<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:chronicle-soar-release-notes</id>
  <title>Google SecOps SOAR - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/chronicle-soar-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-09-06T00:00:00-07:00</updated>

  <entry>
    <title>September 06, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#September_06_2026</id>
    <updated>2026-09-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#September_06_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.100 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Feature</h3>
<p><strong>Reaction triggers</strong></p>
<p>This feature is in preview. Google SecOps now supports reaction triggers. As 
post-ingestion triggers, they allow playbooks to automatically fire in response 
to real-time case or alert updates during active investigations, such as changes 
to the case assignee, case tags, alert priority, or newly added entities.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/using-reaction-triggers-in-playbooks">Use reaction triggers in playbooks</a>.</p>
<h3>Feature</h3>
<p><strong>Case playbooks</strong></p>
<p>This feature is in preview. Google SecOps now supports case playbooks. You can
run playbooks or execute manual actions across an entire case container rather
than individual alerts, consolidating response tasks and reducing redundant
operations during investigations.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/case-playbooks">Case playbooks overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 05, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#September_05_2026</id>
    <updated>2026-09-05T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#September_05_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_30_2026">Release 6.3.99</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 30, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_30_2026</id>
    <updated>2026-08-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_30_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.99 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 29, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_29_2026</id>
    <updated>2026-08-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_29_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_16_2026">Release 6.3.98</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 27, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_27_2026</id>
    <updated>2026-08-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_27_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><strong>Scheduled maintenance</strong> </p>
<p>SOAR database and infrastructure maintenance is scheduled to take place during
the standard maintenance window on Sunday, August 30. During this window, your
system will experience a brief period of downtime. You don't need to take any 
action.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 16, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_16_2026</id>
    <updated>2026-08-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_16_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.98 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 15, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_15_2026</id>
    <updated>2026-08-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_15_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_09_2026">Release 6.3.97</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 13, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_13_2026</id>
    <updated>2026-08-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_13_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><strong>Scheduled Maintenance</strong> </p>
<p>SOAR database and infrastructure maintenance is scheduled to take place during
the standard maintenance window on Sunday, August 16. During this window, your
system will experience a brief period of downtime. No customer action is
required.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 09, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_09_2026</id>
    <updated>2026-08-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_09_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.97 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Feature</h3>
<p><strong>Updated rich-text editor</strong></p>
<p>Upgraded the rich-text editor across Google SecOps, including the Cases Wall, 
Use Case Upload dialog, Report Template dialog, and Dashboard Editor widget.</p>
<p>Key changes include:</p>
<ul>
<li><strong>Simplified typography</strong>: Choose font sizes using semantic options (Small, 
Normal, Large, Huge). Legacy font sizes on existing text are preserved.</li>
<li><strong>Streamlined tables</strong>: You can insert or remove entire tables. Formatting 
inside table cells is no longer supported.</li>
<li><strong>Toolbar cleanup</strong>: Removed the Cut, Copy, and Paste buttons from the toolbar. 
Standard OS keyboard shortcuts remain supported.</li>
<li><strong>Visual alignment</strong>: Improved visual consistency between editor content 
during editing and after submission.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>August 08, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_08_2026</id>
    <updated>2026-08-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_08_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_02_2026">Release 6.3.96</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 03, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_03_2026</id>
    <updated>2026-08-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_03_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>The deadline for Stage 2 of the SOAR migration to Google Cloud has been extended from September 30th to November 30th, 2026.
For more information, refer to the <a href="https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/migrate-to-gcp">SOAR migration guide</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 02, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_02_2026</id>
    <updated>2026-08-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_02_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.96 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 01, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#August_01_2026</id>
    <updated>2026-08-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#August_01_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_26_2026">Release 6.3.95</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 26, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_26_2026</id>
    <updated>2026-07-26T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_26_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.95 is being rolled out to the first phase of regions as listed 
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 25, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_25_2026</id>
    <updated>2026-07-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_25_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_19_2026">Release 6.3.94</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 19, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_19_2026</id>
    <updated>2026-07-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_19_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.94 is being rolled out to the first phase of regions as listed 
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 18, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_18_2026</id>
    <updated>2026-07-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_18_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_12_2026">Release 6.3.93</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 12, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_12_2026</id>
    <updated>2026-07-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_12_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.93 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Feature</h3>
<p><strong>Publisher Agent Version 2.7.0</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_05_2026">Publisher Agent Version 2.7.0</a>
is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 11, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_11_2026</id>
    <updated>2026-07-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_11_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_5_2026">Release 6.3.92</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 07, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_07_2026</id>
    <updated>2026-07-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_07_2026"/>
    <content type="html"><![CDATA[<h3>Feature</h3>
<p><strong>SOAR migration to Google Cloud validation status</strong></p>
<p>You can now check if the SOAR migration was successful by going to the <strong>SOAR Settings &gt; License Management</strong> page.
After successful completion of Stage 1, it will say <strong>Google.com</strong> after the system version number. 
After successful completion of Stage 2 of SOAR permissions to IAM roles, it will say both <strong>Google.com</strong> and <strong>CloudIAM Enabled</strong> after the system version number.</p>
<p>For more information on the migration, see the <a href="https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/migrate-to-gcp">SOAR migration guide</a></p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 05, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_05_2026</id>
    <updated>2026-07-05T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_05_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.92 is being rolled out to the first phase of regions as listed 
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Feature</h3>
<p><strong>Publisher Agent Version 2.7.0</strong></p>
<p>Publisher Agent Version 2.7.0 is being rolled out to the first phase of regions.</p>
<p>This release includes the following updates for the remote agent:</p>
<ul>
<li><strong>High Availability support:</strong> Adds applicative support for Publisher high 
availability.</li>
<li><strong>File transfer support:</strong> You can now upload and download files using
playbooks and the SDK on agents that have been migrated to the GCOM
infrastructure.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>July 04, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#July_04_2026</id>
    <updated>2026-07-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#July_04_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_28_2026">Release 6.3.91</a> is now 
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 28, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_28_2026</id>
    <updated>2026-06-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_28_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.91 is being rolled out to the first phase of regions as listed
<a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Announcement</h3>
<p><strong>Remote Agents Version 2.6.7</strong></p>
<p>Remote Agents Version 2.6.7 is now available. This release contains minor bug
fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 27, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_27_2026</id>
    <updated>2026-06-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_27_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_21_2026">Release 6.3.90</a> is now
available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 26, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_26_2026</id>
    <updated>2026-06-26T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_26_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><strong>Improved documentation portal navigation</strong></p>
<p>Finding help is now easier! We've updated the navigation of our documentation portal to be primarily user-centric. Sections have been reorganized and renamed to align with your workflows, providing a logical path through the documentation.</p>
<p>We've also added:</p>
<ul>
<li>A <a href="https://docs.cloud.google.com/chronicle/docs/secops/release-notes"><strong>Support</strong> tab</a> for technical support, changelogs, and release notes</li>
<li>A <a href="https://docs.cloud.google.com/chronicle/docs/use-cases"><strong>Use cases</strong> tab</a> for persona-driven CUJs and workflows</li>
</ul>
<aside class="note"><strong>Note:</strong><span> Content-level modifications are not included in this update and are scheduled for subsequent phases.</span></aside>
]]>
    </content>
  </entry>

