Stay organized with collections Save and categorize content based on your preferences.
Jump to

Chronicle Security Operations

Chronicle Security Operations (comprising Chronicle SIEM, Chronicle SOAR, and Threat Intelligence) is a modern, cloud-native suite that enables security teams to detect, investigate, and respond to cyber threats with the speed, scale, and intelligence of Google. 

  • 12 months of telemetry retention to enable longer IoC correlation & uncover persistent threats

  • Out-of-the-box detections leverage Google’s collective insights and threat intelligence 

  • Deep context and visualizations surface impactful information to uncover threat insights

  • Threat-centric approach groups related alerts into threat-centric cases to streamline responses

  • Packaged response playbooks and case management to simplify security operations


All your data

Eliminate security blind spots by ingesting all your data at a disruptive cost.

At your fingertips

Accelerate threat understanding with faster time to “aha” with insights at your fingertips.

With Google intelligence

Democratize security operations by leveraging Google’s unparalleled cyber intelligence.

Key features

What you get with Chronicle Security Operations

Chronicle SIEM

A cloud-native security information and event management (SIEM) solution designed to enable security teams to detect, investigate, and hunt threats. Scale your SOC with context-aware and curated detections, build new detections with a powerful detection authoring platform, and prioritize alerts with risk scoring. 

Chronicle SOAR

A modern security orchestration automation and response (SOAR) solution driving effective response to threats with playbook automation, case management, and collaboration. 

Threat intelligence

Detect advanced attacks and drive context-aware investigations with threat intelligence via Google Cloud Threat Intelligence and VirusTotal.


Learn how customers are driving outcomes with Chronicle Security Operations

morgan sindall group

"Our customers trust us to look after their data, so our reputation is important to us. But the bad guys are out there and they’re not going away. We feel that Chronicle is the best tool available to us in countering potential attacks."

Neil Binnie, Head of Information Security and Compliance, Morgan Sindall

What's new

Check out our latest reports

Sign up for Google Cloud newsletters to receive product updates, event information, special offers, and more.


Explore Chronicle Security Operations

Autonomic Security Operations: 10x transformation of the SOC

Learn about Autonomic Security Operations with Google's prescriptive solution on SOC modernization across people, products, and processes. 

Best Practice
Modernizing threat detection and response

Learn how to modernize threat detection and response with Google’s cloud-native Chronicle SIEM and SOAR with this webinar.

Google Cloud and Deloitte: future of the SOC

Download your copy of our white paper to learn more about the forces shaping modern security operations and challenges that must be overcome to continuously mature.

Google Cloud Basics
Chronicle SOAR Marketplace

Check out our integrations, use cases, playbook components, and analytics needs to get up and running with SecOps in no time.

Use Case
Chronicle Security Operations Security Analyst Diaries

Learn how our customers are using Chronicle Security Operations with our practitioner-focused video podcast series, Security Analyst Diaries.


Talk to a security operations expert

Schedule time with a security operations expert to answer technical questions, discuss pricing, or take a deeper dive into the Chronicle Security Operations suite.