The SIEM that stopped making retention a budget argument — Google Security Operations bundles SIEM, SOAR and Mandiant threat intelligence in one platform, with twelve months of hot, searchable data included on every package.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Data residency & processing — confirm before the PoC
Delivery
SaaS on Google Cloud only
No on-premises, self-hosted or air-gapped edition exists. This is what the product is, not a licensing question.
What to confirm
Region — and processing, separately
Storage residency and processing residency are two different commitments. Get both in writing for your region.
If your mandate requires on-premises or air-gapped deployment, this product cannot meet it — the SIEM guide shows the options that can. If it requires data to stay in India, settle storage and processing separately with Google before a proof of concept, not at the audit.
Quick answer
This page covers Google Security Operations — the SIEM. The other pillars:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Google’s cloud-native security operations platform — SIEM, SOAR and threat intelligence in one product, built on the infrastructure that indexes the web. Detections in YARA-L; 12 months hot retention included.
What consolidation actually replaces, dimension by dimension.
| Dimension | No / separate AI tool | Google SecOps |
|---|---|---|
| Retention | Priced per GB per month | 12 months hot, included |
| Old data | Archived, rehydrate to search | Hot and searchable now |
| SOAR | A separate product | In the platform |
| Threat intel | A third subscription | Mandiant, Google-owned |
| Pricing axis | Per GB as you go | A package against a GB cap |
| Rule language | Per-source, rewritten | YARA-L over one data model |
| Honest caveat | — | Cloud-only; YARA-L to learn |
| Best fit | — | Large log estates, cloud-committed |
The retention-and-search answer for large log estates — for on-prem or air-gapped, weigh Splunk or Elastic (TechBag sells Splunk).
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
You buy a package against a cap measured in GB and meter ingestion against it. Forwarders, feeds and hundreds of parsers bring data in; the Data Benefit Program covers eligible Google Cloud audit logs and Workspace logs, and approved third-party EDR alerts, for qualifying orders.
Everything is parsed into one schema on the way in, so a rule written once matches across sources. This is why detection content ports cleanly — and why a badly parsed source is the thing that quietly costs you coverage.
Google's own detection language, purpose-built for security telemetry over time windows. Curated detections ship with the product; your team writes the rest. It is powerful and it is a language to learn.
Every package includes twelve months of hot, searchable data at no extra cost — not archived, not rehydrated on request. Retention beyond that window is billed separately by volume.
Playbooks and case management are in the platform rather than a separate SKU. Enterprise adds UEBA and Gemini AI assistance; Enterprise Plus adds the full Mandiant and VirusTotal intelligence Google owns outright.
One workspace where people meet, make, and share — work moving in one place, not emailed between tools.
Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.
Hundreds of supported sources normalised into the Unified Data Model on ingest.
You size a cap rather than paying per GB as you go — the model replaced per-employee metering.
Searchable at full speed for a year on every tier, with no separate archive step.
One schema for every source, so a rule written once matches across the estate.
Google's security-native rule language, built for correlation over time windows.
Google-authored detection sets you switch on rather than write from scratch.
Entity risk scoring and behavioural baselines (Enterprise and above).
Front-line incident-response intelligence Google owns, richest on Enterprise Plus.
Investigate across a year of data without staging or rehydrating it first.
Orchestration in the platform rather than a separate product to license.
Natural-language investigation and summarisation (Enterprise and above).
Filter, route and shape data before it lands (Enterprise Plus).
Endpoint protection, XDR and Security Copilot.
The platform, introduced by Google.
A walkthrough of the console and workflow.
What it looks like in a real SOC.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets Google SecOps apart (and where Splunk or Elastic may fit better).
This is the design decision everything else follows from, and it is genuinely unusual. Every Google SecOps package — Standard, Enterprise and Enterprise Plus — includes twelve months of hot, searchable data at no additional cost. Not archived. Not in a cheaper tier you have to query differently. Not rehydrated on request with a delay and a bill. Twelve months you can search at full speed, today, as part of what you already bought. The reason that matters is the oldest tension in security operations: the median time to discover an intrusion is measured in months, so the data you most need during an investigation is exactly the data a per-GB-per-month SIEM has been quietly pressuring you to delete. Teams on volume-metered platforms make retention decisions on budget rather than risk, and then discover during an incident that the relevant week is gone. Google inverted that. Retention beyond the twelve-month window is billed separately by volume, so this is not unlimited — but the window covers the overwhelming majority of real investigations.
