Hi,
I’m concerned about finding a cost-effective solution to ingest these logs into Google SecOps. While I want to send this type of log data to Google SecOps, I’ve noticed there is a charge for Cloud Logging. If I agree to pay for the storage and retention costs associated with a Cloud Logging bucket, would there still be any egress charges for transferring these logs to Google SecOps?
Thank you!
Option 1: Direct ingestion
A special Cloud Logging filter can be configured in Google Cloud to send specific log types to Google Security Operations in real-time. These logs are generated by Google Cloud services.
Google Security Operations only ingests supported log types. Available log types include:
Cloud Audit Logs
Cloud NAT
Cloud DNS
Cloud Next Generation Firewall
Cloud Intrusion Detection System
Cloud Load Balancing
Cloud SQL
Windows Event logs
Linux syslog
Linux Sysmon
Zeek
Google Kubernetes Engine
Audit Daemon (auditd)
Apigee
reCAPTCHA Enterprise
Cloud Run logs (GCP_RUN)