gcp Google Cloud release notes ·

Google SecOps SIEM enhances default parser support for diverse security logs

securityawsazuregcppreviewengineer
feature patch

Google SecOps SIEM has updated its list of supported default parsers, significantly enhancing its ability to ingest and analyze security logs from a broader range of sources. This expansion includes parsers for numerous cloud platforms and security products, such as AWS, Azure, various firewalls, and endpoint detection tools. The updates are being rolled out gradually to all regions over one to four days. Additionally, users can now view the content of prebuilt parser preview versions, even when custom parsers are active for the same log type.

  • View prebuilt parser version content
Features (1)
  • Google SecOps SIEM View prebuilt parser version content

    View prebuilt parser version content You can now view the prebuilt parser preview version content even if you are using a custom parser for the same log type. Although the prebuilt parser version is inactive, you can still see the content of the new preview version for this parser.

Enhancements (1)
  • Google SecOps SIEM

    Google SecOps has updated the list of supported default parsers . Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region. The following supported default parsers have been updated. Each parser is listed by product name and log_type value, where applicable. This list includes both released default parsers and pending parser updates. Airlock Digital Application Allowlisting ( AIRLOCK_DIGITAL ) AIX system ( AIX_SYSTEM ) Akamai DataStream 2 ( AKAMAI_DATASTREAM_2 ) Akamai SIEM Connector ( AKAMAI_SIEM_CONNECTOR ) Apache ( APACHE ) Arcsigh

Read the original announcement →

https://docs.cloud.google.com/release-notes#July_29_2026

Related releases