Deprecated: Function get_magic_quotes_gpc() is deprecated in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 99

Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 619

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 832

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839

Warning: Cannot modify header information - headers already sent by (output started at /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php:99) in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 839
tag:google.com,2016:chronicle-release-notes Google SecOps SIEM - Release notes Google Cloud Platform 2025-09-23T00:00:00-07:00 September 23, 2025 tag:google.com,2016:chronicle-release-notes#September_23_2025 2025-09-23T00:00:00-07:00 Changed

Transport-layer migration for third-party API feeds

Google SecOps is migrating the transport layer for third-party API feeds to a new platform to improve performance and reliability. This migration will be completed in phases and is expected to finish by the end of October 2025. The migration should not impact any existing or new, third-party API feeds. If you experience any unexpected issues with your feeds during the migration, contact your Google SecOps representative.

]]>
September 17, 2025 tag:google.com,2016:chronicle-release-notes#September_17_2025 2025-09-17T00:00:00-07:00 Feature

SentinelOneV2: Version 41.0

  • The following new action has been added:

    • Update Alert
  • The following new connector has been added:

    • SentinelOne - Alert Connector
  • A new predefined widget has been added to the following action:

    • Update Alert

Feature

Google Threat Intelligence: Version 4.0

  • The following new action has been added:

    • Set DTM Alert Analysis

Feature

Palo Alto Cortex XDR: Version 18.0

  • The following new actions have been added:

    • Add Comment To Incident

    • Execute XQL Search

    • Get Incident Details

Changed

Google Threat Intelligence: Version 4.0

  • Updated the processing of the threat actor entity in the following action:

    • Enrich Entities
  • Updated the predefined widget in the following actions:

    (REGRESSIVE) The widget now works with GTI information. To see the changes, the widget must be re-added to the existing views in playbooks.

    • Enrich Entities

    • Enrich IOCs

  • Added JSON samples to the following action:

    • Enrich Entities

Changed

Trend Vision One: Version 6.0

  • Added support for Agent UUID in the following actions:

    • Enrich Entities

    • Execute Custom Script

    • Isolate Endpoint

    • Unisolate Endpoint

Changed

Splunk: Version 58.0

  • Updated the alert processing logic in the following connector:

    • Splunk ES - Notable Events Connector

Changed

Jira: Version 48.0

  • Integration: Updated the SDK version.

Changed

Added the ability to modify the API Root and Login API Root in the following integrations:

  • Azure Active Directory: Version 18.0

  • Azure AD Identity Protection: Version 7.0

  • Microsoft Teams: Version 28.0

Changed

Vertex AI: Version 4.0

  • Integration: Increased the default timeout for API requests.

Changed

Microsoft Azure Sentinel: Version 56.0

  • Updated mapping for the ScheduledAlert event types in the following connector:

    • Microsoft Azure Sentinel Incident Connector v2
]]>
September 16, 2025 tag:google.com,2016:chronicle-release-notes#September_16_2025 2025-09-16T00:00:00-07:00 Announcement

Migrate SOAR to Google Cloud

We're actively migrating all SOAR customers and partners to their respective Google Cloud projects. This migration unifies your SOAR experience with your existing cloud environment. For more information, see SOAR migration overview and FAQ.

Announcement

Migrate SOAR to Google Cloud

All customers and partners are being migrated from SOAR to Google Cloud. For more information, see SOAR migration overview and FAQ.

Announcement

Release 6.3.62 is being rolled out to the first phase of regions as listed here.

This release contains internal and customer bug fixes.

]]>
September 15, 2025 tag:google.com,2016:chronicle-release-notes#September_15_2025 2025-09-15T00:00:00-07:00 Announcement

Release 6.3.61 is now available for all regions.

]]>
September 11, 2025 tag:google.com,2016:chronicle-release-notes#September_11_2025 2025-09-11T00:00:00-07:00 Feature

SecOps Labs

This feature is in preview.

You can now configure and run Google SecOps Gemini and other intelligence experiments without disrupting your existing production systems—and benefit from their output. The experiments comply with the Role-Based Access Control (RBAC) configuration of your environment, and they have streamlined configurations with clear actionable results and output.

For details, see Use Gemini and other experiments in Google SecOps.

]]>
September 10, 2025 tag:google.com,2016:chronicle-release-notes#September_10_2025 2025-09-10T00:00:00-07:00 Feature

View data retention start date

You can now view the start date for your account's data retention period. A new, read-only page, Data Retention, is available under SIEM Settings. This page also shows the start date for your Google SecOps account's data retention period.

For more information, see View data retention in your Google SecOps account.

Feature

View data retention start date

You can now view the start date for your account's data retention period. A new, read-only page, Data Retention, is available under SIEM Settings. This page also shows the start date for your Google SecOps account's data retention period.

For more information, see View data retention in your Google SecOps account.

]]>
September 08, 2025 tag:google.com,2016:chronicle-release-notes#September_08_2025 2025-09-08T00:00:00-07:00 Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Collect Akamai Cloud Monitor logs
Collect Akamai DataStream 2 logs
Collect Aware audit logs
Collect AWS API Gateway access logs
Collect AWS VPC Transit Gateway flow logs
Collect Bitwarden Enterprise event logs
Collect Box Collaboration JSON logs
Collect Censys logs
Collect Code42 Incydr core datasets
Collect CSV Custom IOC files
Collect Deep Instinct EDR logs
Collect DigiCert audit logs
Collect DomainTools Iris Investigate results
Collect Duo administrator logs
Collect Duo authentication logs
Collect Duo entity context logs
Collect Google Cloud Abuse Events logs
Collect Harness IO audit logs
Collect HPE Aruba Networking Central logs
Collect Jamf Pro context logs
Collect PingOne Advanced Identity Cloud logs
Collect Slack audit logs
Collect Snyk group-level audit logs
Collect Snyk group-level audit and issues logs
Collect Venafi Zero Touch PKI logs
Collect Veritas NetBackup logs
Collect VMware AirWatch logs
Collect VMware Avi Load Balancer WAF logs
Collect VMware Horizon logs
Collect VMware VeloCloud SD-WAN logs
Collect Zoom operation logs

Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Collect Akamai Cloud Monitor logs
Collect Akamai DataStream 2 logs
Collect Aware audit logs
Collect AWS API Gateway access logs
Collect AWS VPC Transit Gateway flow logs
Collect Bitwarden Enterprise event logs
Collect Box Collaboration JSON logs
Collect Censys logs
Collect Code42 Incydr core datasets
Collect CSV Custom IOC files
Collect Deep Instinct EDR logs
Collect DigiCert audit logs
Collect DomainTools Iris Investigate results
Collect Duo administrator logs
Collect Duo authentication logs
Collect Duo entity context logs
Collect Google Cloud Abuse Events logs
Collect Harness IO audit logs
Collect HPE Aruba Networking Central logs
Collect Jamf Pro context logs
Collect PingOne Advanced Identity Cloud logs
Collect Slack audit logs
Collect Snyk group-level audit logs
Collect Snyk group-level audit and issues logs
Collect Venafi Zero Touch PKI logs
Collect Veritas NetBackup logs
Collect VMware AirWatch logs
Collect VMware Avi Load Balancer WAF logs
Collect VMware Horizon logs
Collect VMware VeloCloud SD-WAN logs
Collect Zoom operation logs

]]>
September 07, 2025 tag:google.com,2016:chronicle-release-notes#September_07_2025 2025-09-07T00:00:00-07:00 Feature

Advanced job scheduling

The job scheduling functionality has been enhanced with advanced options. This functionality provides more precise control and flexible, calendar-like scheduling for your scripts.

