Log in to Google SecOps
Google Security Operations supports the Google Chrome and Mozilla Firefox browsers. Upgrade your browser to the most current version for optimal performance and security. The latest Chrome version is available for download at https://www.google.com/chrome/. Mobile operating systems (iOS/Android) and mobile browsers are not supported.
Authentication and access
Google SecOps integrates with SSO solutions. Access to the Google SecOps platform requires valid enterprise credentials.
Launch Chrome or Firefox.
Verify you have active access to the corporate account.
Go to the following URL and replace customer_subdomain with the customer-specific identifier to access the Google SecOps application:
https://customer_subdomain.backstory.chronicle.security
Network access and domain allowlist
If your organization uses egress firewalls, corporate proxies, or strict web filtering, you must add the following Fully Qualified Domain Names (FQDNs) to your network allowlist to ensure uninterrupted access to Google SecOps and Google SecOps SOAR.
Mandatory SecOps and SOAR core domains
These domains are required for basic UI functionality, core API calls, and workspace navigation.
| Domain Pattern | Purpose |
|---|---|
*.backstory.chronicle.security |
Google SecOps frontend main domain and static application assets. |
*-chronicle.googleapis.com |
Google SecOps core REST APIs (for example, asia-southeast1-chronicle.googleapis.com). |
*.siemplify-soar.com |
Google SecOps SOAR instance navigation and backend API endpoints. |
Mandatory Google infrastructure and Cloud API domains
These endpoints support Google Cloud identity, resource permissions, static asset loading, and background platform services.
| Domain | Purpose |
|---|---|
cloudconsole-pa.clients6.google.com |
Google Cloud console UI integration components. |
cloudresourcemanager.googleapis.com |
Resource management and user permission validation. |
firebase.googleapis.com |
Real-time notification and event streaming services. |
*.gstatic.com |
Static platform resources. |
fonts.gstatic.com |
Google Fonts static file host. |
fonts.googleapis.com |
Google Fonts API interface. |
play.google.com |
Client-side application telemetry and logging. |
Optional and non-blocking domains
Blocking these domains won't prevent core login or security investigation workflows, but it may affect usage telemetry, security policy reporting, or in-app survey prompts.
| Domain | Purpose |
|---|---|
www.google-analytics.com |
Usage metrics and session analytics. |
www.googletagmanager.com |
Tag management for analytics deployment. |
csp.withgoogle.com |
Content Security Policy (CSP) violation reporting. |
*.siteintercept.qualtrics.com |
In-product user feedback and survey popups. |
Initiate a search
Initiate a search by entering the domain, email, username, hostname, IP address, file hash, or URL into the search bar.
Set the search window
Use the integrated date and time selector to focus your search on a specific window. Select the required dates and times using the calendar and clock settings dialog.
Need more help? Get answers from Community members and Google SecOps professionals.