Google Security Products Status Dashboard
Incident affecting Google SecOps
Customers utilizing BigQuery BYOP data export or legacy (deprecated) BigQuery export to TLA projects may experience delays in recent UDM Events appearing in their BigQuery datasets. BigQuery Advanced export for SecOps Enterprise+ customers is unaffected.
Incident began at 2026-08-31 10:27 and ended at 2026-08-31 12:48 (all times are US/Pacific).
Previously affected location(s)
Multi-region: us
| Date | Time | Description | |
|---|---|---|---|
| | 2 Sep 2026 | 23:07 PDT | Summary The issue affecting BigQuery BYOP data export and legacy BigQuery export to TLA projects has been mitigated. Data export and automated backfill of delayed data is now completed. BigQuery Advanced export for SecOps Enterprise+ customers remains unaffected. Description The underlying issue affecting Google Security Operations BigQuery exports has been mitigated as of Monday, 2026-08-31 12:48 US/Pacific. The Product Engineering Team had reverted to a recent software update, and normal export processing for newly generated UDM Events has resumed. Automated backfill processing to export the historical events delayed during the disruption is now completed . No customer action is required. Unaffected Services & Data Safety:
We thank you for your patience while we worked on resolving the issue. Diagnosis / Customer Symptoms Current real-time UDM Events are once again exporting to BigQuery datasets normally. Google Security Operations in-console search, ingestion, and rule detections are unaffected. Workaround This is now mitigated. |
| | 31 Aug 2026 | 14:37 PDT | Summary: The issue affecting BigQuery BYOP data export and legacy BigQuery export to TLA projects has been mitigated. Current data export has resumed, and automated backfill of delayed data is underway (expected to take up to 72 hours). BigQuery Advanced export for SecOps Enterprise+ customers remains unaffected. Description: The underlying issue affecting Google Security Operations BigQuery exports has been mitigated as of Monday, 2026-08-31 12:48 US/Pacific. The Product Engineering Team has reverted to a recent software update, and normal export processing for newly generated UDM Events has resumed. Automated backfill processing is currently underway to export the historical events delayed during the disruption. Due to the volume of queued data across the US region, completing the full backfill across all customer BigQuery datasets is expected to take up to 72 hours (by Thursday, 2026-09-03 13:00 US/Pacific). No customer action is required. Unaffected Services & Data Safety:
We will provide our next update by Thursday, 2026-09-03 13:00 US/Pacific. We thank you for your patience while we work through the backlog. Customer Symptoms: Current real-time UDM Events are once again exporting to BigQuery datasets normally. However, customers querying event records from the disruption window may continue to observe delays in their BigQuery tables while the 72-hour backfill pipeline catches up. Google Security Operations in-console search, ingestion, and rule detections are unaffected. Workaround: Customers requiring immediate, real-time access to event records from the disruption window can search and review logs directly within the Google Security Operations console or via the Search API, where all ingested events remain fully accessible. Backfill into BigQuery will proceed automatically without requiring customer action. |
| | 31 Aug 2026 | 13:14 PDT | Summary: The issue affecting BigQuery BYOP data export and legacy BigQuery export to TLA projects has been mitigated. Current data export has resumed, and automated backfill of delayed data is underway (expected to take up to 72 hours). BigQuery Advanced export for SecOps Enterprise+ customers remains unaffected. Description: The underlying issue affecting Google Security Operations BigQuery exports has been mitigated as of Monday, 2026-08-31 12:48 US/Pacific. The Product Engineering Team has reverted to a recent software update, and normal export processing for newly generated UDM Events has resumed. Automated backfill processing is currently underway to export the historical events delayed during the disruption. Due to the volume of queued data across the US region, completing the full backfill across all customer BigQuery datasets is expected to take up to 72 hours (by Thursday, 2026-09-03 13:00 US/Pacific). No customer action is required. Unaffected Services & Data Safety:
We will provide our next update by Monday, 2026-08-31 16:00 US/Pacific. We thank you for your patience while we work through the backlog. Customer Symptoms: Current real-time UDM Events are once again exporting to BigQuery datasets normally. However, customers querying event records from the disruption window may continue to observe delays in their BigQuery tables while the 72-hour backfill pipeline catches up. Google Security Operations in-console search, ingestion, and rule detections are unaffected. Workaround: Customers requiring immediate, real-time access to event records from the disruption window can search and review logs directly within the Google Security Operations console or via the Search API, where all ingested events remain fully accessible. Backfill into BigQuery will proceed automatically without requiring customer action. |
| | 31 Aug 2026 | 11:57 PDT | Summary: Customers utilizing BigQuery BYOBQ data export or legacy BigQuery export to TLA projects may experience delays in recent UDM Events appearing in their BigQuery datasets. BigQuery Advanced export for SecOps Enterprise+ customers is unaffected. Description: Mitigation work is currently underway by the Product Engineering Team. Unaffected Services & Data Safety:
We do not have an exact mitigation ETA at this time, as backlog catch-up will depend on queue processing volume. We will provide our next update by Monday, 2026-08-31 14:00 US/Pacific with current details. We apologize to all who are affected by this disruption. Customer Symptoms: Customers querying their exported BigQuery datasets may observe event data freshness lagging by several hours up to 10 hours. Google Security Operations in-console search, ingestion, and rule detections are unaffected. Workaround: Customers requiring immediate, real-time access to recent event records can search and review logs directly within the Google Security Operations console or via the Search API, where data freshness is unaffected. Ingested log data is safely queued and will export to BigQuery automatically. |
| | 31 Aug 2026 | 11:04 PDT | Summary: Customers utilizing BigQuery BYOP data export or legacy (deprecated) BigQuery export to TLA projects may experience delays in recent UDM Events appearing in their BigQuery datasets. BigQuery Advanced export for SecOps Enterprise+ customers is unaffected Description: We are investigating an issue with Google Security Operations (SIEM) beginning on Monday, 2026-08-31 10:27 US/Pacific, where customers in US regions utilizing BigQuery BYOP data export and the legacy (deprecated) BigQuery export are experiencing delays in recent UDM Events appearing in their exported BigQuery datasets. BigQuery Advanced export for SecOps Enterprise+ customers is unaffected. Google Security Operations core log ingestion, search, and detection capabilities remain fully operational. Ingested log data is safely preserved, and no data has been lost. The Product Engineering Team has identified the cause and is currently deploying a configuration update to restore normal export processing. Once normal processing resumes, the pipeline will automatically process the backlog and update BigQuery tables without requiring customer action. We will provide more information by Monday, 2026-08-31 12:00 US/Pacific. We apologize to all who are affected by this disruption. Customer Symptoms: Customers querying their exported BigQuery datasets may observe event data freshness lagging by several hours up to 10 hours. Google Security Operations in-console search, ingestion, and rule detections are unaffected. Workaround: Customers requiring immediate, real-time access to recent event records can search and review logs directly within the Google Security Operations console or via the Search API, where data freshness is unaffected. Ingested log data is safely queued and will export to BigQuery automatically. |
- All times are US/Pacific