For more information, see Configure a new job with advanced scheduling.

Feature

Use custom fields in the Close Case dialog

Administrators can now add custom fields to the Close Case dialog. This new functionality provides a more streamlined workflow and replaces the Dynamic Fields feature.

For more information, see Use custom fields in the Close Case dialog.

Announcement

Release 6.3.61 is being rolled out to the first phase of regions, as outlined in our Google SecOps release plan.

This release contains the following features:

Feature

Advanced job scheduling

The job scheduling functionality has been enhanced with advanced options. This functionality provides more precise control and flexible, calendar-like scheduling for your scripts.

For more information, see Configure a new job with advanced scheduling.

Feature

Use custom fields in the Close Case dialog

Administrators can now add custom fields to the Close Case dialog. This new functionality provides a more streamlined workflow and replaces the Dynamic Fields feature.

For more information, see Use custom fields in the Close Case dialog.

]]>
September 06, 2025 tag:google.com,2016:chronicle-release-notes#September_06_2025 2025-09-06T00:00:00-07:00 Announcement

Release 6.3.60 is now available for all regions.

]]>
September 05, 2025 tag:google.com,2016:chronicle-release-notes#September_05_2025 2025-09-05T00:00:00-07:00 Changed

Advanced filtering in alerts and search results

You can now filter alerts and search results by any field in the detection object. This update provides more granular control over your queries, letting you filter by nested fields from events and entities within a detection.

Changed

Advanced filtering in alerts and search results

You can now filter alerts and search results by any field in the detection object. This update provides more granular control over your queries, letting you filter by nested fields from events and entities within a detection.

]]>
September 04, 2025 tag:google.com,2016:chronicle-release-notes#September_04_2025 2025-09-04T00:00:00-07:00 Changed

Time zone override for forwarder logs

Google SecOps now lets you override the default time zone for your logs when you create or configure a forwarder.

For details, see Add collector configuration.

Changed

Improved Okta and Symantec Endpoint Protection parsers

These changes are currently in Preview.

The Okta and Symantec Endpoint Protection parsers are now more efficient, with increased log-field coverage and more-accurate log-field mappings. These changes include new UDM fields and updated field mappings. We advise you to opt-in and get these new versions.

Announcement

CBN alerts functionality removed from all prebuilt parsers

As part of deprecating the Configuration Based Normalization (CBN) alerts functionality, all prebuilt parsers that included the CBN alerts functionality were updated, and the functionality was removed.

Changed

Time zone override for forwarder logs

Google SecOps now lets you override the default time zone for your logs when you create or configure a forwarder.

For details, see Add collector configuration.

Changed

Improved Okta and Symantec Endpoint Protection parsers

These changes are currently in Preview.

The Okta and Symantec Endpoint Protection parsers are now more efficient, with increased log-field coverage and more-accurate log-field mappings. These changes include new UDM fields and updated field mappings. We advise you to opt-in and get these new versions.

Announcement

CBN alerts functionality removed from all prebuilt parsers

As part of deprecating the Configuration Based Normalization (CBN) alerts functionality, all prebuilt parsers that included the CBN alerts functionality were updated, and the functionality was removed.

]]>
September 03, 2025 tag:google.com,2016:chronicle-release-notes#September_03_2025 2025-09-03T00:00:00-07:00 Changed

Extended match window for multi-event rules

You can now configure rules to analyze data over a longer period. The maximum match window for these rules has been extended to 14 days. The run frequency for multi-event rules is automatically set based on the rule's match window:

  • For a window size of 1 to 48 hours, the run frequency is 1 hour.

  • For a window size greater than 48 hours, the run frequency is 24 hours.

Changed

Extended match window for multi-event rules

You can now configure rules to analyze data over a longer period. The maximum match window for these rules has been extended to 14 days. The run frequency for multi-event rules is automatically set based on the rule's match window:

  • For a window size of 1 to 48 hours, the run frequency is 1 hour.

  • For a window size greater than 48 hours, the run frequency is 24 hours.

Changed

Google Threat Intelligence: Version 3.0

  • Extended supported filters in the following connector:

    • Google Threat Intelligence - ASM Issues Connector
]]>
August 31, 2025 tag:google.com,2016:chronicle-release-notes#August_31_2025 2025-08-31T00:00:00-07:00 Announcement

Release 6.3.60 is being rolled out to the first phase of regions as listed here.

This release contains internal and customer bug fixes.

]]>
August 30, 2025 tag:google.com,2016:chronicle-release-notes#August_30_2025 2025-08-30T00:00:00-07:00 Announcement

Release 6.3.59 is now available for all regions.

]]>
August 29, 2025 tag:google.com,2016:chronicle-release-notes#August_29_2025 2025-08-29T00:00:00-07:00 Changed

MITRE ATT&CK coverage dashboard is now available

This feature is currently in Preview.

The new MITRE ATT&CK coverage dashboard lets you measure your security posture against the MITRE ATT&CK framework, helping you:

  • Assess threat coverage
  • Identify gaps
  • Prioritize security efforts

Changed

MITRE ATT&CK coverage dashboard is now available

This feature is currently in Preview.

The new MITRE ATT&CK coverage dashboard lets you measure your security posture against the MITRE ATT&CK framework, helping you:

  • Assess threat coverage
  • Identify gaps
  • Prioritize security efforts
]]>
August 28, 2025 tag:google.com,2016:chronicle-release-notes#August_28_2025 2025-08-28T00:00:00-07:00 Changed

Composite detections for MITRE ATT&CK

The Curated Detections feature has been enhanced with new composite rules that define chains of MITRE ATT&CK tactics and techniques.

These powerful new rule packs are now in public preview for customers with a Google SecOps Enterprise or Enterprise Plus license.

To learn more, a companion blog post will be published on the Google Security Cloud Community on September 9, 2025.

Changed

Composite detections for MITRE ATT&CK

The Curated Detections feature has been enhanced with new composite rules that define chains of MITRE ATT&CK tactics and techniques.

These powerful new rule packs are now in public preview for customers with a Google SecOps Enterprise or Enterprise Plus license.

To learn more, a companion blog post will be published on the Google Security Cloud Community on September 9, 2025.

]]>
August 27, 2025 tag:google.com,2016:chronicle-release-notes#August_27_2025 2025-08-27T00:00:00-07:00 Feature

Google Workspace: Version 20.0

  • The following new actions have been added:

