
Google Security Operations (formerly Google Chronicle) is a cloud-native SIEM and SOAR platform built on Google's infrastructure. It's designed for enterprises to retain, analyze, and search massive volumes of security telemetry data at scale, with a default 12-month data retention period. The platform ingests data through forwarders, collectors, ingestion APIs, and third-party integrations, then normalizes it using the Unified Data Model (UDM) to enable correlation and contextual analysis Review collected by and hosted on G2.com.
The SOAR/SIEM integration feels bolted together, and the YARA‑L learning curve is steep.
Two specific pain points:
The UI inconsistency – The SIEM side (Chronicle) and the SOAR side (playbooks) don't feel like one product. Navigation, workflows, and even design language shift between the two. Alert management in particular is underdeveloped – filtering, bulk actions, and case management are clunkier than they should be.
YARA‑L is powerful but punishing – For teams coming from Splunk SPL or KQL, the transition is rough. Documentation is thin, there are few out-of-the-box detection rules, and writing custom rules requires dedicated training. You can't just "plug and play" – you need a mature detection engineering team to make it sing.
Also, for all its cloud-native hype, some users report query performance is 2–3× slower than Splunk for certain high-cardinality searches, and native dashboards are basic compared to competitors. Review collected by and hosted on G2.com.