From the course: Introduction to SecOps on Google Distributed Cloud (GDC) by Google
Unlock this course with a free trial
Join today to access over 25,400 courses taught by industry experts.
Security-specific metrics in Splunk - Google Cloud Platform Tutorial
From the course: Introduction to SecOps on Google Distributed Cloud (GDC) by Google
Security-specific metrics in Splunk
- [Instructor] What security services are metrics collected for? Well, event logs can also be converted to metric data points in Splunk, either at indexing or at search time. You can look at two security metric types defined from logs: audits and operations. Audit logs include these sources in decreasing order of log volume, Kubernetes API server, Linux audit, Nessus Monitoring, SSH server, and other Linux audit types such as Chkrootkit and ClamAV. The JSON logs refer to the original logs before being parsed and indexed by Splunk in a more digestible and readable format. In an ideal world, you wouldn't use these, but they are still relevant for any unsupported stream. Audit logs provide crucial insights into system activities, user authentication, network scanning, and potential security threats detected by tools like Nessus and ClamAV, which are fundamental for compliance and security monitoring. Operations logs…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
-
-
-
-
(Locked)
Module overview1m 14s
-
(Locked)
Log types in the GDC SOC2m 24s
-
(Locked)
Audit logs5m 51s
-
(Locked)
Audit logs at Cymbal Federal1m 36s
-
(Locked)
Security logs51s
-
(Locked)
Operational logs1m 36s
-
(Locked)
Operational logs at Cymbal Federal46s
-
(Locked)
Review: Logs in Splunk1m 19s
-
(Locked)
Metrics in Splunk1m 27s
-
(Locked)
Baseline metrics4m 34s
-
(Locked)
Security-specific metrics in Splunk1m 47s
-
(Locked)
Using Splunk metrics1m 57s
-
(Locked)
Splunk metrics at Cymbal Federal1m 30s
-
(Locked)
Splunk dashboards5m 32s
-
(Locked)
Alerts in Splunk1m 19s
-
(Locked)
Alerts at Cymbal Federal1m
-
(Locked)
Alert rules1m 55s
-
(Locked)
The alert inventory2m 4s
-
(Locked)
Module review59s
-
(Locked)