    • Block Extension

    • Delete Extension

    • Get Extension Details

    • Get Host Browser Details

    • Search User Activity Events

Changed

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • A10 Load Balancer (A10_LOAD_BALANCER)
  • AIX system (AIX_SYSTEM)
  • Apache (APACHE)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Aruba Switch (ARUBA_SWITCH)
  • Aruba (ARUBA_WIRELESS)
  • Attivo Networks (ATTIVO)
  • Auth0 (AUTH_ZERO)
  • Amazon VPC Transit Gateway Flow Logs (AWS_VPC_TRANSIT_GATEWAY)
  • AWS WAF (AWS_WAF)
  • Azure AD (AZURE_AD)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Azure Firewall (AZURE_FIREWALL)
  • Azure Front Door (AZURE_FRONT_DOOR)
  • Carbon Black App Control (CB_APP_CONTROL)
  • None (CHROME_MANAGEMENT)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco DNA Center Platform (CISCO_DNAC)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco IronPort (CISCO_IRONPORT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Router (CISCO_ROUTER)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco Umbrella Audit (CISCO_UMBRELLA_AUDIT)
  • Cisco VCS Expressway (CISCO_VCS)
  • Cisco WSA (CISCO_WSA)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Claroty Xdome (CLAROTY_XDOME)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Cloudflare (CLOUDFLARE)
  • Cloudflare WAF (CLOUDFLARE_WAF)
  • Corelight (CORELIGHT)
  • Palo Alto Cortex XDR Alerts (CORTEX_XDR)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • CrowdStrike Falcon Stream (CS_STREAM)
  • Cyberark Privilege Cloud (CYBERARK_PRIVILEGE_CLOUD)
  • Darktrace (DARKTRACE)
  • Datadog (DATADOG)
  • Elastic Defend (ELASTIC_DEFEND)
  • F5 ASM (F5_ASM)
  • F5 Distributed Cloud Services (F5_DCS)
  • F5 Silverline (F5_SILVERLINE)
  • Fidelis Network (FIDELIS_NETWORK)
  • FireEye (FIREEYE_ALERT)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint DLP (FORCEPOINT_DLP)
  • ForgeRock Identity Cloud (FORGEROCK_IDENTITY_CLOUD)
  • FortiGate (FORTINET_FIREWALL)
  • Cloud SQL (GCP_CLOUDSQL)
  • Google Cloud DNS Threat Detector (GCP_DNS_ATD)
  • Cloud Load Balancing (GCP_LOADBALANCING)
  • None (GCP_SECURITYCENTER_THREAT)
  • VPC Flow Logs (GCP_VPC_FLOW)
  • AWS GuardDuty (GUARDDUTY)
  • IBM-i Operating System (IBM_I)
  • Imperva (IMPERVA_WAF)
  • Infoblox DHCP (INFOBLOX_DHCP)
  • Jamf Protect Telemetry V2 (JAMF_TELEMETRY_V2)
  • Kemp Load Balancer (KEMP_LOADBALANCER)
  • Kubernetes Node (KUBERNETES_NODE)
  • ManageEngine AD360 (MANAGE_ENGINE_AD360)
  • McAfee ePolicy Orchestrator (MCAFEE_EPO)
  • McAfee IPS (MCAFEE_IPS)
  • Medigate IoT (MEDIGATE_IOT)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft Sentinel (MICROSOFT_SENTINEL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mikrotik Router (MIKROTIK_ROUTER)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • Unix system (NIX_SYSTEM)
  • Oracle Cloud Infrastructure VCN Flow Logs (OCI_FLOW)
  • Office 365 (OFFICE_365)
  • Office 365 Message Trace (OFFICE_365_MESSAGETRACE)
  • Okta (OKTA)
  • Okta Scaleft (OKTA_SCALEFT)
  • Oracle (ORACLE_DB)
  • Orca Cloud Security Platform (ORCA)
  • Proofpoint Threat Response (PROOFPOINT_TRAP)
  • Quest Active Directory (QUEST_AD)
  • Radware Web Application Firewall (RADWARE_FIREWALL)
  • Red Hat OpenShift (REDHAT_OPENSHIFT)
  • Symantec Endpoint Protection (SEP)
  • Silverfort Authentication Platform (SILVERFORT)
  • Squid Web Proxy (SQUID_WEBPROXY)
  • STIX Threat Intelligence (STIX)
  • Symantec DLP (SYMANTEC_DLP)
  • Sysdig (SYSDIG)
  • Tenable Security Center (TENABLE_SC)
  • Trend Micro (TIPPING_POINT)
  • Trellix HX Event Streamer (TRELLIX_HX_ES)
  • Trend Micro Apex one (TRENDMICRO_APEX_ONE)
  • Trend Micro Vision One Activity (TRENDMICRO_VISION_ONE_ACTIVITY)
  • Trend Micro Vision One (TRENDMICRO_VISION_ONE)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • Ubiquiti UniFi Switch (UBIQUITI_SWITCH)
  • Cisco Umbrella DNS (UMBRELLA_DNS)
  • Cisco Umbrella IP (UMBRELLA_IP)
  • Varonis (VARONIS)
  • Vectra XDR (VECTRA_XDR)
  • VMware vCenter (VMWARE_VCENTER)
  • VMware vRealize Suite (VMware Aria) (VMWARE_VREALIZE)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Zscaler CASB (ZSCALER_CASB)
  • ZScaler Deception (ZSCALER_DECEPTION)
  • Zscaler DLP (ZSCALER_DLP)
  • ZScaler DNS (ZSCALER_DNS)
  • ZScaler NGFW (ZSCALER_FIREWALL)
  • Zscaler Internet Access Audit Logs (ZSCALER_INTERNET_ACCESS)
  • Zscaler Tunnel (ZSCALER_TUNNEL)
  • Zscaler (ZSCALER_WEBPROXY)
  • Zscaler Secure Private Access Audit Logs (ZSCALER_ZPA_AUDIT)
  • Zscaler Private Access (ZSCALER_ZPA)

The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.

  • Alicloud ApsaraDB (ALICLOUD_APSARADB)
  • AliCloud Firewall (ALICLOUD_FIREWALL)
  • AuthMind (AUTHMIND)
  • Microsoft Entra Recommendations (MS_ENTRA_RECOMMENDATIONS)
  • Palo Alto Networks Prisma Access (PAN_PRISMA_ACCESS)
  • Trellix Malware Analysis (TRELLIX_AX)
  • Everfox ULTRA (ULTRA)
  • ZScaler NSS VM (ZSCALER_NSS_VM)