  <entry>
    <title>June 23, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_23_2026</id>
    <updated>2026-06-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_23_2026"/>
    <content type="html"><![CDATA[<h3>Breaking</h3>
<p><strong>Critical Notice: Upcoming reservation of siemAlertId field</strong></p>
<p>Effective July 5, 2026, the <code>siemAlertId</code> field will be strictly reserved for
internal Chronicle SIEM alert IDs. </p>
<p>Starting July 5, the system will automatically overwrite any custom or
user-supplied data passed through this field. This change impacts all ingestion
methods, including the Ingestion API, webhooks, and both first-party and
third-party connectors. If you are currently utilizing a custom field named 
<code>siemAlertId</code> in any of your alert ingestion configurations, please
migrate to a different field name immediately to prevent data loss.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 21, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_21_2026</id>
    <updated>2026-06-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_21_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.90 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
<h3>Announcement</h3>
<p><strong>Scheduled Maintenance</strong> </p>
<p>CloudSQL will undergo a scheduled minor upgrade.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 20, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_20_2026</id>
    <updated>2026-06-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_20_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_14_2026">Release 6.3.89</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 16, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_16_2026</id>
    <updated>2026-06-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_16_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p><strong>New Documentation changelogs</strong></p>
<p>Google SecOps is now releasing a monthly changelog to capture major documentation updates.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs">Documentation changelog</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 14, 2026</title>
    <id>tag:google.com,2016:chronicle-soar-release-notes#June_14_2026</id>
    <updated>2026-06-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_14_2026"/>
    <content type="html"><![CDATA[<h3>Announcement</h3>
<p>Release 6.3.89 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

</feed>
