gcp Google Cloud release notes ·

Google SecOps SIEM Adds `match_all` Option to Grok Filter Parser Syntax

securitygcpgaengineer
feature

Google SecOps SIEM has updated its parser syntax to include the `match_all` option within the Grok filter. This enhancement allows users to extract all non-overlapping pattern occurrences from a field, rather than being limited to only the first match. The change provides more comprehensive data extraction capabilities for security operations teams. Further details are available in the updated Parser syntax reference.

Features (1)
  • Google SecOps SIEM Grok filter match_all option in parser syntax

    Grok filter match_all option in parser syntax The Google SecOps parser syntax is updated to support the match_all option within the Grok filter. This allows parsers to extract all non-overlapping pattern occurrences within a field, rather than returning only the first match. For more information, see Parser syntax reference .

Read the original announcement →

https://docs.cloud.google.com/release-notes#September_15_2026

Related releases