Changed

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • A10 Load Balancer (A10_LOAD_BALANCER)
  • AIX system (AIX_SYSTEM)
  • Apache (APACHE)
  • Arcsight CEF (ARCSIGHT_CEF)
  • Aruba Switch (ARUBA_SWITCH)
  • Aruba (ARUBA_WIRELESS)
  • Attivo Networks (ATTIVO)
  • Auth0 (AUTH_ZERO)
  • Amazon VPC Transit Gateway Flow Logs (AWS_VPC_TRANSIT_GATEWAY)
  • AWS WAF (AWS_WAF)
  • Azure AD (AZURE_AD)
  • Azure AD Organizational Context (AZURE_AD_CONTEXT)
  • Azure Firewall (AZURE_FIREWALL)
  • Azure Front Door (AZURE_FRONT_DOOR)
  • Carbon Black App Control (CB_APP_CONTROL)
  • None (CHROME_MANAGEMENT)
  • Cisco ASA (CISCO_ASA_FIREWALL)
  • Cisco DNA Center Platform (CISCO_DNAC)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco IronPort (CISCO_IRONPORT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Router (CISCO_ROUTER)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco Switch (CISCO_SWITCH)
  • Cisco Umbrella Audit (CISCO_UMBRELLA_AUDIT)
  • Cisco VCS Expressway (CISCO_VCS)
  • Cisco WSA (CISCO_WSA)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Claroty Xdome (CLAROTY_XDOME)
  • HP Aruba (ClearPass) (CLEARPASS)
  • Cloudflare (CLOUDFLARE)
  • Cloudflare WAF (CLOUDFLARE_WAF)
  • Corelight (CORELIGHT)
  • Palo Alto Cortex XDR Alerts (CORTEX_XDR)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • CrowdStrike Falcon Stream (CS_STREAM)
  • Cyberark Privilege Cloud (CYBERARK_PRIVILEGE_CLOUD)
  • Darktrace (DARKTRACE)
  • Datadog (DATADOG)
  • Elastic Defend (ELASTIC_DEFEND)
  • F5 ASM (F5_ASM)
  • F5 Distributed Cloud Services (F5_DCS)
  • F5 Silverline (F5_SILVERLINE)
  • Fidelis Network (FIDELIS_NETWORK)
  • FireEye (FIREEYE_ALERT)
  • FireEye NX (FIREEYE_NX)
  • Forcepoint DLP (FORCEPOINT_DLP)
  • ForgeRock Identity Cloud (FORGEROCK_IDENTITY_CLOUD)
  • FortiGate (FORTINET_FIREWALL)
  • Cloud SQL (GCP_CLOUDSQL)
  • Google Cloud DNS Threat Detector (GCP_DNS_ATD)
  • Cloud Load Balancing (GCP_LOADBALANCING)
  • None (GCP_SECURITYCENTER_THREAT)
  • VPC Flow Logs (GCP_VPC_FLOW)
  • AWS GuardDuty (GUARDDUTY)
  • IBM-i Operating System (IBM_I)
  • Imperva (IMPERVA_WAF)
  • Infoblox DHCP (INFOBLOX_DHCP)
  • Jamf Protect Telemetry V2 (JAMF_TELEMETRY_V2)
  • Kemp Load Balancer (KEMP_LOADBALANCER)
  • Kubernetes Node (KUBERNETES_NODE)
  • ManageEngine AD360 (MANAGE_ENGINE_AD360)
  • McAfee ePolicy Orchestrator (MCAFEE_EPO)
  • McAfee IPS (MCAFEE_IPS)
  • Medigate IoT (MEDIGATE_IOT)
  • Microsoft Defender for Endpoint (MICROSOFT_DEFENDER_ENDPOINT)
  • Microsoft Graph API Alerts (MICROSOFT_GRAPH_ALERT)
  • Microsoft Sentinel (MICROSOFT_SENTINEL)
  • Microsoft SQL Server (MICROSOFT_SQL)
  • Mikrotik Router (MIKROTIK_ROUTER)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • Unix system (NIX_SYSTEM)
  • Oracle Cloud Infrastructure VCN Flow Logs (OCI_FLOW)
  • Office 365 (OFFICE_365)
  • Office 365 Message Trace (OFFICE_365_MESSAGETRACE)
  • Okta (OKTA)
  • Okta Scaleft (OKTA_SCALEFT)
  • Oracle (ORACLE_DB)
  • Orca Cloud Security Platform (ORCA)
  • Proofpoint Threat Response (PROOFPOINT_TRAP)
  • Quest Active Directory (QUEST_AD)
  • Radware Web Application Firewall (RADWARE_FIREWALL)
  • Red Hat OpenShift (REDHAT_OPENSHIFT)
  • Symantec Endpoint Protection (SEP)
  • Silverfort Authentication Platform (SILVERFORT)
  • Squid Web Proxy (SQUID_WEBPROXY)
  • STIX Threat Intelligence (STIX)
  • Symantec DLP (SYMANTEC_DLP)
  • Sysdig (SYSDIG)
  • Tenable Security Center (TENABLE_SC)
  • Trend Micro (TIPPING_POINT)
  • Trellix HX Event Streamer (TRELLIX_HX_ES)
  • Trend Micro Apex one (TRENDMICRO_APEX_ONE)
  • Trend Micro Vision One Activity (TRENDMICRO_VISION_ONE_ACTIVITY)
  • Trend Micro Vision One (TRENDMICRO_VISION_ONE)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • Ubiquiti UniFi Switch (UBIQUITI_SWITCH)
  • Cisco Umbrella DNS (UMBRELLA_DNS)
  • Cisco Umbrella IP (UMBRELLA_IP)
  • Varonis (VARONIS)
  • Vectra XDR (VECTRA_XDR)
  • VMware vCenter (VMWARE_VCENTER)
  • VMware vRealize Suite (VMware Aria) (VMWARE_VREALIZE)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Zscaler CASB (ZSCALER_CASB)
  • ZScaler Deception (ZSCALER_DECEPTION)
  • Zscaler DLP (ZSCALER_DLP)
  • ZScaler DNS (ZSCALER_DNS)
  • ZScaler NGFW (ZSCALER_FIREWALL)
  • Zscaler Internet Access Audit Logs (ZSCALER_INTERNET_ACCESS)
  • Zscaler Tunnel (ZSCALER_TUNNEL)
  • Zscaler (ZSCALER_WEBPROXY)
  • Zscaler Secure Private Access Audit Logs (ZSCALER_ZPA_AUDIT)
  • Zscaler Private Access (ZSCALER_ZPA)

The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.

  • Alicloud ApsaraDB (ALICLOUD_APSARADB)
  • AliCloud Firewall (ALICLOUD_FIREWALL)
  • AuthMind (AUTHMIND)
  • Microsoft Entra Recommendations (MS_ENTRA_RECOMMENDATIONS)
  • Palo Alto Networks Prisma Access (PAN_PRISMA_ACCESS)
  • Trellix Malware Analysis (TRELLIX_AX)
  • Everfox ULTRA (ULTRA)
  • ZScaler NSS VM (ZSCALER_NSS_VM)

Changed

Google Threat Intelligence: Version 3.0

  • Integration: Updated authentication flow.
]]>
August 23, 2025 tag:google.com,2016:chronicle-release-notes#August_23_2025 2025-08-23T00:00:00-07:00 Announcement

Release 6.3.59 is being rolled out to the first phase of regions as listed here.

This release contains internal and customer bug fixes.

]]>
August 22, 2025 tag:google.com,2016:chronicle-release-notes#August_22_2025 2025-08-22T00:00:00-07:00 Announcement

Release 6.3.58 is now available for all regions.

]]>
August 21, 2025 tag:google.com,2016:chronicle-release-notes#August_21_2025 2025-08-21T00:00:00-07:00 Feature

Enhanced curated detections has been enhanced with composite detection content for Mandiant Hunt Cloud Classification, including AWS, GCP, and Azure. This rule pack is available for Mandiant Threat Defense (MTD) customers with a Google Security Operations Enterprise or Enterprise Plus license.

Feature

Enhanced curated detections has been enhanced with composite detection content for Mandiant Hunt Cloud Classification, including AWS, GCP, and Azure. This rule pack is available for Mandiant Threat Defense (MTD) customers with a Google Security Operations Enterprise or Enterprise Plus license.

]]>
August 20, 2025 tag:google.com,2016:chronicle-release-notes#August_20_2025 2025-08-20T00:00:00-07:00 Changed

New rules added to rule pack

Curated Detections has been enhanced with additional Chrome Enterprise Premium Browser Threat detections. The following rules have been added to the rule pack:

  • Dangerous Download with Matching Hashes by multiple users in Chrome Management

  • GTI High Severity File Download Event in Chrome Management

  • GTI Medium Severity File Download Event in Chrome Management

  • GTI Low Severity File Download Event in Chrome Management

  • Safe-browsing High Severity File Download Event in Chrome Management

  • Multiple Dangerous Download Events by same user in Chrome Management

  • Url Event to Newly Created Domain in Chrome Management

Changed

New rules added to rule pack

Curated Detections has been enhanced with additional Chrome Enterprise Premium Browser Threat detections. The following rules have been added to the rule pack:

  • Dangerous Download with Matching Hashes by multiple users in Chrome Management

  • GTI High Severity File Download Event in Chrome Management

  • GTI Medium Severity File Download Event in Chrome Management

  • GTI Low Severity File Download Event in Chrome Management

  • Safe-browsing High Severity File Download Event in Chrome Management

  • Multiple Dangerous Download Events by same user in Chrome Management

  • Url Event to Newly Created Domain in Chrome Management

Feature

Composite detections are now generally available

The composite detections feature is now in General Availability. Composite detections lets you link multiple YARA-L rules to detect complex, multistage threats. This capability enhances detection by correlating alerts that individual rules might not detect.

