Professional Cloud Security EngineerManaging operationsMedium

A security engineer needs to ensure that specific sensitive log entries, such as those indicating data exfiltration attempts or critical security alerts, are immediately forwarded to a Security Information and Event Management (SIEM) system for real-time analysis and incident response. They want to avoid any delays in log delivery and ensure reliability. Which Cloud Logging feature should be configured?

  1. AA Log Sink to BigQuery
  2. BA Log Sink to Cloud Storage
  3. CA Log Sink to Cloud Logging bucket
  4. DA Log Sink to Pub/Sub
Show answer & explanation

Correct answer: D. A Log Sink to Pub/Sub

A Log Sink to Pub/Sub is the recommended method for streaming logs to external systems like a SIEM for real-time processing. Pub/Sub provides low-latency, reliable message delivery, ensuring that critical log entries are forwarded without significant delays for immediate analysis.

Why the other options are wrong

  • A. BigQuery is used for analytical queries and data warehousing, not for real-time streaming to external SIEMs.
  • B. Cloud Storage is typically used for long-term archival, not real-time streaming to a SIEM.
  • C. Routing to another Cloud Logging bucket keeps logs within Cloud Logging, but doesn't forward them to an external SIEM system.

Cloud Logging Log Sink to Pub/Sub

A Cloud Logging feature that forwards selected log entries in real-time to a Pub/Sub topic, enabling immediate consumption by external systems like SIEMs for real-time analysis and incident response.

  • Provides low-latency, real-time log streaming.
  • Ensures reliable message delivery.
  • Ideal for integrating with external SIEMs, SOARs, or custom analytics platforms.
  • Supports filtering to send only relevant logs.

Memory trick: Pub/Sub is the 'Post Office' for your logs, ensuring 'swift' and 'reliable' delivery to your SIEM.

More Managing operations questions