Google SecOps Enhances Threat Detection with Custom Rule Schedules and Revamped Case Management
Google SecOps introduces two new capabilities in public preview: customizable schedules for multi-event rules and an updated investigation and case management experience. The custom rule schedules allow users to account for data ingestion latency, reducing false negatives and enhancing alert accuracy. The revamped investigation management supports diverse investigation types and higher volumes, providing tools to track UDM events and detections alongside alerts, with capabilities like attaching SIEM search results and an interactive events viewer. These enhancements are aimed at security engineers and analysts, though the new case management is currently limited to single-SIEM deployments.
- →Customizable schedules for multi-event rules
- →[Spotlight Feature] Investigation and case management experience
Features (2) ›
- Google SecOps Customizable schedules for multi-event rules
Customizable schedules for multi-event rules Customizable schedules for multi-event rules are available in public preview. You can customize rule execution schedules on the Rule schedule tab to specify a first-run delay offset that accounts for data ingestion latency. The system also performs automated background true-up runs to catch late-arriving logs and process metadata enrichment without requiring manual system interventions. This gives you precise control over detection evaluation timing, reduces false negatives without missing detections, and promotes alert accuracy. To view or modify r
- Google SecOps [Spotlight Feature] Investigation and case management experience
[Spotlight Feature] Investigation and case management experience This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking raw UDM events and detections alongside alerts to accommodate new investigation types (such as retrohunt and threat hunt) and higher investigation volumes in cases. You can navigate your case queue using customizable table views, side-drawer previews, and integrated UDM Search workflows. For more information, see Investigation and case management overview . This preview is currently supported only fo
https://docs.cloud.google.com/release-notes#July_26_2026
Related releases
- GKE introduces Agent Substrate to scale agentic workloads efficiently Google Cloud release notes ·
- Apigee X fixes SemanticCacheLookup incompatibility with Vertex AI Vector Search PSC Google Cloud release notes ·
- Cluster Toolkit v1.102.0 Enhances GKE with MTC, Flex Volumes, and HPC Capabilities Google Cloud release notes ·
- Google Cloud's Managed Apache Airflow receives new features and improved resilience Google Cloud release notes ·
- Google Cloud CCaaS v6.12 Adds Cold Transfer Auto-Resume, HubSpot DNC, & Network Diagnostics Google Cloud release notes ·
- Google Addresses Security Vulnerabilities in Slurm for Cluster Toolkit Google Cloud release notes ·