Google SecOps: The SIEM's Third Act, published by SANS Institute in January 2025, is a product review examining whether Google SecOps represents a viable evolution of the SIEM platform beyond log collection and threat detection consolidation. The review evaluates SecOps' data ingestion, detection engineering, investigation workflows, SOAR automation, and AI-assisted capabilities from the perspective of practitioners with decades of security operations experience.
Key findings:
- SecOps ingests, normalizes, and analyzes security data using Google's infrastructure, supporting on-premises collection agents and native APIs for AWS, Azure, and Google Cloud
- The platform provides hundreds of prebuilt parsers and converts all ingested data to a Unified Data Model (UDM) for consistent search and detection
- An autonomous parsing feature, currently in preview, uses machine learning to reduce the engineering overhead of building and maintaining custom parsers
- SecOps includes a library of hundreds of curated detections actively maintained by the Google Threat Intelligence team, built on the YARA-L detection language
- Risk Analytics and UEBA capabilities calculate customizable risk scores for users and assets across authentication, network traffic, peer group behavior, and data loss prevention
- Natural language search allows analysts to query SIEM data in plain English, with Gemini converting queries into UDM search syntax automatically
- Gemini is integrated throughout the platform to summarize detection rules, explain alerts, generate case overviews, and recommend investigative next steps
- Google Threat Intelligence combines Mandiant frontline incident response data, VirusTotal crowd-sourced intelligence, and Chrome Safe Browsing data from billions of devices
- SOAR capabilities, built on the Siemplify platform Google acquired in 2022, include a graphical Playbook Designer and an AI-assisted Playbook Assistant for natural-language playbook creation
- Dashboarding is built on Google's Looker business intelligence tool, with a Native Dashboards feature planned to eventually replace it
The review concludes that Google SecOps successfully integrates search performance, threat intelligence, and AI-assisted automation into a SIEM that avoids the complexity and scope creep that has affected the broader product category. Its AI-generated case summaries and natural language search were highlighted as standout capabilities that reduce analyst triage time, though the review notes that Gemini's outputs still require human validation as the technology matures.
This review was conducted by a SANS analyst and practitioner based on hands-on evaluation of the Google SecOps platform, drawing on direct experience across SIEM data collection, threat detection, investigation, and SOAR functions.