Security analytics & SIEM · Google LLC

Google Security Operations

Google Cloud's SIEM, built on the Chronicle backend, offering high-volume, long-retention log search with integrated threat intelligence.

Google Security Operations (formerly Chronicle, and before that Chronicle Security Operations) is Google Cloud's SIEM, built on infrastructure originally designed for Google-scale log search, which it uses to offer flat-rate ingestion with long retention windows rather than charging per query or per scanned byte. It bundles Google-curated threat intelligence (including Mandiant and VirusTotal signal) directly into detections, and increasingly layers Gemini-based AI assistance for investigation and detection-rule authoring. It is cloud-only and sold through Google Cloud, typically as an annual commitment sized to ingest volume; Google does not publish self-serve per-GB rates, and a dedicated public pricing page was not reachable at the time of writing.

At a glance

Vendor Google LLC
Pricing model Quote only
Free tier No
Deployment Cloud
Open source No
Best for Organizations wanting Google-scale log retention and curated threat intelligence built into their SIEM.

Pricing

Typically sold as an annual ingest-volume commitment; no public self-serve per-GB rate card found.

Pricing has not been verified yet — see the vendor's site.

Features

  • High-volume log ingestion with long retention at flat rates
  • Built-in Mandiant and VirusTotal threat intelligence
  • Gemini-assisted investigation and detection authoring
  • YARA-L based detection rule language
  • SOAR case management (via integrated Chronicle SOAR)
  • Petabyte-scale search performance

Integrations

Profile last reviewed September 21, 2026

Alternatives

Google Security Operations in the index now

Terms to know

Related guides