Google Cloud Digital LeaderData and AI with Google CloudHard

A cybersecurity firm needs to analyze vast amounts of network log data (terabytes per day) in real-time to detect security threats and anomalies. They require a highly scalable, low-latency search and analytics engine that can handle full-text search and aggregate queries across diverse log formats. Which Google Cloud product is best suited for this requirement?

  1. ACloud SQL
  2. BBigQuery
  3. CElastic Cloud on Google Cloud (managed Elasticsearch)
  4. DCloud Spanner
Show answer & explanation

Correct answer: C. Elastic Cloud on Google Cloud (managed Elasticsearch)

Elasticsearch (or Elastic Cloud on Google Cloud) is an open-source distributed search and analytics engine specifically designed for full-text search, log analysis, and real-time operational intelligence. It excels at handling high-volume, semi-structured data like network logs with low-latency querying and aggregation.

Why the other options are wrong

  • A. Cloud SQL is a relational database, not suitable for high-volume, semi-structured log data and full-text search.
  • B. BigQuery is a data warehouse optimized for large-scale analytical queries, not real-time, full-text log search with low latency.
  • D. Cloud Spanner is a globally distributed relational database for transactional consistency, not log analytics.

Elasticsearch for Log Analytics

Elasticsearch is a distributed, RESTful search and analytics engine capable of solving a growing number of use cases. It's commonly used for log analytics, full-text search, security intelligence, and operational monitoring.

  • Provides real-time full-text search and analytical capabilities.
  • Scales horizontally to handle massive data volumes.
  • Ideal for semi-structured data like logs and events.
  • Often deployed with Kibana for visualization (ELK stack).

Memory trick: For 'Elastic' search on 'logs', think of 'Elasticsearch' stretching to cover all your data.

More Data and AI with Google Cloud questions