Log in to Google SecOps

Supported in:

Google Security Operations supports the Google Chrome and Mozilla Firefox browsers. Upgrade your browser to the most current version for optimal performance and security. The latest Chrome version is available for download at https://www.google.com/chrome/. Mobile operating systems (iOS/Android) and mobile browsers are not supported.

Authentication and access

Google SecOps integrates with SSO solutions. Access to the Google SecOps platform requires valid enterprise credentials.

  1. Launch Chrome or Firefox.

  2. Verify you have active access to the corporate account.

  3. Go to the following URL and replace customer_subdomain with the customer-specific identifier to access the Google SecOps application:

    https://customer_subdomain.backstory.chronicle.security

Network access and domain allowlist

If your organization uses egress firewalls, corporate proxies, or strict web filtering, you must add the following Fully Qualified Domain Names (FQDNs) to your network allowlist to ensure uninterrupted access to Google SecOps and Google SecOps SOAR.

Mandatory SecOps and SOAR core domains

These domains are required for basic UI functionality, core API calls, and workspace navigation.

Domain Pattern Purpose
*.backstory.chronicle.security Google SecOps frontend main domain and static application assets.
*-chronicle.googleapis.com Google SecOps core REST APIs (for example, asia-southeast1-chronicle.googleapis.com).
*.siemplify-soar.com Google SecOps SOAR instance navigation and backend API endpoints.

Mandatory Google infrastructure and Cloud API domains

These endpoints support Google Cloud identity, resource permissions, static asset loading, and background platform services.

Domain Purpose
cloudconsole-pa.clients6.google.com Google Cloud console UI integration components.
cloudresourcemanager.googleapis.com Resource management and user permission validation.
firebase.googleapis.com Real-time notification and event streaming services.
*.gstatic.com Static platform resources.
fonts.gstatic.com Google Fonts static file host.
fonts.googleapis.com Google Fonts API interface.
play.google.com Client-side application telemetry and logging.

Optional and non-blocking domains

Blocking these domains won't prevent core login or security investigation workflows, but it may affect usage telemetry, security policy reporting, or in-app survey prompts.

Domain Purpose
www.google-analytics.com Usage metrics and session analytics.
www.googletagmanager.com Tag management for analytics deployment.
csp.withgoogle.com Content Security Policy (CSP) violation reporting.
*.siteintercept.qualtrics.com In-product user feedback and survey popups.

Initiate a search by entering the domain, email, username, hostname, IP address, file hash, or URL into the search bar.

Set the search window

Use the integrated date and time selector to focus your search on a specific window. Select the required dates and times using the calendar and clock settings dialog.

Need more help? Get answers from Community members and Google SecOps professionals.