gcp Google Cloud release notes ·

Google SecOps Enhances Threat Detection with Custom Rule Schedules and Revamped Case Management

securitygcppreviewengineer
feature

Google SecOps introduces two new capabilities in public preview: customizable schedules for multi-event rules and an updated investigation and case management experience. The custom rule schedules allow users to account for data ingestion latency, reducing false negatives and enhancing alert accuracy. The revamped investigation management supports diverse investigation types and higher volumes, providing tools to track UDM events and detections alongside alerts, with capabilities like attaching SIEM search results and an interactive events viewer. These enhancements are aimed at security engineers and analysts, though the new case management is currently limited to single-SIEM deployments.

  • Customizable schedules for multi-event rules
  • [Spotlight Feature] Investigation and case management experience
Features (2)
  • Google SecOps Customizable schedules for multi-event rules

    Customizable schedules for multi-event rules Customizable schedules for multi-event rules are available in public preview. You can customize rule execution schedules on the Rule schedule tab to specify a first-run delay offset that accounts for data ingestion latency. The system also performs automated background true-up runs to catch late-arriving logs and process metadata enrichment without requiring manual system interventions. This gives you precise control over detection evaluation timing, reduces false negatives without missing detections, and promotes alert accuracy. To view or modify r

  • Google SecOps [Spotlight Feature] Investigation and case management experience

    [Spotlight Feature] Investigation and case management experience This feature is in public preview. Google SecOps now includes a revamped Investigation Management experience that supports tracking raw UDM events and detections alongside alerts to accommodate new investigation types (such as retrohunt and threat hunt) and higher investigation volumes in cases. You can navigate your case queue using customizable table views, side-drawer previews, and integrated UDM Search workflows. For more information, see Investigation and case management overview . This preview is currently supported only fo

Read the original announcement →

https://docs.cloud.google.com/release-notes#July_26_2026

Related releases