Hello everyone,
Iām interested in learning how other teams approach security monitoring in Google Cloud environments.
For organizations using multiple cloud services, what are the most important things to consider when setting up security monitoring and alerting? Iām particularly interested in approaches for identifying suspicious activity, managing large numbers of alerts, and making sure important incidents are investigated quickly.
Iād also like to know how teams balance automated detection with manual investigation. For example, which security signals or events do you consider the highest priority, and how do you avoid unnecessary alert fatigue?


