Google SecOps Updates: Debian/Podman Agents, Connector Size Limits, and EOL Forwarder
Google SecOps is announcing several updates, including support for Debian and Podman for Remote Agent installation, a new 25 MB limit for Publisher Connector packages, and an increased alert trimming limit. Notably, the forwarder component will reach end-of-life in January 2027, requiring migration of data collection workflows. Additionally, users of the CrowdStrike Detection Monitoring API connector must update API permissions before September 30, 2025, due to CrowdStrike's API decommissioning.
- →Debian support for Remote Agents
- →Podman support for Remote Agents
- →Forwarder component end-of-life and migration
- →Update CrowdStrike API permissions before decommission
- →Publisher Connector package size limit enforced
Deprecations (2) ›
- Forwarder component end-of-life and migration
The forwarder component of Google SecOps will reach end-of-life in January 2027. All data collection pipelines currently using the forwarder must be migrated to an alternative mechanism before April 1, 2027. Google recommends migrating to the Bindplane OpenTelemetry (OTel) collector.
- Update CrowdStrike API permissions before decommission
CrowdStrike is decommissioning its Detects API on September 30, 2025, replaced by the Alerts API. Google SecOps users leveraging the CrowdStrike Detection Monitoring API connector with the CS_DETECTS log type must update their API client permissions to read alerts before September 30, 2025, to avoid data ingestion disruption.
Features (2) ›
- Debian support for Remote Agents
Google SecOps now supports installing a Remote Agent using Debian, offering a streamlined deployment workflow as an alternative to existing methods. Detailed instructions can be found in the 'Deploy an agent with Debian' documentation.
- Podman support for Remote Agents
Remote Agents can now be installed using Podman, providing a lightweight and streamlined deployment option compared to existing methods. Further details are available in the 'Deploy an agent with Podman' documentation.
Enhancements (2) ›
- Publisher Connector package size limit enforced
A maximum size limit of 25 MB has been implemented for Publisher's Connector Packages.
- Increased Alert Trimming limit for Remote Agent
The default setting for Alert Trimming on the Remote Agent has been raised to 25 MB.
https://cloud.google.com/release-notes#google-secops
Related releases
- BigQuery Graph Adds Measures Support for Agentic Workloads (Preview) Google Cloud Blog ·
- Access Transparency for Firebase App Hosting enters Preview Google Cloud release notes ·
- Error Reporting Adds Rust Stack Trace Support on GCP Google Cloud release notes ·
- Firebase App Hosting Access Approval enters Preview Google Cloud release notes ·
- Apigee X Maintenance Updates Begin for Instances with Preferred Windows Google Cloud release notes ·
- Cloud Workstations adds Compute Engine VM suspend and resume in Preview Google Cloud release notes ·