Professional Cloud Security EngineerManaging operationsMedium

A security engineer needs to create a custom dashboard in Cloud Monitoring to visualize specific security events from Cloud Logging. The dashboard should display the count of 'authentication_failure' events for SSH connections over the last 24 hours, grouped by source IP address. Which query language should the engineer use to define the log-based metric for this dashboard?

  1. AMQL (Monitoring Query Language)
  2. BSQL (Structured Query Language)
  3. CLogQL (Log Query Language)
  4. DPromQL (Prometheus Query Language)
Show answer & explanation

Correct answer: A. MQL (Monitoring Query Language)

To create custom log-based metrics and visualize them in Cloud Monitoring dashboards, especially when doing aggregations and groupings on log data, Monitoring Query Language (MQL) is the primary and most powerful tool. While basic log-based metrics can sometimes be created with simpler filters, MQL provides the flexibility for complex scenarios like grouping by source IP.

Why the other options are wrong

  • B. SQL is a general-purpose database query language and not directly used to define log-based metrics within Cloud Monitoring.
  • C. LogQL is used in Grafana Loki for log querying, not a standard Google Cloud Monitoring query language.
  • D. PromQL is used for querying Prometheus metrics, not directly for Cloud Logging data or custom log-based metrics in Cloud Monitoring.

Monitoring Query Language (MQL)

A powerful query language used within Google Cloud Monitoring to define, query, and manipulate metric data, including custom log-based metrics for dashboards and alerting.

  • Used for advanced metric analysis in Cloud Monitoring.
  • Supports aggregations, filters, and time series manipulation.
  • Essential for complex custom dashboards and alerting policies.
  • Can query both standard and custom log-based metrics.

Memory trick: MQL makes metrics meaningful, especially from logs.

More Managing operations questions