Security analytics & SIEM · Google LLC
Google Security Operations
Google Cloud's SIEM, built on the Chronicle backend, offering high-volume, long-retention log search with integrated threat intelligence.
Google Security Operations (formerly Chronicle, and before that Chronicle Security Operations) is Google Cloud's SIEM, built on infrastructure originally designed for Google-scale log search, which it uses to offer flat-rate ingestion with long retention windows rather than charging per query or per scanned byte. It bundles Google-curated threat intelligence (including Mandiant and VirusTotal signal) directly into detections, and increasingly layers Gemini-based AI assistance for investigation and detection-rule authoring. It is cloud-only and sold through Google Cloud, typically as an annual commitment sized to ingest volume; Google does not publish self-serve per-GB rates, and a dedicated public pricing page was not reachable at the time of writing.
At a glance
| Vendor | Google LLC |
|---|---|
| Pricing model | Quote only |
| Free tier | No |
| Deployment | Cloud |
| Open source | No |
| Best for | Organizations wanting Google-scale log retention and curated threat intelligence built into their SIEM. |
Pricing
Typically sold as an annual ingest-volume commitment; no public self-serve per-GB rate card found.
Pricing has not been verified yet — see the vendor's site.
Features
- High-volume log ingestion with long retention at flat rates
- Built-in Mandiant and VirusTotal threat intelligence
- Gemini-assisted investigation and detection authoring
- YARA-L based detection rule language
- SOAR case management (via integrated Chronicle SOAR)
- Petabyte-scale search performance
Integrations
Profile last reviewed September 21, 2026