Hi all,
We're seeing repeated 429 / RESOURCE_EXHAUSTED errors when our SOAR playbook closes cases via the Chronicle API. Looking for guidance on which quota this is hitting and what a reasonable limit increase request would look like.
Environment:
- Google SecOps / Chronicle SOAR (Siemplify-based)
- Custom integration action that calls cases.executeBulkClose, plus several read calls (get_case, list_custom_fields, get_case_custom_fields, list wall records) per case closure
- Closing cases in batches (currently ~50+ 'Overflow' cases in a single run)
Error returned:
{
"error": {
"code": 429,
"message": "You have reached the maximum allowed quota for this operation. Please wait until the quota is refreshed or reduce API calls rate. You can check your quota limits here: https://console.cloud.google.com/apis/api/chronicle.googleapis.com/quotas",
"status": "RESOURCE_EXHAUSTED"
}
}
Questions:
1. Is there a per-method breakdown of Chronicle API quotas (e.g., is listCustomFields limited separately from executeBulkClose), or is this a single project-wide quota across all Chronicle API calls?
2. What's a typical/default quota limit for these operations, and is a quota increase request the recommended path for higher-volume batch case closures, or is there a preferred bulk/batch endpoint we should be using instead?
3. Are there Chronicle API best practices for batch-closing large numbers of cases (e.g., recommended pacing, batch size limits, or a dedicated bulk endpoint that counts differently against quota than repeated single-case calls)?
Any guidance from folks who've hit this at scale, or from the Chronicle team, would be appreciated. Happy to share more logs/config if useful.
Thanks!



