Google SecOps SIEM deprecates legacy APIs
Google Security Operations is deprecating its legacy SIEM APIs, including the Backstory API and Ingestion API, in favor of the modern Chronicle API. This change affects custom scripts, integrations, SOAR connectors, or ingestion feeds that rely on these legacy endpoints. The deprecation will fully take effect with the complete shutdown of legacy APIs for all existing instances on July 20, 2027.
Deprecations (1) ›
- Google SecOps SIEM [Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs
[Spotlight Feature] Deprecation of Google Security Operations legacy SIEM APIs Google Security Operations is deprecating its legacy SIEM APIs— Backstory API (including Customer Management API ) and Ingestion API —in favor of the modern Chronicle API . Key dates October 26, 2026: New Google SecOps instances provisioned from this date will no longer support legacy API calls. July 20, 2027: All requests to legacy endpoints fail from this date because legacy APIs for all existing instances will be completely turned down. This change applies only to custom scripts, integrations, SOAR connectors, or
https://docs.cloud.google.com/release-notes#July_20_2026
Related releases
- Google Cloud AI Infrastructure and Orchestration Updates - July 2026 Google Cloud Blog ·
- Confidential VMs Expand vCPU Support on C3D/C4D Google Cloud release notes ·
- Google Kubernetes Engine: New versions and deprecations Google Cloud release notes ·
- Datastream adds preview support for Workday replication Google Cloud release notes ·
- Google Cloud CISO Perspectives: AI Threat Defense for Boards Google Cloud Blog ·
- Data Studio Conversational Analytics GA, adds BigQuery integration Google Cloud release notes ·