nerdexam
Google

PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #35

Your company recently started pulling JSON logs from a third-party system into Google Security Operations (SecOps). You noticed that some fields are missing, and you want to parse them into UDM…

The correct answer is B. Create parser extensions using the no-code approach. The fastest way to handle missing fields in JSON logs is to create parser extensions using the no- code approach in Google SecOps. This allows you to quickly map additional fields into UDM without writing code or waiting on support requests, ensuring rapid parsing and…

Data Ingestion and Parsing

Question

Your company recently started pulling JSON logs from a third-party system into Google Security Operations (SecOps). You noticed that some fields are missing, and you want to parse them into UDM fields as quickly as possible. What should you do?

Options

  • AConfigure auto extraction to add the additional fields.
  • BCreate parser extensions using the no-code approach.
  • CCreate parser extensions using the code snippet approach.
  • DSubmit a parser improvement request to Cloud Customer Care.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    80% (20)
  • C
    12% (3)
  • D
    4% (1)

Explanation

The fastest way to handle missing fields in JSON logs is to create parser extensions using the no- code approach in Google SecOps. This allows you to quickly map additional fields into UDM without writing code or waiting on support requests, ensuring rapid parsing and normalization of the third-party logs.

Topics

#log parsing#UDM fields#parser extensions#no-code parsing

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER Practice