Skip to main content
Google Cloud Documentation
Documentation
  • Get Started
  • Get Started with Google Cloud
  • Product List
  • Cloud Customer Care
  • Featured Products
  • Agent Platform
  • Apigee API Management
  • BigQuery
  • Compute Engine
  • Cloud CDN
  • Cloud Run
  • Cloud Storage
  • Cloud SQL
  • Gemini Enterprise
  • Google Kubernetes Engine
  • Looker
  • Cross-product Tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
  • Technology Areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
/
Console
  • English
  • Deutsch
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • Google Security Operations
Start free
Overview Guides Use cases Reference Support Resources
Google Cloud Documentation
  • Documentation
    • More
    • Overview
    • Guides
    • Use cases
    • Reference
    • Support
    • Resources
  • Console
  • Discover
  • Introduction
    • Google SecOps overview
    • Google Unified Security overview
    • Recommended Google Unified Security products
    • Understand the Google SecOps platform
    • Google SecOps architecture
  • Google SecOps lifecycle
    • Collect data
      • Data ingestion overview
      • UDM overview
    • Detect threats
      • Applied Threat Intelligence overview
      • Get started with YARA-L
    • Investigate alerts
      • Investigation and case management overview
      • Investigate alerts and entity context
    • Respond to alerts
      • Playbook automation overview
      • Embed AI agents in playbooks
      • Respond to alerts and cases
    • Manage and monitor
      • Content Hub overview
      • Ingestion metrics overview
      • Dashboards overview
  • Gemini in Google SecOps
    • Overview
    • Access in-product help with Gemini
  • Licensing
    • Google SecOps packages overview
    • Google SecOps Security Tokens overview
  • Get started
  • Access a Google SecOps instance
  • Log in to Google SecOps
  • Navigate the Google SecOps platform
  • Configure user preferences
  • Administer
  • Set up an instance
    • Deploy an instance
    • Understand your billing
    • Configure a Google Cloud project
    • Link an instance to Google Cloud
    • Configure authentication
      • Configure Google Cloud identity
      • Configure third-party identity
      • Change authentication
  • Configure feature access
  • Configure data access
    • Data RBAC overview
    • Configure data RBAC
    • Manage RBAC impact
      • Overview
      • Control access to dashboards
      • Control access to data tables
      • Control access to 1P cases and alerts
      • Control access to reference lists
    • Configure legacy RBAC
  • Configure SOAR access
    • Overview
    • Manage permission groups
      • Overview
      • Understand user groups
      • Create a managed user
      • Create a collaborator user
      • Create a view-only user
    • Manage SOC roles
    • Manage environments
      • Overview
      • Manage environment groups
      • Configure custom environment groups
    • Enable access
      • Enable SOAR access
      • Map users with Cloud identity
      • Map users with third-party identity
      • Apply multiple control access parameters
    • Enable federated access
    • View all users
    • Delete a user account
  • Configure compliance
    • Supported compliance standards
    • Data encryption at rest and in transit
    • Configure CMEK
    • Configure VPC service controls
  • Configure MCP
  • Configure instance settings
    • Manage operational settings
      • Define a landing page
      • Rebrand your platform
      • Set time zone
      • Configure email settings
      • Manage preview features
    • Manage data retention
      • Configure SIEM data retention
      • Configure SOAR data retention
    • Monitor and audit platform activity
      • Manage audit logs
      • Monitor user activities
    • Manage administrative assets
      • Create custom lists
      • Create email HTML templates
      • Create email templates
      • Add variables to email templates
      • Create user requests
      • Manage properties metadata
      • Retrieve raw Python logs
    • Manage case settings
      • Manage case stages
      • Configure case naming conventions
      • Create custom fields for cases
      • Manage custom case closure fields
      • Configure the close case dialog
      • Configure the default case view
    • Manage alert settings