For more information, see Overview of composite detections.

Feature

Composite detections are now generally available

The composite detections feature is now in General Availability. Composite detections lets you link multiple YARA-L rules to detect complex, multistage threats. This capability enhances detection by correlating alerts that individual rules might not detect.

For more information, see Overview of composite detections.

Changed

CrowdStrike Falcon: Version 63.0

  • Updated processing of On-Demand Scan alerts in the following connector:

    • Crowdstrike Falcon - Alerts Connector

Changed

Google Chronicle: Version 64.0

  • Added support for aggregated searches in the following action:

    • Execute UDM Query

Changed

Microsoft Graph Mail: Version 30.0

  • Improved handling of Case Name Template in the following connector:

    • Microsoft Graph Mail - Microsoft Graph Mail Connector

Changed

Microsoft Graph Mail Delegated: Version 6.0

  • Improved handling of Case Name Template in the following connector:

    • Microsoft Graph Mail Delegated - Microsoft Graph Mail Delegated Connector
]]>
August 19, 2025 tag:google.com,2016:chronicle-release-notes#August_19_2025 2025-08-19T00:00:00-07:00 Announcement

Reference lists retiring

The reference list functionality is being phased out of the Google SecOps platform.

  • October 2025: You'll no longer be able to create new reference lists. Instead, use data tables to provide expanded functionality.

  • Migration period: All existing reference lists will be automatically migrated to data tables. During this migration period, you can continue to use your existing reference lists without changes.

  • September 2026: The legacy reference list functionality will be fully retired from the platform. After that date, all data will be available only through the data table interface.

Announcement

Reference lists retiring

The reference list functionality is being phased out of the Google SecOps platform.

  • October 2025: You'll no longer be able to create new reference lists. Instead, use data tables to provide expanded functionality.

  • Migration period: All existing reference lists will be automatically migrated to data tables. During this migration period, you can continue to use your existing reference lists without changes.

  • September 2026: The legacy reference list functionality will be fully retired from the platform. After that date, all data will be available only through the data table interface.

]]>
August 17, 2025 tag:google.com,2016:chronicle-release-notes#August_17_2025 2025-08-17T00:00:00-07:00 Announcement

Release 6.3.58 is being rolled out to the first phase of regions as listed here.

This release contains internal and customer bug fixes.

]]>
August 16, 2025 tag:google.com,2016:chronicle-release-notes#August_16_2025 2025-08-16T00:00:00-07:00 Announcement

Release 6.3.57 is now available for all regions.

]]>
August 13, 2025 tag:google.com,2016:chronicle-release-notes#August_13_2025 2025-08-13T00:00:00-07:00 Feature

New CyberArk Credential Provider integration

Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Announcement

New parser documentation now available

New parser documentation is available to help you ingest and normalize logs from the following sources:

Changed

Jira: Version 47.0

  • Updated timestamp processing logic in the following jobs:

    • Sync Comments

    • Sync Closure

  • Updated logic for processing closed tickets in the following job:

    • Sync Closure

Changed

Microsoft Graph Mail: Version 29.0

  • Integration: Updated dependencies.
]]>
August 12, 2025 tag:google.com,2016:chronicle-release-notes#August_12_2025 2025-08-12T00:00:00-07:00 Changed

Data RBAC self-service enablement

Data RBAC now includes a self-service option for direct enablement. This makes the initial onboarding process faster and simpler. For details, see Configure data RBAC for users.

Changed

Data RBAC self-service enablement

Data RBAC now includes a self-service option for direct enablement. This makes the initial onboarding process faster and simpler. For details, see Configure data RBAC for users.

]]>
August 10, 2025 tag:google.com,2016:chronicle-release-notes#August_10_2025 2025-08-10T00:00:00-07:00 Announcement

New permissions for Content Hub

To access all modules in the Content Hub, you must set the correct IAM role permissions.

For full details, see Google SecOps Content Hub overview.

Feature

Updated permissions for accessing product-centric feeds

If you have assigned Custom IAM Roles, you can now grant access to the product-centric feeds by adding the following permissions to the role:

  • chronicle.feedPacks.get
  • chronicle.feedPacks.list

To learn more about how to configure feeds using the product-centric feeds UI, see Configure feeds by product.

Feature

Updated permissions for accessing product-centric feeds

If you have assigned Custom IAM Roles, you can now grant access to the product-centric feeds by adding the following permissions to the role:

  • chronicle.feedPacks.get
  • chronicle.feedPacks.list

To learn more about how to configure feeds using the product-centric feeds UI, see Configure feeds by product.

Feature

Expression Builder enhancements

The Expression Builder has been enhanced with a new set of pre-built filters to help streamline query creation.

We've improved the information within the platform for all filters, both new and existing. The supporting documentation provides clearer descriptions and practical examples for each transformer, making it easier to understand their purpose and syntax.

For details, see Use the Expression Builder.

Feature

Remote agent notifications

Agent notifications will alert you to new remote agent version releases and agent downtime based on your permissions and associated environments. Agent notifications are now enabled by default. You can opt out of these notifications at any time from your user preferences.

For details, see Agent notifications.

Announcement

Release 6.3.57 is being rolled out to the first phase of regions, as outlined in our Google SecOps release plan.

This release contains the following features:

Feature

Expression Builder enhancements

The Expression Builder has been enhanced with a new set of pre-built filters to help streamline query creation.

We've improved the information within the platform for all filters, both new and existing. The supporting documentation provides clearer descriptions and practical examples for each transformer, making it easier to understand their purpose and syntax.

For details, see Use the Expression Builder.

Feature

Remote agent notifications

Agent notifications will alert you to new remote agent version releases and agent downtime based on your permissions and associated environments. Agent notifications are now enabled by default. You can opt out of these notifications at any time from your user preferences.

For details, see Agent notifications.

]]>
August 09, 2025 tag:google.com,2016:chronicle-release-notes#August_09_2025 2025-08-09T00:00:00-07:00 Announcement

Release 6.3.56 is now available for all regions.