On most stacks these are three purchases: the SIEM, then a SOAR beside it, then a threat-intelligence subscription on top — three contracts, three renewal dates, three integrations to build and maintain. Google SecOps ships them as one platform. Playbooks and case management are in the product rather than a separate SKU, and the threat intelligence is Mandiant, which Google owns outright rather than licenses — front-line incident-response intelligence from the firm that investigates many of the year's most significant breaches, with VirusTotal alongside it. Enterprise adds UEBA and Gemini AI assistance; Enterprise Plus adds the full Mandiant and VirusTotal depth plus advanced pipeline management. For a SOC doing the maths honestly, the comparison is not Google's licence against one competitor's licence — it is Google's package against a SIEM plus a SOAR plus an intel feed.
Google SecOps runs on the infrastructure Google built to index the web, and the practical consequence is that searching a year of security telemetry behaves like searching the web rather than like running a batch job. That changes analyst behaviour in a way that is hard to convey on a datasheet: when a search across months returns while you are still holding the thought, you follow hunches you would otherwise abandon as too expensive to check. On platforms where a broad historical query means a long wait or a cost conversation, investigations get narrowed to what is affordable rather than what is thorough. The Unified Data Model is the other half of this — every source is normalised into one schema on ingest, so a single rule or query matches across the estate instead of being rewritten per source.
Google was named a Leader in the 2025 Gartner Magic Quadrant for SIEM in only its second year of participating in that evaluation, and was positioned furthest for Completeness of Vision of every vendor assessed — ahead of incumbents who have been in the category for two decades. Read that for what it is: Completeness of Vision measures where the market is going and how coherently a vendor's strategy addresses it, which is a genuine signal about direction and a limited one about how the product behaves in your estate today. Ability to Execute is the other axis, and the incumbents did not get to be incumbents by accident. What the placement does tell you is that the platform argument here — one product, cloud-native, retention as a design decision rather than a line item — is being taken seriously by the analysts who talk to the most buyers.
Being honest, and TechBag sells the alternatives: Google SecOps is delivered only as SaaS on Google Cloud. If you have an on-premises mandate, an air-gapped environment, or a regulator who has ruled on where processing may happen, this is not a candidate and no amount of feature comparison changes that — ManageEngine Log360, FortiSIEM on appliances, Kaspersky KUMA and self-managed Elastic are where that conversation goes. Second, YARA-L is Google's own rule language: powerful, well-suited to security telemetry, and something your detection engineers have to learn, with a smaller pool of people who already know it than SPL or KQL. Third, this is a platform commitment rather than a component — the value comes from putting your data in and adopting the workflow, which is a bigger organisational change than swapping a log store. And note the pricing model changed: the per-employee metering Google Security Operations was known for is gone, replaced by GB-based data caps, so any comparison written before 2026 is describing a product you cannot buy today. Google does not publish US commercial unit prices, so the real number comes from a quote.
Google Security Operations is the right SIEM for organisations with large or fast-growing log estates that want twelve months of hot retention without a retention negotiation, SIEM and SOAR and threat intelligence in one platform rather than three, and search fast enough to change how analysts investigate. It suits teams willing to learn YARA-L and commit to a platform. It is the wrong choice if you need on-premises or air-gapped deployment, if your obligation is about processing location, or if your value comes from an existing library of SPL your team has spent years building. TechBag sells Splunk and Microsoft Sentinel as well, and the useful thing we do is model your GB/day by source against a package cap before you commit — quoted in INR with GST.
Inventory sources and estimate GB/day, separating data covered by the Data Benefit Program from the rest. The cap you buy is the decision. TechBag does this modelling free.
Stand up forwarders and feeds, and get parsing right — a badly parsed source silently costs you detection coverage later.
Turn on curated detections, write the YARA-L your estate needs, and build the SOAR playbooks for what they raise. Budget the language ramp honestly.
Use the twelve-month window the way it is meant to be used — follow hunches across months rather than rationing queries. Review the cap against actual ingest quarterly.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Twelve months of hot data changed how we investigate. We stopped deciding what to keep on budget grounds and started keeping what mattered — the difference showed up the first time we traced something back four months.”
“Search across a year returns while you are still thinking about the question. On our old SIEM a query that broad was a coffee break and a cost conversation, so nobody ran them.”
“SIEM, SOAR and Mandiant intelligence on one contract removed two renewals and two integrations from my year. That is a real saving that never appears on a feature comparison.”
“Honest warning: YARA-L is a new language for the team. Budget the ramp — our first month of custom detections was slower than we planned, and hiring for it is harder than for SPL.”
“The Unified Data Model is the quiet win. One rule matches across sources instead of being rewritten per source, so our detection library actually stayed maintainable.”
“Parsing is where the effort went. A poorly parsed source silently costs you coverage, and that work is not visible in the sales cycle.”
