QuestionQ54

Platform operations

Your company has deployed two on-premises firewalls. You need to configure them to send logs to Google Security Operations (SecOps) through Syslog. What should you do?

  • A Pull the firewall logs by using a Google SecOps feed integration.
  • B Set the Google SecOps URL instance as the Syslog destination.
  • C Deploy a third-party agent (e.g Bindplane, NXLog) on your on-premises environment, and set the agent as the Syslog destination.
  • D Deploy a Google Ops Agent on your on-premises environment, and set the agent as the Syslog destination.
Explanation

Google SecOps uses a local log-collection agent for Syslog from on-premises sources. Deploying a supported third-party agent such as Bindplane or NXLog allows the firewalls to send Syslog to that local destination, which then forwards the logs to Google SecOps. Google documents the Bindplane agent for on-premises log forwarding, including on-premises firewalls.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!