]]>
August 08, 2025 tag:google.com,2016:chronicle-release-notes#August_08_2025 2025-08-08T00:00:00-07:00 Changed

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • 1Password (ONEPASSWORD)
  • A10 Load Balancer (A10_LOAD_BALANCER)
  • AIX system (AIX_SYSTEM)
  • Akamai Enterprise Application Access (AKAMAI_EAA)
  • Akamai WAF (AKAMAI_WAF)
  • Apache (APACHE)
  • Aqua Security (AQUA_SECURITY)
  • Aruba (ARUBA_WIRELESS)
  • Attivo Networks (ATTIVO)
  • Auth0 (AUTH_ZERO)
  • AWS Config (AWS_CONFIG)
  • AWS GuardDuty (GUARDDUTY)
  • AWS Lambda Function (AWS_LAMBDA_FUNCTION)
  • AWS RDS (AWS_RDS)
  • AWS VPC Flow (AWS_VPC_FLOW)
  • Azure AD (AZURE_AD)
  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Azure AD Sign-In (AZURE_AD_SIGNIN)
  • Azure Key Vault logging (AZURE_KEYVAULT_AUDIT)
  • Azure VNET Flow (AZURE_VNET_FLOW)
  • Barracuda Email (BARRACUDA_EMAIL)
  • Barracuda WAF (BARRACUDA_WAF)
  • BeyondTrust BeyondInsight (BEYONDTRUST_BEYONDINSIGHT)
  • Bitdefender (BITDEFENDER)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • Check Point (CHECKPOINT_FIREWALL)
  • Check Point Sandblast (CHECKPOINT_EDR)
  • Chrome Management (N/A)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco IronPort (CISCO_IRONPORT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Meraki (CISCO_MERAKI)
  • Cisco NX-OS (CISCO_NX_OS)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Stealthwatch (CISCO_STEALTHWATCH)
  • Cisco Umbrella SWG DLP (CISCO_UMBRELLA_SWG_DLP)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco WLC/WCS (CISCO_WIRELESS)
  • Cisco WSA (CISCO_WSA)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Cloud Audit Logs (N/A)
  • Cloud DNS (N/A)
  • Cloud Load Balancing (GCP_LOADBALANCING)
  • Cloudflare (CLOUDFLARE)
  • Corelight (CORELIGHT)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • CrowdStrike Falcon Stream (CS_STREAM)
  • CSV Custom IOC (CSV_CUSTOM_IOC)
  • CyberArk (CYBERARK)
  • Cybereason EDR (CYBEREASON_EDR)
  • Darktrace (DARKTRACE)
  • EfficientIP DDI (EFFICIENTIP_DDI)
  • Elastic Defend (ELASTIC_DEFEND)
  • EPIC Systems (EPIC)
  • ExtraHop RevealX (EXTRAHOP)
  • F5 Advanced Firewall Management (F5_AFM)
  • F5 ASM (F5_ASM)
  • F5 BIGIP Access Policy Manager (F5_BIGIP_APM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • F5 DNS (F5_DNS)
  • F5 Silverline (F5_SILVERLINE)
  • Fidelis Network (FIDELIS_NETWORK)
  • FireEye ETP (FIREEYE_ETP)
  • ForgeRock Identity Cloud (FORGEROCK_IDENTITY_CLOUD)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet Proxy (FORTINET_WEBPROXY)
  • Fortinet Web Application Firewall (FORTINET_FORTIWEB)
  • GitHub (GITHUB)
  • Halcyon Anti Ransomware (HALCYON)
  • HAProxy (HAPROXY)
  • HP Aruba (ClearPass) (CLEARPASS)
  • IBM DataPower Gateway (IBM_DATAPOWER)
  • Imperva (IMPERVA_WAF)
  • Imperva SecureSphere Management (IMPERVA_SECURESPHERE)
  • Infoblox DHCP (INFOBLOX_DHCP)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • Kubernetes Node (KUBERNETES_NODE)
  • Lacework Cloud Security (LACEWORK)
  • Linux Auditing System (AuditD) (AUDITD)
  • Linux Sysmon (LINUX_SYSMON)
  • McAfee IPS (MCAFEE_IPS)
  • Menlo Security (MENLO_SECURITY)
  • Microsoft AD (WINDOWS_AD)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Microsoft Defender for Identity (MICROSOFT_DEFENDER_IDENTITY)
  • Microsoft IIS (IIS)
  • Mimecast (MIMECAST_MAIL)
  • Mimecast Mail V2 (MIMECAST_MAIL_V2)
  • MISP Threat Intelligence (MISP_IOC)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • NGINX (NGINX)
  • One Identity Identity Manager (ONE_IDENTITY_IDENTITY_MANAGER)
  • Opnsense (OPNSENSE)
  • Orca Cloud Security Platform (ORCA)
  • Palo Alto Cortex XDR Events (PAN_CORTEX_XDR_EVENTS)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Palo Alto Panorama (PAN_PANORAMA)
  • Palo Alto Prisma Access (PAN_CASB)
  • pfSense (PFSENSE)
  • Ping Federate (PING_FEDERATE)
  • Proofpoint Observeit (OBSERVEIT)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • Proofpoint Tap Alerts (PROOFPOINT_MAIL)
  • Qualys VM (QUALYS_VM)
  • Remediant SecureONE (REMEDIANT_SECUREONE)
  • SAP SM20 (SAP_SM20)
  • SecureAuth (SECUREAUTH_SSO)
  • SentinelOne EDR (SENTINEL_EDR)
  • Silverfort Authentication Platform (SILVERFORT)
  • Sophos Central (SOPHOS_CENTRAL)
  • Sophos UTM (SOPHOS_UTM)
  • Squid Web Proxy (SQUID_WEBPROXY)
  • Symantec DLP (SYMANTEC_DLP)
  • Symantec Web Security Service (SYMANTEC_WSS)
  • Tenable Active Directory Security (TENABLE_ADS)
  • Tenable Security Center (TENABLE_SC)
  • Thinkst Canary (THINKST_CANARY)
  • Trellix HX Event Streamer (TRELLIX_HX_ES)
  • Trend Micro Apex one (TRENDMICRO_APEX_ONE)
  • Trend Micro Cloud one (TRENDMICRO_CLOUDONE)
  • Trend Micro Vision One Activity (TRENDMICRO_VISION_ONE_ACTIVITY)
  • Trend Micro Vision One Observerd Attack Techniques (TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • Tripwire (TRIPWIRE_FIM)
  • Unix system (NIX_SYSTEM)
  • VMware Horizon (VMWARE_HORIZON)
  • VMware vCenter (VMWARE_VCENTER)
  • VMware vRealize Suite (VMware Aria) (VMWARE_VREALIZE)
  • WatchGuard (WATCHGUARD)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Workday Audit Logs (WORKDAY_AUDIT)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Workspace Users (WORKSPACE_USERS)
  • ZScaler Deception (ZSCALER_DECEPTION)

The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.

  • Akamai MFA (AKAMAI_MFA)
  • Azure Org Context (AZURE_ORG_CONTEXT)
  • Cisco Remote Access VPN (CISCO_RAVPN)
  • CoreView Audit-log SIEM integration (COREVIEW)
  • Fortinet Network Detection and Response (FORTINET_FORTINDR)
  • GCP Security Command Center Chokepoint (GCP_SECURITYCENTER_CHOKEPOINT)
  • Imperva Cloud WAF (IMPERVA_CLOUD_WAF)
  • Lumu Universal SIEM (LUMU)
  • Microsoft Azure Databricks (MICROSOFT_DATABRICKS_WORKSPACES)
  • Microsoft Insights/Components (MICROSOFT_INSIGHTS_COMPONENTS)
  • Microsoft ServiceBus/Namespaces (MICROSOFT_SERVICEBUS_NAMESPACES)
  • Microsoft Azure SQL Managed Instances (MICROSOFT_SQL_MANAGED_INSTANCES)
  • Moveworks (MOVEWORKS)
  • Network Box Unified Threat Management+ (NETWORKBOX_UTM)
  • Oracle Cloud Infrastructure Identity Cloud Service (OCI_IDENTITY_CLOUD_SERVICE)
  • SAP Commerce Cloud (SAP_HAC)
  • Sonatype Lifecycle (SONATYPE_LIFECYCLE)
  • TeamViewer Tensor (TEAMVIEWER_TENSOR)
  • Torq Audit Logs (TORQ_AUDIT_LOGS)
  • Velociraptor - digital forensic & incident response tool (VELOCIRAPTOR)
  • Zoom Activity Logs (ZOOM_ACTIVITY)

For a list of supported log types and details about default parser changes, see Supported log types and default parsers.

