Skip to main content

Hey, I do not know if it is just me, but I think Chronicle/SecOps still has a lot to mature. From several issues I have had with the tool, 3 have ended in Feature Requests. 2 are related with audit logging (which does not seem as a new functionality but rather as something the product should already have and probably will take a while to be implemented) and the other is a visual thing which is a minor thing. There are still a lot of references to siemplify (the solution, just delete the references, but c'mon what about the howto? wouldnt it better to upgrade?). SIEM and SOAR give the sensation that are two different products (just look how even the SIEM and SOAR admin GUI is different from each other or how SOAR logging is not integrated with GCP). The CLI is limited and the training usually is not updated.

Any thoughts? Might be just me? Thank you!

Hi Keso,


You are correct that SIEM and SOAR are two different products (Backstory and Siemplify), but there has been a lot of work over the last two years to merge the two together, i.e., SecOps. 


In 2025 SecOps SOAR will move to use the Chronicle API (chronicle.googleapis.com), which will provide a unified API, enable more consistent UX workflows, and will provide an audit trail for SOAR activity that will align with the existing audit trail for SecOps SIEM.


Regarding the legacy names of prior products, a lot of these have been replaced, but in some cases they may have been missed, or technical components are still called Siemplify, e.g., Marketplace Integrations, the original name is left as is (as it wouldn't make sense to change if it doesn't match).


SecOps is less than 5 years old as a go to market platform, so depending on what you're comparing to in some areas may appear less mature, but SecOps is a very actively developed platform within Google, and Feature requests and feedback either direct or via this community is welcomed, and helps to mature the platform.


Best Regards,


Chris


Reply