Title: Google Chronicle SOAR Integration Fails "Test Connection" with GA v1 1Platform Endpoint (/ioc/listiocs 404 JSONDecodeError)
Product: Google Security Operations (SOAR & SIEM)
Integration: Google Chronicle (Marketplace Integration)
1. Description of the Issue
Google’s official Chronicle API Migration Documentation instructs customers migrating away from legacy APIs (Backstory / Ingestion) to use the 1Platform General Availability (GA) regional template:
https://{region}-chronicle.googleapis.com/v1/projects/{project}/locations/{location}/instances/{instance_id}
However, when configuring the official Google Chronicle integration instance inside Google SecOps SOAR using this documented GA v1 endpoint, clicking Test fails immediately with the following error:
Status: 2: Result Value: false
Output Message: Authentication with Workload Identity to Google Chronicle server resulted in failure.
Error: Unable to connect to Google Chronicle, please validate your credentials: Unable to list IOCs: Expecting value: line 1 column 1 (char 0).
2. Root Cause Analysis
By inspecting the integration logs and testing the endpoints directly, the technical root cause is clear:
- Hardcoded Legacy Test Call: When the Test button is pressed, the SOAR connector’s packaged Python script executes a connectivity ping that attempts to query the legacy Backstory IOC path:
/ioc/listiocs. - Missing from Strict GA
v1Schema: In the 1Platform GA endpoint (https://{region}-chronicle.googleapis.com/v1/...), the legacy/ioc/listiocspath has been deprecated and removed. As a result, the Google API gateway returns an HTTP 404 HTML page (<!DOCTYPE html>...). - JSON Parser Crash: The integration's Python code attempts to deserialize this HTML response with
response.json()(orjson.loads()). Because HTML cannot be parsed as JSON, Python throws:json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0)
The integration then misidentifies this parser crash as an authentication/credential failure ("Unable to connect to Google Chronicle, please validate your credentials").
3. Current Workaround (Why We Are Forced to Use v1alpha)
If customers change the API Root in SOAR to the legacy/early-access endpoint:
https://chronicle.{region}.rep.googleapis.com/v1alpha/projects/{project}/locations/{location}/instances/{instance_id}
The connection test passes green immediately, ingestion works, and playbooks execute without issue.
This is because the v1alpha gateway still retains legacy routing that satisfies the integration's /ioc/listiocs check, whereas the official GA v1 endpoint does not.
4. Business Impact
Customers attempting to follow Google's official best practices and migrate their SOAR environments to the GA v1 production endpoint are blocked from doing so. Teams are forced to remain on the early-access v1alpha endpoint, leaving uncertainty about future deprecation and turn-down dates.
5. Suggested Remediation for Google SecOps Engineering
Please update the Google Chronicle SOAR marketplace integration package to modernize the test_connectivity / ping action:
- Remove the dependency on
/ioc/listiocs. - Validate connection using a GA
v1endpoint, such as:GET https://{region}-chronicle.googleapis.com/v1/projects/{project}/locations/{location}/instances/{instance_id}(instances.get), or- A lightweight query to
:udmSearchwithlimit=1.