Changed

Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.

The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates.

  • 1Password (ONEPASSWORD)
  • A10 Load Balancer (A10_LOAD_BALANCER)
  • AIX system (AIX_SYSTEM)
  • Akamai Enterprise Application Access (AKAMAI_EAA)
  • Akamai WAF (AKAMAI_WAF)
  • Apache (APACHE)
  • Aqua Security (AQUA_SECURITY)
  • Aruba (ARUBA_WIRELESS)
  • Attivo Networks (ATTIVO)
  • Auth0 (AUTH_ZERO)
  • AWS Config (AWS_CONFIG)
  • AWS GuardDuty (GUARDDUTY)
  • AWS Lambda Function (AWS_LAMBDA_FUNCTION)
  • AWS RDS (AWS_RDS)
  • AWS VPC Flow (AWS_VPC_FLOW)
  • Azure AD (AZURE_AD)
  • Azure AD Directory Audit (AZURE_AD_AUDIT)
  • Azure AD Sign-In (AZURE_AD_SIGNIN)
  • Azure Key Vault logging (AZURE_KEYVAULT_AUDIT)
  • Azure VNET Flow (AZURE_VNET_FLOW)
  • Barracuda Email (BARRACUDA_EMAIL)
  • Barracuda WAF (BARRACUDA_WAF)
  • BeyondTrust BeyondInsight (BEYONDTRUST_BEYONDINSIGHT)
  • Bitdefender (BITDEFENDER)
  • Blue Coat Proxy (BLUECOAT_WEBPROXY)
  • Check Point (CHECKPOINT_FIREWALL)
  • Check Point Sandblast (CHECKPOINT_EDR)
  • Chrome Management (N/A)
  • Cisco Email Security (CISCO_EMAIL_SECURITY)
  • Cisco Firepower NGFW (CISCO_FIREPOWER_FIREWALL)
  • Cisco Internetwork Operating System (CISCO_IOS)
  • Cisco IronPort (CISCO_IRONPORT)
  • Cisco ISE (CISCO_ISE)
  • Cisco Meraki (CISCO_MERAKI)
  • Cisco NX-OS (CISCO_NX_OS)
  • Cisco Router (CISCO_ROUTER)
  • Cisco Stealthwatch (CISCO_STEALTHWATCH)
  • Cisco Umbrella SWG DLP (CISCO_UMBRELLA_SWG_DLP)
  • Cisco vManage SD-WAN (CISCO_SDWAN)
  • Cisco WLC/WCS (CISCO_WIRELESS)
  • Cisco WSA (CISCO_WSA)
  • Citrix Netscaler (CITRIX_NETSCALER)
  • Cloud Audit Logs (N/A)
  • Cloud DNS (N/A)
  • Cloud Load Balancing (GCP_LOADBALANCING)
  • Cloudflare (CLOUDFLARE)
  • Corelight (CORELIGHT)
  • CrowdStrike Alerts API (CS_ALERTS)
  • CrowdStrike Detection Monitoring (CS_DETECTS)
  • CrowdStrike Falcon (CS_EDR)
  • CrowdStrike Falcon Stream (CS_STREAM)
  • CSV Custom IOC (CSV_CUSTOM_IOC)
  • CyberArk (CYBERARK)
  • Cybereason EDR (CYBEREASON_EDR)
  • Darktrace (DARKTRACE)
  • EfficientIP DDI (EFFICIENTIP_DDI)
  • Elastic Defend (ELASTIC_DEFEND)
  • EPIC Systems (EPIC)
  • ExtraHop RevealX (EXTRAHOP)
  • F5 Advanced Firewall Management (F5_AFM)
  • F5 ASM (F5_ASM)
  • F5 BIGIP Access Policy Manager (F5_BIGIP_APM)
  • F5 BIGIP LTM (F5_BIGIP_LTM)
  • F5 DNS (F5_DNS)
  • F5 Silverline (F5_SILVERLINE)
  • Fidelis Network (FIDELIS_NETWORK)
  • FireEye ETP (FIREEYE_ETP)
  • ForgeRock Identity Cloud (FORGEROCK_IDENTITY_CLOUD)
  • FortiGate (FORTINET_FIREWALL)
  • Fortinet FortiAnalyzer (FORTINET_FORTIANALYZER)
  • Fortinet Proxy (FORTINET_WEBPROXY)
  • Fortinet Web Application Firewall (FORTINET_FORTIWEB)
  • GitHub (GITHUB)
  • Halcyon Anti Ransomware (HALCYON)
  • HAProxy (HAPROXY)
  • HP Aruba (ClearPass) (CLEARPASS)
  • IBM DataPower Gateway (IBM_DATAPOWER)
  • Imperva (IMPERVA_WAF)
  • Imperva SecureSphere Management (IMPERVA_SECURESPHERE)
  • Infoblox DHCP (INFOBLOX_DHCP)
  • Jamf pro context (JAMF_PRO_CONTEXT)
  • Kubernetes Node (KUBERNETES_NODE)
  • Lacework Cloud Security (LACEWORK)
  • Linux Auditing System (AuditD) (AUDITD)
  • Linux Sysmon (LINUX_SYSMON)
  • McAfee IPS (MCAFEE_IPS)
  • Menlo Security (MENLO_SECURITY)
  • Microsoft AD (WINDOWS_AD)
  • Microsoft Azure Activity (AZURE_ACTIVITY)
  • Microsoft Defender for Identity (MICROSOFT_DEFENDER_IDENTITY)
  • Microsoft IIS (IIS)
  • Mimecast (MIMECAST_MAIL)
  • Mimecast Mail V2 (MIMECAST_MAIL_V2)
  • MISP Threat Intelligence (MISP_IOC)
  • NetApp ONTAP (NETAPP_ONTAP)
  • Netskope V2 (NETSKOPE_ALERT_V2)
  • Netskope Web Proxy (NETSKOPE_WEBPROXY)
  • NGINX (NGINX)
  • One Identity Identity Manager (ONE_IDENTITY_IDENTITY_MANAGER)
  • Opnsense (OPNSENSE)
  • Orca Cloud Security Platform (ORCA)
  • Palo Alto Cortex XDR Events (PAN_CORTEX_XDR_EVENTS)
  • Palo Alto Networks Firewall (PAN_FIREWALL)
  • Palo Alto Panorama (PAN_PANORAMA)
  • Palo Alto Prisma Access (PAN_CASB)
  • pfSense (PFSENSE)
  • Ping Federate (PING_FEDERATE)
  • Proofpoint Observeit (OBSERVEIT)
  • Proofpoint On Demand (PROOFPOINT_ON_DEMAND)
  • Proofpoint Tap Alerts (PROOFPOINT_MAIL)
  • Qualys VM (QUALYS_VM)
  • Remediant SecureONE (REMEDIANT_SECUREONE)
  • SAP SM20 (SAP_SM20)
  • SecureAuth (SECUREAUTH_SSO)
  • SentinelOne EDR (SENTINEL_EDR)
  • Silverfort Authentication Platform (SILVERFORT)
  • Sophos Central (SOPHOS_CENTRAL)
  • Sophos UTM (SOPHOS_UTM)
  • Squid Web Proxy (SQUID_WEBPROXY)
  • Symantec DLP (SYMANTEC_DLP)
  • Symantec Web Security Service (SYMANTEC_WSS)
  • Tenable Active Directory Security (TENABLE_ADS)
  • Tenable Security Center (TENABLE_SC)
  • Thinkst Canary (THINKST_CANARY)
  • Trellix HX Event Streamer (TRELLIX_HX_ES)
  • Trend Micro Apex one (TRENDMICRO_APEX_ONE)
  • Trend Micro Cloud one (TRENDMICRO_CLOUDONE)
  • Trend Micro Vision One Activity (TRENDMICRO_VISION_ONE_ACTIVITY)
  • Trend Micro Vision One Observerd Attack Techniques (TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES)
  • Trend Micro Vision One Workbench (TRENDMICRO_VISION_ONE_WORKBENCH)
  • Tripwire (TRIPWIRE_FIM)
  • Unix system (NIX_SYSTEM)
  • VMware Horizon (VMWARE_HORIZON)
  • VMware vCenter (VMWARE_VCENTER)
  • VMware vRealize Suite (VMware Aria) (VMWARE_VREALIZE)
  • WatchGuard (WATCHGUARD)
  • Windows Event (WINEVTLOG)
  • Windows Event (XML) (WINEVTLOG_XML)
  • Workday Audit Logs (WORKDAY_AUDIT)
  • Workspace Activities (WORKSPACE_ACTIVITY)
  • Workspace Users (WORKSPACE_USERS)
  • ZScaler Deception (ZSCALER_DECEPTION)

