Vivek U.
VU
Founder
Enterprise (> 1000 emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Centralized Monitoring That Speeds Up Threat Detection and Investigations"
4.5/5
What do you like best about Google Security Operations?

Google Security Operations (formerly Google Chronicle) is a cloud-native SIEM and SOAR platform built on Google's infrastructure. It's designed for enterprises to retain, analyze, and search massive volumes of security telemetry data at scale, with a default 12-month data retention period. The platform ingests data through forwarders, collectors, ingestion APIs, and third-party integrations, then normalizes it using the Unified Data Model (UDM) to enable correlation and contextual analysis Review collected by and hosted on G2.com.

What do you dislike about Google Security Operations?

The SOAR/SIEM integration feels bolted together, and the YARA‑L learning curve is steep.

Two specific pain points:

The UI inconsistency – The SIEM side (Chronicle) and the SOAR side (playbooks) don't feel like one product. Navigation, workflows, and even design language shift between the two. Alert management in particular is underdeveloped – filtering, bulk actions, and case management are clunkier than they should be.

YARA‑L is powerful but punishing – For teams coming from Splunk SPL or KQL, the transition is rough. Documentation is thin, there are few out-of-the-box detection rules, and writing custom rules requires dedicated training. You can't just "plug and play" – you need a mature detection engineering team to make it sing.

Also, for all its cloud-native hype, some users report query performance is 2–3× slower than Splunk for certain high-cardinality searches, and native dashboards are basic compared to competitors. Review collected by and hosted on G2.com.

See what 136 reviewers think of Google Security Operations

4.4 out of 5 · Verified reviews from real users

Read all reviews