Google Cloud Digital LeaderData and AI with Google CloudHard
A cybersecurity firm needs to analyze vast amounts of network log data (terabytes per day) in real-time to detect security threats and anomalies. They require a highly scalable, low-latency search and analytics engine that can handle full-text search and aggregate queries across diverse log formats. Which Google Cloud product is best suited for this requirement?
- ACloud SQL
- BBigQuery
- CElastic Cloud on Google Cloud (managed Elasticsearch)
- DCloud Spanner
Show answer & explanationAnswer & explanation
Correct answer: C. Elastic Cloud on Google Cloud (managed Elasticsearch)
Elasticsearch (or Elastic Cloud on Google Cloud) is an open-source distributed search and analytics engine specifically designed for full-text search, log analysis, and real-time operational intelligence. It excels at handling high-volume, semi-structured data like network logs with low-latency querying and aggregation.
Why the other options are wrong
- A. Cloud SQL is a relational database, not suitable for high-volume, semi-structured log data and full-text search.
- B. BigQuery is a data warehouse optimized for large-scale analytical queries, not real-time, full-text log search with low latency.
- D. Cloud Spanner is a globally distributed relational database for transactional consistency, not log analytics.
Elasticsearch for Log Analytics
Elasticsearch is a distributed, RESTful search and analytics engine capable of solving a growing number of use cases. It's commonly used for log analytics, full-text search, security intelligence, and operational monitoring.
- Provides real-time full-text search and analytical capabilities.
- Scales horizontally to handle massive data volumes.
- Ideal for semi-structured data like logs and events.
- Often deployed with Kibana for visualization (ELK stack).
Memory trick: For 'Elastic' search on 'logs', think of 'Elasticsearch' stretching to cover all your data.