Google SecOps SOAR: siemAlertId Field Reservation
Effective July 5, 2026, Google SecOps SOAR will reserve the `siemAlertId` field exclusively for internal Chronicle SIEM alert IDs, overwriting any custom data. This change impacts all ingestion methods and requires users to migrate custom `siemAlertId` fields immediately to prevent data loss. Engineers and architects using SOAR for alert ingestion should update their configurations before the deadline.
Breaking changes (1) ›
- Google SecOps SOAR Critical Notice: Upcoming reservation of siemAlertId field
Critical Notice: Upcoming reservation of siemAlertId field Effective July 5, 2026, the siemAlertId field will be strictly reserved for internal Chronicle SIEM alert IDs. Starting July 5, the system will automatically overwrite any custom or user-supplied data passed through this field. This change impacts all ingestion methods, including the Ingestion API, webhooks, and both first-party and third-party connectors. If you are currently utilizing a custom field named siemAlertId in any of your alert ingestion configurations, please migrate to a different field name immediately to prevent data lo
https://docs.cloud.google.com/release-notes#June_23_2026
Related releases
- Google Cloud AI Infrastructure and Orchestration Updates - July 2026 Google Cloud Blog ·
- Confidential VMs Expand vCPU Support on C3D/C4D Google Cloud release notes ·
- Google Kubernetes Engine: New versions and deprecations Google Cloud release notes ·
- Datastream adds preview support for Workday replication Google Cloud release notes ·
- Google Cloud CISO Perspectives: AI Threat Defense for Boards Google Cloud Blog ·
- Data Studio Conversational Analytics GA, adds BigQuery integration Google Cloud release notes ·