Google SecOps
Deprecated — This integration uses the legacy Siemplify SOAR External API, which Google has deprecated. It remains available for existing tenants but will be removed in a future release. New tenants should use Google SecOps Chronicle instead.
Overview
The Google SecOps integration connects RedCarbon to a Google Security Operations (Chronicle SOAR) instance via the legacy SOAR External API. RedCarbon authenticates using a static API key (AppKey) issued by the SOAR administration panel.
Configuration
| Field | Description |
|---|---|
| URL | Base URL of the Google SecOps SOAR instance (e.g. https://tenant.siemplify-soar.com) |
| App Key | API key generated in the SOAR administration panel |
Migration to Google SecOps Chronicle
Google has deprecated the SOAR External API. To migrate to the new Chronicle REST API:
- Set up a new Google SecOps Chronicle source — see the Google SecOps Chronicle guide.
- Verify that ingestion is working correctly on the new source.
- Deactivate this (Google SecOps) source from the RedCarbon Dashboard.
The migration is safe and reversible at every step: both sources can run in parallel during the transition.