - AWS RDS (
Database) - AWS Route 53 DNS (
AWS Specific) - AWS S3 Server Access (
AWS Specific) - AWS VPC Flow (
AWS Specific) - Azure AD Directory Audit (
Audit) - Azure AD Organizational Context (
LDAP) - Azure API Management (
Schema) - Azure App Service (
SAAS) - Azure Application Gateway (
GATEWAY) - Azure Firewall (
Azure Firewall Application Rule) - Azure Key Vault logging (
Audit) - Azure SQL (
Database) - Barracuda WAF (
Firewall) - Barracuda Web Filter (
Webfilter) - BeyondTrust BeyondInsight (
Privileged Account Activity) - BeyondTrust Endpoint Privilege Management (
Privileged Account Activity) - BIND (
DNS) - BloxOne Threat Defense (
DNS) - Blue Coat Proxy (
Web Proxy) - Cato Networks (
NDR) - Check Point (
Firewall) - Ciena Router logs (
Application server logs) - Cisco ACS (
Authentication) - Cisco APIC (
Software-defined Networking (SDN)) - Cisco Call Manager (
NETWORKING) - Cisco DNA Center Platform (
Network Management and Optimization) - Cisco Email Security (
Email Server) - Cisco EStreamer (
Network Monitoring) - Cisco Firepower NGFW (
Firewall) - Cisco FireSIGHT Management Center (
SaaS Application) - Cisco Internetwork Operating System (
Network Infrastructure) - Cisco ISE (
Identity and Access Management) - Cisco Router (
Switches, Routers) - Cisco Secure Workload (
AV and Endpoint) - Cisco Stealthwatch (
Log Aggregator) - Cisco Switch (
Switches, Routers) - Cisco TACACS+ (
Authentication) - Cisco VPN (
VPN) - Citrix Netscaler (
Load Balancer, Traffic Shaper, ADC) - Claroty Continuous Threat Detection (
IoT) - Cloudflare (
SaaS Application) - Colinet Trotta GAUS SEGUROS (
Alert) - CrowdStrike Detection Monitoring (
EDR) - CrowdStrike Falcon (
EDR) - CrowdStrike Falcon Stream (
Alerts) - CrowdStrike Filevantage (
IT infrastructure) - Cyber 2.0 IDS (
IDS) - Cyberark Privilege Cloud (
Identity & Access Management) - CyberArk Privileged Access Manager (PAM) (
CyberArk Privileged Access Manager) - Cybereason EDR (
EDR) - Darktrace (
NDR) - Dell CyberSense (
Data Security) - Dell EMC PowerStore (
DATA STORAGE) - Druva Backup (
Security) - Duo Administrator Logs (
Authentication) - Duo Auth (
Authentication) - EfficientIP DDI (
Network) - ExtraHop RevealX (
Firewall IDS/IPS) - F5 Advanced Firewall Management (
Firewall) - F5 ASM (
WAF) - F5 BIGIP LTM (
Load Balancer, Traffic Shaper, ADC) - F5 VPN (
VPN) - FingerprintJS (
Vulnerability scanners) - FireEye eMPS (
Email server log types.) - FireEye HX (
EDR) - Forcepoint DLP (
Forcepoint DLP) - Forcepoint NGFW (
Network) - Forcepoint Proxy (
Web Proxy) - Forescout NAC (
NAC) - ForgeRock OpenAM (
Identity and Access Management) - Forgerock OpenIdM (
DATA SECURITY) - FortiGate (
Firewall) - Fortinet FortiAnalyzer (
Fortinet FortiAnalyzer) - Fortinet Switch (
Switches and Routers) - GitHub (
SaaS Application) - Guardicore Centra (
Deception Software) - Hashicorp Vault (
Privileged Account Activity) - HCNET Account Adapter Plus (
DHCP) - IBM MaaS360 (
Security) - IBM Security Access Manager (
WAF) - IBM z/OS (
OS) - Illumio Core (
Policy Management) - Imperva (
WAF) - Imperva Advanced Bot Protection (
Bot Protection) - Imperva Attack Analytics (
WAF) - Ingrian Networks DataSecure Appliance (
System and Audit Logs) - Intel 471 Malware Intelligence (``)
- ISC DHCP (
DHCP) - Jenkins (
Automation and DevOps) - Journald (
Log Aggregation and SIEM Systems) - Juniper (
Firewall) - Juniper Mist (
Network Management and Optimization software) - Juniper MX Router (
Routers and Switches) - Keeper Enterprise Security (
Security) - Kubernetes Audit Azure (
Log Aggregator) - Lacework Cloud Security (
Cloud Security) - Lenel Onguard Badge Management (
Access Control System) - Linux Auditing System (AuditD) (
OS) - Linux Sysmon (