PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #9
You are implementing Google Security Operations (SecOps) with multiple log sources. You want to closely monitor the health of the ingestion pipeline's forwarders and collection agents, and detect…
The correct answer is A. Create a notification in Cloud Monitoring using a metric-absence condition based on sample. The best solution is to create a Cloud Monitoring notification with a metric-absence condition for each collector_id. A metric-absence alert triggers when expected ingestion metrics are missing within a defined period (e.g., five minutes), which quickly identifies silent…
Question
You are implementing Google Security Operations (SecOps) with multiple log sources. You want to closely monitor the health of the ingestion pipeline's forwarders and collection agents, and detect silent sources within five minutes. What should you do?
Options
- ACreate a notification in Cloud Monitoring using a metric-absence condition based on sample
- BCreate a Google SecOps SIEM dashboard to show the ingestion metrics for each log_type and
- CCreate an ingestion notification for health metrics in Cloud Monitoring based on the total ingested
- DCreate a Looker dashboard that queries the BigQuery ingestion metrics schema for each
How the community answered
(33 responses)- A70% (23)
- B9% (3)
- C18% (6)
- D3% (1)
Explanation
The best solution is to create a Cloud Monitoring notification with a metric-absence condition for each collector_id. A metric-absence alert triggers when expected ingestion metrics are missing within a defined period (e.g., five minutes), which quickly identifies silent sources or failed collectors. This provides near real-time detection of ingestion health issues in the SecOps
Topics
Community Discussion
No community discussion yet for this question.