“We could not use it — an on-premises mandate made it a non-starter regardless of how good the platform is. TechBag said so in the first conversation rather than the fourth.”
“As an Indian enterprise, having the GB/day modelled against a package cap in INR before signing was what made the business case defensible to our board.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
2025 MQ Leader — furthest on Vision.
The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.
Retention and search at scale — the corner it fills.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The SIEM leaders — honest lanes; the edge is 12 months hot retention + SOAR and Mandiant in the platform. Deepest search, or on-prem? Splunk. We say so (and sell it).
| Dimension | Google Security Operations | Splunk Enterprise Security | Microsoft Sentinel | Palo Alto Cortex XSIAM | Elastic Security |
|---|---|---|---|---|---|
| Position | Cloud-native SIEM + SOAR + intel | The search-power incumbent | SIEM for Microsoft estates | AI-led SOC replacement | Open, ELK-based |
| Pricing axis | Package against a GB cap | Ingest or workload — historically costly | Per GB ingested per day | Platform subscription by data and scope | Resource-based; free self-managed tier |
| Retention included | 12 months hot on every tier | Priced by volume and term | 90 days, then charged | Bundled by tier | Yours to configure |
| Search speed at scale | Sub-second across a year | SPL — the benchmark | KQL, strong but volume-shaped | Platform-native | Very fast, you tune it |
| SOAR | In the platform | Splunk SOAR, separate SKU | Logic Apps, billed separately | Included | Basic; often paired |
| Threat intelligence | Mandiant + VirusTotal, Google-owned | Cisco Talos | MDTI, free tier available | Unit 42 | Elastic + community |
| Deployment model | SaaS only, on Google Cloud | Cloud, on-prem or hybrid | SaaS only, on Azure | SaaS only | Cloud, on-prem, air-gapped |
| Rule language & talent pool | YARA-L — powerful, smaller talent pool | SPL — the largest pool | KQL — widely known | Platform-native | Lucene / ES|QL |
| First-party log economics | Google Cloud and Workspace logs benefit | All sources metered | Microsoft logs ingest free | Palo Alto telemetry native | Neutral |
| The thing to plan around | Pricing model changed — pre-2026 comparisons are stale | Cisco integration reshaping roadmap | Azure portal retires 31 Mar 2027 | An operating-model change, not a swap | You run and tune it yourself |
| Best fit | Large log estates wanting retention solved | Mature detection-engineering teams | Microsoft-standardised estates | SOCs replacing the triage model | Budget-constrained or air-gapped |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Google Security Operations is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →
Sentinel bills on data ingested, so this is the only sum that matters. The baseline puts every GB on the analytics tier at pay-as-you-go (~$4.30/GB). The optimised figure moves your low-value logs to the data lake tier (~$0.05/GB) and prices the rest at the 100 GB/day commitment rate (~$2.96/GB) once you qualify. Microsoft’s published East US rates at ~₹84/USD; regional rates differ and Microsoft calls them estimates, not quotes. Excludes Logic Apps, Functions and Copilot, which bill separately.
Free first-party sources — Azure Activity, Microsoft 365 audit logs and Defender XDR alerts — are excluded from both figures, so count only your billable GB. The commitment rate applies at 100 GB/day and above. Illustrative: your TechBag quote models your real sources.
Google SecOps is sold as a package against a data cap measured in GB — the per-employee metering Google Security Operations was known for has been retired, so pre-2026 comparisons describe a product you cannot buy. Google does not publish US commercial unit prices, so every deal is quoted. What IS fixed across all three packages: twelve months of hot retention, included. TechBag sizes the cap against your real GB/day and quotes in INR with GST.
Best for core security operations
Best for most SOCs
Best for complex estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What is your GB/day by source, and which sources qualify for the Data Benefit Program?
What package cap does that volume need, and what happens — commercially — when you exceed it?
Does twelve months of hot retention cover your mandate, and what does retention beyond it cost?
Standard, Enterprise or Enterprise Plus? UEBA and Gemini start at Enterprise; full Mandiant and pipeline management at Plus.
Can you accept SaaS on Google Cloud? An on-premises or air-gapped mandate rules this out entirely.
Who on your team will write YARA-L, and have you budgeted the ramp? The talent pool is smaller than for SPL or KQL.
Is any analysis you are relying on written against the OLD per-employee model? That product is no longer sold.
Google does not publish US list prices — have you modelled the quote in INR with GST?
Size the package cap against your real GB/day, check what the Data Benefit Program covers, or get an honest Google-SecOps-vs-Splunk comparison — in INR/GST.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.