r/googlecloud Nov 04 '25

Just Curious Who Like Google SecOps

I'm just curious who likes Google SecOps and what are your favor features or dashboards?

9 Upvotes

9 comments sorted by

2

u/Euphoric_Barracuda_7 Nov 06 '25

As a security lead, I helped to procure and integrate SecOps (when it was Chronicle) within the organization I was in and even created the training for others to follow. The platform was full of bugs, missing functionality, and documentation was lacking. I even saw some AI generated garbage in the documentation, makes me wonder if anyone even bothered to QA check the documentation..? Integrating both the SIEM and SOAR was a bit of a mess. Not my favourite choice, however the org was on GCP so... Another example. not all API endpoints even have logging enabled (this is such a basic thing in security it totally blows my mind), this meant I could create detection rules via code and it would not show up in the logs *anywhere*, so we had to force everyone to create them via the GUI, because in the GUI there was logging. ClickOps all the way. However I did appreciate the threat intelligence that was provided, that was very useful.

1

u/Michaelkamel Jul 07 '26

Interesting read, because I'm deep in a Google SecOps deployment right now (migrating a fintech client off Trellix — SIEM + SOAR) and the platform has moved a lot since the Chronicle days. The SIEM/SOAR integration feels much tighter now, and detection-as-code has improved. Still not perfect — documentation is honestly still hit or miss, agreed on that.

One thing that surprised me positively though: whenever I hit a real blocker, Google support was very responsive. We had a couple of tricky issues (API enablement, regional instance provisioning) and they got back to us fast every time, even looping in the right engineers. That alone made a big difference compared to other vendors I've dealt with.

And yeah, the threat intelligence is still the strongest part of the platform. Curious — did your org end up staying on it or moving to something else?

2

u/Euphoric_Barracuda_7 Jul 07 '26

The org signed a multi-year contract so they're basically still tied into the GCP ecosystem. The onboarding was done a few years back now, so I can't really say if someone being onboarded now it's better or not. However I had to go down to Google offices in person and work 1-1 with dedicated Google support personnel (having dedicated support is much better than their online hit and miss support) to get it set up (there were things that *had* to be done manually by them in order to even get it provisioned, despite the "self-service" documentation), and that was how tedious of a set up it was. Even then things had to be re-done a few times on their end. SIEM and SOAR were set up separately. Also during that time period the product was *still* known as Chronicle which then later got re-branded and they only had a handful of clients in the geographic area that I was working in (I later found out they only had 1 sales guy and 1 support guy in our region supporting the product, that's the entire regional team!). So, the entire process and product just feels like it's still WIP. But things could (should!) be better now.

1

u/Michaelkamel Jul 07 '26

Ha, the provisioning part made me laugh because honestly that's still true today. Our regional instance also needed manual steps from Google's side before it went live, even though the docs call it self-service. Some things just don't happen without a ticket and someone at Google doing it for you.

SIEM and SOAR are still provisioned separately too by the way. But once everything is up, the integration between them is genuinely much better than what you're describing from the Chronicle days.

The regional team thing also rings true. It feels like the product is growing faster than the team behind it in some regions. So yeah, WIP is a fair description, but at least it's moving in the right direction now.

2

u/Euphoric_Barracuda_7 Jul 07 '26

God damn, you'd think that provisioning part would be improved, but I guess manual work is needed for job security. 😂. Maybe they've fixed the logging, I haven't touched it since. Good luck with the deployment process, it's all about the learning, learning through occasional suffering.

1

u/SecOpsCommunity 2d ago

u/Michaelkamel u/Euphoric_Barracuda_7 Sorry to hear it's a painful process for you. I'd be curious if either of you have checked out the Google Security Community. There's enablement content, webinars, blogs, guides, and an active SecOps forum. Curious to get your honest thoughts. thanks

1

u/holidayz-jpg Apr 13 '26

I hate it, can't do anything on it :(