Skip to main content
Question

ENTITY_RISK_CHANGE events no longer being generated

  • July 30, 2026
  • 2 replies
  • 23 views

tsvetathuntandhackett
Forum|alt.badge.img

Hello,

I have a question regarding `ENTITY_RISK_CHANGE` events in Google SecOps.

I ran the following search:

```yaral
metadata.event_type = "ENTITY_RISK_CHANGE"
```

and can successfully retrieve matching events. However, the most recent events are dated 13 May; no newer `ENTITY_RISK_CHANGE` events appear after that date. We have observed the same behavior across multiple tenants.

I checked with our internal team, and they confirmed that no intentional configuration changes were made around that time. We manage these resources through Terraform, so we would expect any relevant change to be visible in our Git history.

Could `ENTITY_RISK_CHANGE` event generation have moved behind a feature, entitlement, or licence requirement? I have reviewed the available Google docs and other public sources but have not found an explanation.

Could you please tell me whether there were any product, licensing, configuration, or rollout changes that could cause these events to stop being generated?

Thank you.

2 replies

cmorris
Staff
Forum|alt.badge.img+16
  • Staff
  • July 30, 2026

This likely needs a support case. Working in my tenant and not aware of any changes.


whathehack81
Forum|alt.badge.img+7

If a support case is created I think it would make it easier for support if the customer said something like ....…

 

We are seeing a complete stop in newly generated ENTITY_RISK_CHANGE events after 13 May, while historical events remain queryable and underlying data ingestion appears normal. This behavior is reproducible across multiple tenants, and no configuration, Terraform, or licensing changes were made on our side. Could you verify whether the ENTITY_RISK_CHANGE generation pipeline is operating correctly for our tenants and whether any backend changes, feature flags, entitlement changes, or known regressions could explain why new derived events are no longer being generated? 

 

That might help support get straight to the issue, and not have to rely and wasted time for a lengthy investigation.