Professional Cloud Security EngineerManaging operationsMedium
A security engineer needs to ensure that specific sensitive log entries, such as those indicating data exfiltration attempts or critical security alerts, are immediately forwarded to a Security Information and Event Management (SIEM) system for real-time analysis and incident response. They want to avoid any delays in log delivery and ensure reliability. Which Cloud Logging feature should be configured?
- AA Log Sink to BigQuery
- BA Log Sink to Cloud Storage
- CA Log Sink to Cloud Logging bucket
- DA Log Sink to Pub/Sub
Show answer & explanationAnswer & explanation
Correct answer: D. A Log Sink to Pub/Sub
A Log Sink to Pub/Sub is the recommended method for streaming logs to external systems like a SIEM for real-time processing. Pub/Sub provides low-latency, reliable message delivery, ensuring that critical log entries are forwarded without significant delays for immediate analysis.
Why the other options are wrong
- A. BigQuery is used for analytical queries and data warehousing, not for real-time streaming to external SIEMs.
- B. Cloud Storage is typically used for long-term archival, not real-time streaming to a SIEM.
- C. Routing to another Cloud Logging bucket keeps logs within Cloud Logging, but doesn't forward them to an external SIEM system.
Cloud Logging Log Sink to Pub/Sub
A Cloud Logging feature that forwards selected log entries in real-time to a Pub/Sub topic, enabling immediate consumption by external systems like SIEMs for real-time analysis and incident response.
- Provides low-latency, real-time log streaming.
- Ensures reliable message delivery.
- Ideal for integrating with external SIEMs, SOARs, or custom analytics platforms.
- Supports filtering to send only relevant logs.
Memory trick: Pub/Sub is the 'Post Office' for your logs, ensuring 'swift' and 'reliable' delivery to your SIEM.