Feature deprecations
The Google Cloud Platform Terms of Service (section "Discontinuation of Services") defines the deprecation policy that applies to Google Security Operations. The deprecation policy only applies to the services, features, or products listed therein.
After a service, feature, or product is officially deprecated, it continues to be available for at least the period of time defined in the Terms of Service. After this period of time, the service is scheduled for shutdown.
The following table lists feature deprecations and their related shutdown schedules for Google Security Operations.
GOOGLE_CLOUD_STORAGE
, AMAZON_S3
, AMAZON_SQS
, and AZURE_BLOBSTORE
.The new v2 framework uses the Google Cloud Storage Transfer Service (STS) for improved reliability, scalability, and performance.
Action required: You must migrate your feeds to the v2 framework before the March 15, 2027 end-of-life date to avoid interruption to data ingestion. Google SecOps will automatically migrate your cloud storage data feeds using v1 connectors to v2 connectors in waves starting from April 10, 2026. To facilitate this, customers might be required to take certain actions, such as updating IP allowlists or service account permissions. You can also self-migrate by replacing your existing data feeds using v1 connectors with new feeds using v2 connectors, by following the configuration guide for v2 connectors .
Key dates:
- April 10, 2026: auto-migration commences.
- September 15, 2026: Support for v1 connectors is discontinued.
- March 15, 2027: v1 feeds officially reach end-of-life and will stop returning data.
chronicle.soarAnalyst
, chronicle.soarViewer
, and chronicle.soarEngineer
roles in Cloud IAM are deprecated and will be removed. These roles were non-operational and are being replaced by Google Cloud IAM functionality as part of the SOAR Migration. To maintain access, transition users to pre-defined roles
or use the self-service migration
to convert Permission Groups to custom roles.MICROSOFT_GRAPH_ALERT
log type are pointing towards the legacy alerts endpoint, you must update the API Full Path in your feed configuration to switch to the alerts_v2
endpoint instead, as described in How to set up Microsoft Graph API alerts
. After the shutdown date, configurations using Legacy Alerts will stop returning data.ListAvailableLogTypes
APIListAvailableLogTypes
API is deprecated. To get a list of all log types, you can now use the logTypes.list
API.Action required: If you're currently using the forwarder component, you must migrate your data collection workflows to an alternative mechanism before April 1, 2027. You'll need to use another data pipeline management application for log ingestion.
We recommend that you migrate to the Bindplane OpenTelemetry (OTel) collector , which provides a scalable, open-standard solution for log and metric ingestion.
The following are key dates to note:
- Apr 1, 2026: New Google SecOps customers cannot use the forwarder component.
- Jan 1, 2027: The forwarder is officially EOL. No further patches, including security patches, will be released.
- Apr 1, 2027: Data is no longer allowed to be ingested from the forwarder component.
All existing reference lists will be transparently migrated to data tables. This migration is fully automatic and requires no action on your part. There is no expected downtime, ingestion delay, or service limitation during the migration window.
During this migration period, you can continue to use your existing reference lists until they're migrated. In September 2026, the legacy reference list functionality will be fully retired from the platform. At that time, all data will be accessible through the data table interface.
This change doesn't affect Google Security Operations Enterprise Plus customers.
idm.is_significant
and idm.is_alert
have been deprecated. Use YARA-L detection rule alerts
for alert metadata.Symantec Event Export
API feedSymantec Event Export
has been discontinued due to the deprecation of Symantec Event Export API
. To ingest data, use a Cloud Storage bucket. For more information, see Add a feed
and Adding a Data Bucket event stream type
.ingestion_stats
table in BigQueryingestion_stats
table in BigQuery has been deprecated and will no longer be updated after May 15, 2024. Existing data is retained until May 15, 2025. Use the Google SecOps ingestion_metrics
table in BigQuery, which provides more accurate ingestion metrics. Additionally, real-time alerting on ingestion metrics is also available in Google Security Operations Cloud Monitoring integration
.labels
fields for UDM nounslabels
fields for UDM nouns are deprecated: about.labels
, intermediary.labels
, observer.labels
, principal.labels
, src.labels
, security_result.about.labels
, and target.labels
. For existing parsers, in addition to these UDM fields, the logs fields are also mapped to key/value additional.fields
UDM fields. For new parsers, the key/value settings in additional.fields
UDM fields are used instead of the deprecated labels
UDM fields. We recommend that you update the existing rules to use the key/value settings in the additional.fields
UDM fields instead of the deprecated labels
UDM fields.udm_events
tableudm_events
table in Chronicle-managed BigQuery projects will be fully replaced with a new table named events
. This new table is currently available for all Customers
. Chronicle will handle all changes in-product for this new table. Customers issuing queries against the udm_events
table through Cloud Console, API, or directly connecting to BQ should fully migrate queries to the new table by July 1 to avoid interruption. When migrating SQL queries to use the new Event table, also replace the _PARTITIONTIME field with the new hour_time_bucket field.MICROSOFT_SECURITY_CENTER_ALERT
log typeMICROSOFT_SECURITY_CENTER_ALERT
log type has been removed. Logs previously fetched by the MICROSOFT_SECURITY_CENTER_ALERT
feed are now a part of the MICROSOFT_GRAPH_ALERT
feed. If you have a feed configured using the MICROSOFT_SECURITY_CENTER_ALERT
log type, you can create a new feed using the MICROSOFT_GRAPH_ALERT
log type. For more information about the MICROSOFT_GRAPH_ALERT
log type, see Microsoft Graph Security API Alerts
.
