PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #35
Your company recently started pulling JSON logs from a third-party system into Google Security Operations (SecOps). You noticed that some fields are missing, and you want to parse them into UDM…
The correct answer is B. Create parser extensions using the no-code approach. The fastest way to handle missing fields in JSON logs is to create parser extensions using the no- code approach in Google SecOps. This allows you to quickly map additional fields into UDM without writing code or waiting on support requests, ensuring rapid parsing and…
Question
Your company recently started pulling JSON logs from a third-party system into Google Security Operations (SecOps). You noticed that some fields are missing, and you want to parse them into UDM fields as quickly as possible. What should you do?
Options
- AConfigure auto extraction to add the additional fields.
- BCreate parser extensions using the no-code approach.
- CCreate parser extensions using the code snippet approach.
- DSubmit a parser improvement request to Cloud Customer Care.
How the community answered
(25 responses)- A4% (1)
- B80% (20)
- C12% (3)
- D4% (1)
Explanation
The fastest way to handle missing fields in JSON logs is to create parser extensions using the no- code approach in Google SecOps. This allows you to quickly map additional fields into UDM without writing code or waiting on support requests, ensuring rapid parsing and normalization of the third-party logs.
Topics
Community Discussion
No community discussion yet for this question.