Skip to main content
Question

Querying data tables via the GoogleChronicle SOAR integration

  • May 5, 2026
  • 1 reply
  • 14 views

donkos
Forum|alt.badge.img+9

I have an playbook that extracts IOCs from an email, and then adds them to reference lists. These lists are then referred in stats UDM queries that are executed using the marketplace “Execute UDM Query” action in the Google Chronicle.

Reference lists will no longer be usable after Sep 2026 so I’m trying to replace them with data tables. However when doing testing and encountering a 400 error, a limitation was flagged to me saying that data tables cant be used in searches via the Chronicle API:

 

https://docs.cloud.google.com/chronicle/docs/investigation/data-tables#search-data-tables

Is that correct? given the nearing EoL deadline for reference lists, do we have an ETA on getting the limitation removed?

1 reply

cmorris
Staff
Forum|alt.badge.img+12
  • Staff
  • May 5, 2026

Data Table search support via the udmSearch API will be coming this quarter.