The following log types were added without a default parser. Each parser is listed by product name and log_type value, where applicable.

  • Akamai MFA (AKAMAI_MFA)
  • Azure Org Context (AZURE_ORG_CONTEXT)
  • Cisco Remote Access VPN (CISCO_RAVPN)
  • CoreView Audit-log SIEM integration (COREVIEW)
  • Fortinet Network Detection and Response (FORTINET_FORTINDR)
  • GCP Security Command Center Chokepoint (GCP_SECURITYCENTER_CHOKEPOINT)
  • Imperva Cloud WAF (IMPERVA_CLOUD_WAF)
  • Lumu Universal SIEM (LUMU)
  • Microsoft Azure Databricks (MICROSOFT_DATABRICKS_WORKSPACES)
  • Microsoft Insights/Components (MICROSOFT_INSIGHTS_COMPONENTS)
  • Microsoft ServiceBus/Namespaces (MICROSOFT_SERVICEBUS_NAMESPACES)
  • Microsoft Azure SQL Managed Instances (MICROSOFT_SQL_MANAGED_INSTANCES)
  • Moveworks (MOVEWORKS)
  • Network Box Unified Threat Management+ (NETWORKBOX_UTM)
  • Oracle Cloud Infrastructure Identity Cloud Service (OCI_IDENTITY_CLOUD_SERVICE)
  • SAP Commerce Cloud (SAP_HAC)
  • Sonatype Lifecycle (SONATYPE_LIFECYCLE)
  • TeamViewer Tensor (TEAMVIEWER_TENSOR)
  • Torq Audit Logs (TORQ_AUDIT_LOGS)
  • Velociraptor - digital forensic & incident response tool (VELOCIRAPTOR)
  • Zoom Activity Logs (ZOOM_ACTIVITY)

For a list of supported log types and details about default parser changes, see Supported log types and default parsers.

]]>
August 05, 2025 tag:google.com,2016:chronicle-release-notes#August_05_2025 2025-08-05T00:00:00-07:00 Feature

New YARA-L features

The following capabilities have been added to YARA-L 2.0 to enhance search precision, data analysis, and investigative workflows:

  • Conditions in UDM search and dashboards

    You can now filter aggregates defined in the outcome section using the new condition clause. This gives you more precise control over your results and supports more targeted investigations.

    • New functionality includes support for OR and n of [a, b, c.. z] expressions.

    • General availability for search and dashboards.

  • Deduplicate events in searches and dashboards

    The new dedup section lets you remove duplicate events after the match clause in both standard UDM searches and YARA-L 2.0 queries.

    General availability for search and dashboards.

  • Use metrics functions in UDM searches

    You can now apply metrics functions in the outcome section of your search to access aggregated historical data directly in your search queries.

    • Uses the same syntax as metrics in rules.
    • General availability for search.
  • Increased limits for array and array_distinct

    The element limit for array and array_distinct aggregation functions in YARA-L has increased from 25 to 1,000.

    • General availability for search and dashboards.
    • Private preview for rules.
  • Restrict search results using limit

    The limit keyword now lets you restrict the number of results returned by a search. Use this to quickly preview data, optimize performance, or focus on a subset of results.

    General availability for search and dashboards.

  • earliest and latest timestamps

    New earliest and latest timestamps let you extract the time range of your data (within microseconds) during aggregation.

    General availability for search.

  • Layer aggregations and analytics across multi-stage queries

    Recent updates to multi-stage queries let you:

    • Layer aggregations and data statistical functions. Calculate baselines, deviations, and trends across multiple stages of data processing.

    • Conduct joins both within and across stages.

    Private preview for search and dashboards. Contact your Google SecOps representative to enroll.

  • Join events, the entity graph, and data tables

    You can now perform Inner joins between events, the entity graph, and data tables. These queries require a match clause for these joins and return results as statistics.

    Private preview for search and dashboards. Contact your Google SecOps representative to enroll.

Feature

New YARA-L features

The following capabilities have been added to YARA-L 2.0 to enhance search precision, data analysis, and investigative workflows:

  • Conditions in UDM search and dashboards

    You can now filter aggregates defined in the outcome section using the new condition clause. This gives you more precise control over your results and supports more targeted investigations.

    • New functionality includes support for OR and n of [a, b, c.. z] expressions.

    • General availability for search and dashboards.

  • Deduplicate events in searches and dashboards

    The new dedup section lets you remove duplicate events after the match clause in both standard UDM searches and YARA-L 2.0 queries.

    General availability for search and dashboards.

  • Use metrics functions in UDM searches

    You can now apply metrics functions in the outcome section of your search to access aggregated historical data directly in your search queries.

    • Uses the same syntax as metrics in rules.
    • General availability for search.
  • Increased limits for array and array_distinct

    The element limit for array and array_distinct aggregation functions in YARA-L has increased from 25 to 1,000.

    • General availability for search and dashboards.
    • Private preview for rules.
  • Restrict search results using limit

    The limit keyword now lets you restrict the number of results returned by a search. Use this to quickly preview data, optimize performance, or focus on a subset of results.

    General availability for search and dashboards.

  • earliest and latest timestamps

    New earliest and latest timestamps let you extract the time range of your data (within microseconds) during aggregation.

    General availability for search.

  • Layer aggregations and analytics across multi-stage queries

    Recent updates to multi-stage queries let you:

    • Layer aggregations and data statistical functions. Calculate baselines, deviations, and trends across multiple stages of data processing.

    • Conduct joins both within and across stages.

    Private preview for search and dashboards. Contact your Google SecOps representative to enroll.

  • Join events, the entity graph, and data tables

    You can now perform Inner joins between events, the entity graph, and data tables. These queries require a match clause for these joins and return results as statistics.

    Private preview for search and dashboards. Contact your Google SecOps representative to enroll.

]]>

Warning: fread(): SSL operation failed with code 1. OpenSSL Error messages: error:0A000126:SSL routines::unexpected eof while reading in /hermes/walnacweb04/walnacweb04ab/b2791/pow.jasaeld/htdocs/De1337/nothing/index.php on line 845