Google SecOps deprecates legacy SIEM APIs
Google Security Operations is deprecating its legacy SIEM APIs, including the Backstory and Ingestion APIs, in favor of the modern Chronicle API. This change impacts custom scripts, integrations, and ingestion feeds that use these legacy endpoints. Full deprecation is scheduled for July 20, 2027, with new instances no longer supporting legacy calls from October 26, 2026.
Deprecations (1) ›
- Google SecOps [Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs Google Security Operations is deprecating its legacy SIEM APIs— Backstory API (including Customer Management API ) and Ingestion API —in favor of the modern Chronicle API . Key dates October 26, 2026: New Google SecOps instances provisioned from this date will no longer support legacy API calls. July 20, 2027: All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down. This change applies only to custom scripts, integrations, SOAR connectors, or
https://docs.cloud.google.com/release-notes#July_20_2026
Related releases
- Cloud SDK 578.0.0: Database Migration default change, AlloyDB backup DR GA, BigQuery improvements Google Cloud release notes ·
- GKE: Opt-out of Arm taint, CORS for Gateways Google Cloud release notes ·
- Confidential VM: August 2026 kernel update may impact AMD SEV-SNP instances Google Cloud release notes ·
- Security Command Center ServiceNow Integration Updates Google Cloud release notes ·
- Compute Engine C4D Instances Increase Hyperdisk Throughput Google Cloud release notes ·
- Spanner allows creating tables without explicit primary keys Google Cloud release notes ·