Google Cloud

Introduction to Google Security Operations (SIEM)

通过 Coursera Plus 提高技能,仅需 239 美元/年(原价 399 美元)。立即节省

Google Cloud

Introduction to Google Security Operations (SIEM)

包含在 Coursera Plus

深入了解一个主题并学习基础知识。
初级 等级
无需具备相关经验
6 小时 完成
灵活的计划
自行安排学习进度
深入了解一个主题并学习基础知识。
初级 等级
无需具备相关经验
6 小时 完成
灵活的计划
自行安排学习进度

您将学到什么

  • Explain the architecture, data model, and core components of Google SecOps SIEM, including ingestion methods, UDM, normalization, and RBAC.

  • Ingest, normalize, and manage log data from multiple sources, using direct ingestion, APIs, cloud buckets, streaming services, and on-prem collectors

  • Perform effective investigations using raw logs, UDM search, statistical search, and data tables, and build dashboards.

  • Design, test, and optimize detections using YARA-L, including single-event, multi-event, composite rules, entity context, etc..

要了解的详细信息

可分享的证书

添加到您的领英档案

最近已更新!

April 2026

作业

5 项作业

授课语言:英语(English)

了解顶级公司的员工如何掌握热门技能

Petrobras, TATA, Danone, Capgemini, P&G 和 L'Oreal 的徽标

该课程共有5个模块

This module introduces the foundational concepts of Google SecOps SIEM, providing learners with a clear understanding of the platform’s purpose, architecture, and data model. It covers key elements such as SIEM-supported ingestion methods, RBAC fundamentals, the Unified Data Model (UDM), normalization workflows, and the core search and visualization capabilities available in the SIEM interface. Learners will explore how detections are structured and how SIEM transforms raw logs into normalized, enriched events. By the end of the module, participants will have a strong conceptual baseline for how data flows through SIEM and how analysts interact with it in daily operations. This Module serves to give just the short topic introductions - there will be a deepdive to all of these topics and more in the respective learning modules.

涵盖的内容

8个视频1个作业

This module provides a comprehensive walkthrough of setting up Google SecOps SIEM, focusing on the full lifecycle of data onboarding, access control, and normalization. Learners will explore every supported ingestion path—direct collectors, third-party APIs, cloud storage buckets, streaming services, and on-prem deployments using BindPlane—understanding when and how each method is used. The module also dives deeply into SIEM’s RBAC framework, covering feature-level permissions, data-scoped access, scopes, labels, and practical strategies for implementing secure, least-privileged operations. Finally, learners will work through normalization concepts and parser management to ensure that ingested logs are structured, transformed, and enriched according to UDM best practices. By the end, participants will be able to deploy a fully functional and well-governed SIEM ingest pipeline.

涵盖的内容

19个视频1个作业

This module provides a comprehensive walkthrough of investigating security events within Google SecOps SIEM, focusing on how analysts move from raw log exploration to structured, hypothesis-driven investigations using UDM. Learners will begin with raw log search techniques to understand how data enters the platform and how to quickly validate ingestion, timestamps, and source context. The module then introduces the UDM schema and field families, explaining how normalization enables consistent querying across disparate data sources. Participants will progress to UDM search and statistical aggregation, learning how to pivot, group, and correlate events using structured queries and data tables. Through practical demos and guided examples, learners will develop efficient investigation workflows that combine raw logs, UDM searches, and aggregations to identify suspicious behavior, validate detections, and support incident response decisions.

涵盖的内容

6个视频1个作业

This module provides a comprehensive overview of dashboards in Google SecOps SIEM, focusing on how dashboards are used to visualize, monitor, and operationalize security data. Learners will begin with an introduction to curated dashboards and out-of-the-box content, understanding when and how to use prebuilt views versus custom dashboards. The module then guides participants through building YARA-L queries for dashboards, applying effective filtering techniques to focus on relevant signals and reduce noise. Advanced native dashboard functionalities are explored, including interactive widgets, drill-downs, and performance considerations, followed by an overview of legacy SIEM dashboards and how they differ from native dashboards. By the end of the module, learners will be able to design and maintain dashboards that provide clear, actionable security insights for both analysts and stakeholders.

涵盖的内容

5个视频1个作业

This module provides a comprehensive introduction to detection engineering in Google SecOps SIEM, focusing on building, testing, and optimizing detections using YARA-L. Learners will begin by exploring curated detection categories, rule sets, and rule dependencies to understand how detections are organized and deployed at scale. The module then dives into YARA-L rule construction, covering rule structure, variables, regex string matching, reference lists, repeated fields, and core YARA-L functions. Participants will learn how to design single-event, multi-event, and composite rules, leverage entity context and the entity graph to enhance detection fidelity, and understand how events are transformed into alerts. Finally, learners will practice rule testing and optimization techniques to improve performance, accuracy, and maintainability of detections in production environments.

涵盖的内容

14个视频1篇阅读材料1个作业

位教师

Google Cloud Training
Google Cloud
2,115 门课程4,055,999 名学生

提供方

Google Cloud

从 Software Development 浏览更多内容

人们为什么选择 Coursera 来帮助自己实现职业发展

Felipe M.

自 2018开始学习的学生
''能够按照自己的速度和节奏学习课程是一次很棒的经历。只要符合自己的时间表和心情,我就可以学习。'

Jennifer J.

自 2020开始学习的学生
''我直接将从课程中学到的概念和技能应用到一个令人兴奋的新工作项目中。'

Larry W.

自 2021开始学习的学生
''如果我的大学不提供我需要的主题课程,Coursera 便是最好的去处之一。'

Chaitanya A.

''学习不仅仅是在工作中做的更好:它远不止于此。Coursera 让我无限制地学习。'
Coursera Plus

通过 Coursera Plus 开启新生涯

无限制访问 10,000+ 世界一流的课程、实践项目和就业就绪证书课程 - 所有这些都包含在您的订阅中

通过在线学位推动您的职业生涯

获取世界一流大学的学位 - 100% 在线

加入超过 3400 家选择 Coursera for Business 的全球公司

提升员工的技能,使其在数字经济中脱颖而出

常见问题