gcp Google Cloud release notes ·

Google SecOps Updates: Debian/Podman Agents, Connector Size Limits, and EOL Forwarder

gcpdeprecationeolengineermedia
announcement deprecation

Google SecOps is announcing several updates, including support for Debian and Podman for Remote Agent installation, a new 25 MB limit for Publisher Connector packages, and an increased alert trimming limit. Notably, the forwarder component will reach end-of-life in January 2027, requiring migration of data collection workflows. Additionally, users of the CrowdStrike Detection Monitoring API connector must update API permissions before September 30, 2025, due to CrowdStrike's API decommissioning.

  • Debian support for Remote Agents
  • Podman support for Remote Agents
  • Forwarder component end-of-life and migration
  • Update CrowdStrike API permissions before decommission
  • Publisher Connector package size limit enforced
Deprecations (2)
  • Forwarder component end-of-life and migration

    The forwarder component of Google SecOps will reach end-of-life in January 2027. All data collection pipelines currently using the forwarder must be migrated to an alternative mechanism before April 1, 2027. Google recommends migrating to the Bindplane OpenTelemetry (OTel) collector.

  • Update CrowdStrike API permissions before decommission

    CrowdStrike is decommissioning its Detects API on September 30, 2025, replaced by the Alerts API. Google SecOps users leveraging the CrowdStrike Detection Monitoring API connector with the CS_DETECTS log type must update their API client permissions to read alerts before September 30, 2025, to avoid data ingestion disruption.

Features (2)
  • Debian support for Remote Agents

    Google SecOps now supports installing a Remote Agent using Debian, offering a streamlined deployment workflow as an alternative to existing methods. Detailed instructions can be found in the 'Deploy an agent with Debian' documentation.

  • Podman support for Remote Agents

    Remote Agents can now be installed using Podman, providing a lightweight and streamlined deployment option compared to existing methods. Further details are available in the 'Deploy an agent with Podman' documentation.

Enhancements (2)
  • Publisher Connector package size limit enforced

    A maximum size limit of 25 MB has been implemented for Publisher's Connector Packages.

  • Increased Alert Trimming limit for Remote Agent

    The default setting for Alert Trimming on the Remote Agent has been raised to 25 MB.

Read the original announcement →

https://cloud.google.com/release-notes#google-secops

Related releases