Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium

A security operations center (SOC) is integrating a new cloud-native application into its SIEM system. The application generates logs in a proprietary JSON format, which the existing SIEM cannot directly parse for meaningful security events. What is the MOST critical step required to ensure these logs can be effectively analyzed by the SIEM?

  1. AIncreasing the storage capacity of the SIEM
  2. BImplementing a distributed denial-of-service (DDoS) protection service
  3. CUpgrading the SIEM's hardware to improve processing power
  4. DConfiguring log normalization and parsing rules
Show answer & explanation

Correct answer: D. Configuring log normalization and parsing rules

Log normalization and parsing rules are essential to transform proprietary or raw log data into a standardized, structured format that the SIEM can understand and analyze. Without these rules, the SIEM cannot extract meaningful security events, correlate data, or generate alerts, regardless of its storage or processing capabilities.

Why the other options are wrong

  • A. Increasing storage capacity is necessary if log volume is high, but it doesn't solve the problem of parsing unreadable formats.
  • B. DDoS protection is a network security measure and has no direct relevance to parsing proprietary log formats within a SIEM.
  • C. Upgrading hardware might improve processing speed, but it won't enable the SIEM to understand and extract information from an unknown log format.

Log Normalization

The process of converting disparate log formats from various sources into a common, structured format for easier analysis and correlation.

  • Essential for SIEM effectiveness.
  • Involves parsing and mapping fields.
  • Enables consistent querying and reporting.

Memory trick: Normalize the noise so your SIEM can make sense of it.

More Cloud Security Operations questions