This course provides a comprehensive, end-to-end exploration of Google SecOps SIEM, guiding learners from foundational concepts to advanced investigation and detection engineering. Participants will gain hands-on experience with data ingestion, normalization, RBAC configuration, searching, and dashboarding using both legacy and native capabilities. Through structured modules, demos, and curated examples, the course emphasizes real-world investigation workflows, UDM-based analytics, and YARA-L rule development. By the end of the course, learners will be equipped to operationalize SIEM effectively within their environment and build scalable processes for detection, investigation, and reporting.
通过 Coursera Plus 提高技能,仅需 239 美元/年(原价 399 美元)。立即节省

您将学到什么
Explain the architecture, data model, and core components of Google SecOps SIEM, including ingestion methods, UDM, normalization, and RBAC.
Ingest, normalize, and manage log data from multiple sources, using direct ingestion, APIs, cloud buckets, streaming services, and on-prem collectors
Perform effective investigations using raw logs, UDM search, statistical search, and data tables, and build dashboards.
Design, test, and optimize detections using YARA-L, including single-event, multi-event, composite rules, entity context, etc..
要了解的详细信息

可分享的证书
添加到您的领英档案
最近已更新!
April 2026
作业
5 项作业
授课语言:英语(English)
了解顶级公司的员工如何掌握热门技能

从 Software Development 浏览更多内容
状态:免费试用
状态:免费试用
状态:免费试用
状态:免费试用
人们为什么选择 Coursera 来帮助自己实现职业发展

Felipe M.
自 2018开始学习的学生
''能够按照自己的速度和节奏学习课程是一次很棒的经历。只要符合自己的时间表和心情,我就可以学习。'

Jennifer J.
自 2020开始学习的学生
''我直接将从课程中学到的概念和技能应用到一个令人兴奋的新工作项目中。'

Larry W.
自 2021开始学习的学生
''如果我的大学不提供我需要的主题课程,Coursera 便是最好的去处之一。'

Chaitanya A.
''学习不仅仅是在工作中做的更好:它远不止于此。Coursera 让我无限制地学习。'




