Google SecOps

Google SecOps

Deprecated — This integration uses the legacy Siemplify SOAR External API, which Google has deprecated. It remains available for existing tenants but will be removed in a future release. New tenants should use Google SecOps Chronicle instead.

Overview

The Google SecOps integration connects RedCarbon to a Google Security Operations (Chronicle SOAR) instance via the legacy SOAR External API. RedCarbon authenticates using a static API key (AppKey) issued by the SOAR administration panel.

Configuration

FieldDescription
URLBase URL of the Google SecOps SOAR instance (e.g. https://tenant.siemplify-soar.com)
App KeyAPI key generated in the SOAR administration panel

Migration to Google SecOps Chronicle

Google has deprecated the SOAR External API. To migrate to the new Chronicle REST API:

  1. Set up a new Google SecOps Chronicle source — see the Google SecOps Chronicle guide.
  2. Verify that ingestion is working correctly on the new source.
  3. Deactivate this (Google SecOps) source from the RedCarbon Dashboard.

The migration is safe and reversible at every step: both sources can run in parallel during the transition.