From the course: Introduction to SecOps on Google Distributed Cloud (GDC) by Google
Unlock this course with a free trial
Join today to access over 25,400 courses taught by industry experts.
Module review - Google Cloud Platform Tutorial
From the course: Introduction to SecOps on Google Distributed Cloud (GDC) by Google
Module review
- [Instructor] In this module, you were introduced to the basics of the SIEM setup for GDC. You learned about the types of logs that are collected and analyzed in Splunk, such as audit, security, and operational logs. You then looked at the pre-existing metrics that are available in Splunk. Correlating these metrics across various infrastructure components in Splunk enables you to detect usage and performance trends, as well as efficiently manage incidents before they affect system performance. You then explored some of the most common dashboard charts used in Splunk for the GDC SOC. Dashboards guide users through a narrative that reveal insights, trends, and critical information. Through the smart design of dashboards, efficient decision making and fast actions are made possible. Finally, you looked at the different types of alert rules that can be sent and how the alert inventory collects all alerts predefined for the…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
-
(Locked)
Module overview1m 14s
-
(Locked)
Log types in the GDC SOC2m 24s
-
(Locked)
Audit logs5m 51s
-
(Locked)
Audit logs at Cymbal Federal1m 36s
-
(Locked)
Security logs51s
-
(Locked)
Operational logs1m 36s
-
(Locked)
Operational logs at Cymbal Federal46s
-
(Locked)
Review: Logs in Splunk1m 19s
-
(Locked)
Metrics in Splunk1m 27s
-
(Locked)
Baseline metrics4m 34s
-
(Locked)
Security-specific metrics in Splunk1m 47s
-
(Locked)
Using Splunk metrics1m 57s
-
(Locked)
Splunk metrics at Cymbal Federal1m 30s
-
(Locked)
Splunk dashboards5m 32s
-
(Locked)
Alerts in Splunk1m 19s
-
(Locked)
Alerts at Cymbal Federal1m
-
(Locked)
Alert rules1m 55s
-
(Locked)
The alert inventory2m 4s
-
(Locked)
Module review59s
-
(Locked)