2Data management
- 2.1Ingesting logs for security tooling
Understand determining data-ingestion approaches in security tools (SCC, Google SecOps), configuring ingestion tools/features, assessing required logs for detection/response (incl. automated sources, SCC Event Threat Detection), evaluating Google SecOps parsers and configuring parser modifications/extensions, data normalization (UDM) from log sources, evaluating new labels, and managing log/ingestion costs.
- 2.2User, asset, and entity context
Understand identifying relevant threat intelligence in the enterprise, differentiating event vs entity data log sources (Cloud Audit Logs, Active Directory organizational context), and evaluating event/entity data matches for enrichment using aliasing fields.

