Hey, I do not know if it is just me, but I think Chronicle/SecOps still has a lot to mature. From several issues I have had with the tool, 3 have ended in Feature Requests. 2 are related with audit logging (which does not seem as a new functionality but rather as something the product should already have and probably will take a while to be implemented) and the other is a visual thing which is a minor thing. There are still a lot of references to siemplify (the solution, just delete the references, but c'mon what about the howto? wouldnt it better to upgrade?). SIEM and SOAR give the sensation that are two different products (just look how even the SIEM and SOAR admin GUI is different from each other or how SOAR logging is not integrated with GCP). The CLI is limited and the training usually is not updated.
Any thoughts? Might be just me? Thank you!