Google Cloud

Introduction to Google Security Operations (SIEM)

Grow your skills with Coursera Plus for $239/year (usually $399). Save now.

Google Cloud

Introduction to Google Security Operations (SIEM)

Gain insight into a topic and learn the fundamentals.
Beginner level
No prior experience required
6 hours to complete
Flexible schedule
Learn at your own pace
Gain insight into a topic and learn the fundamentals.
Beginner level
No prior experience required
6 hours to complete
Flexible schedule
Learn at your own pace

What you'll learn

  • Explain the architecture, data model, and core components of Google SecOps SIEM, including ingestion methods, UDM, normalization, and RBAC.

  • Ingest, normalize, and manage log data from multiple sources, using direct ingestion, APIs, cloud buckets, streaming services, and on-prem collectors

  • Perform effective investigations using raw logs, UDM search, statistical search, and data tables, and build dashboards.

  • Design, test, and optimize detections using YARA-L, including single-event, multi-event, composite rules, entity context, etc..

Details to know

Shareable certificate

Add to your LinkedIn profile

Recently updated!

April 2026

Assessments

5 assignments

Taught in English

See how employees at top companies are mastering in-demand skills

 logos of Petrobras, TATA, Danone, Capgemini, P&G and L'Oreal

There are 5 modules in this course

This module introduces the foundational concepts of Google SecOps SIEM, providing learners with a clear understanding of the platform’s purpose, architecture, and data model. It covers key elements such as SIEM-supported ingestion methods, RBAC fundamentals, the Unified Data Model (UDM), normalization workflows, and the core search and visualization capabilities available in the SIEM interface. Learners will explore how detections are structured and how SIEM transforms raw logs into normalized, enriched events. By the end of the module, participants will have a strong conceptual baseline for how data flows through SIEM and how analysts interact with it in daily operations. This Module serves to give just the short topic introductions - there will be a deepdive to all of these topics and more in the respective learning modules.

What's included

8 videos1 assignment

This module provides a comprehensive walkthrough of setting up Google SecOps SIEM, focusing on the full lifecycle of data onboarding, access control, and normalization. Learners will explore every supported ingestion path—direct collectors, third-party APIs, cloud storage buckets, streaming services, and on-prem deployments using BindPlane—understanding when and how each method is used. The module also dives deeply into SIEM’s RBAC framework, covering feature-level permissions, data-scoped access, scopes, labels, and practical strategies for implementing secure, least-privileged operations. Finally, learners will work through normalization concepts and parser management to ensure that ingested logs are structured, transformed, and enriched according to UDM best practices. By the end, participants will be able to deploy a fully functional and well-governed SIEM ingest pipeline.

What's included

19 videos1 assignment

This module provides a comprehensive walkthrough of investigating security events within Google SecOps SIEM, focusing on how analysts move from raw log exploration to structured, hypothesis-driven investigations using UDM. Learners will begin with raw log search techniques to understand how data enters the platform and how to quickly validate ingestion, timestamps, and source context. The module then introduces the UDM schema and field families, explaining how normalization enables consistent querying across disparate data sources. Participants will progress to UDM search and statistical aggregation, learning how to pivot, group, and correlate events using structured queries and data tables. Through practical demos and guided examples, learners will develop efficient investigation workflows that combine raw logs, UDM searches, and aggregations to identify suspicious behavior, validate detections, and support incident response decisions.

What's included

6 videos1 assignment

This module provides a comprehensive overview of dashboards in Google SecOps SIEM, focusing on how dashboards are used to visualize, monitor, and operationalize security data. Learners will begin with an introduction to curated dashboards and out-of-the-box content, understanding when and how to use prebuilt views versus custom dashboards. The module then guides participants through building YARA-L queries for dashboards, applying effective filtering techniques to focus on relevant signals and reduce noise. Advanced native dashboard functionalities are explored, including interactive widgets, drill-downs, and performance considerations, followed by an overview of legacy SIEM dashboards and how they differ from native dashboards. By the end of the module, learners will be able to design and maintain dashboards that provide clear, actionable security insights for both analysts and stakeholders.

What's included

5 videos1 assignment

This module provides a comprehensive introduction to detection engineering in Google SecOps SIEM, focusing on building, testing, and optimizing detections using YARA-L. Learners will begin by exploring curated detection categories, rule sets, and rule dependencies to understand how detections are organized and deployed at scale. The module then dives into YARA-L rule construction, covering rule structure, variables, regex string matching, reference lists, repeated fields, and core YARA-L functions. Participants will learn how to design single-event, multi-event, and composite rules, leverage entity context and the entity graph to enhance detection fidelity, and understand how events are transformed into alerts. Finally, learners will practice rule testing and optimization techniques to improve performance, accuracy, and maintainability of detections in production environments.

What's included

14 videos1 reading1 assignment

Instructor

Google Cloud Training
Google Cloud
2,114 Courses4,033,576 learners

Offered by

Google Cloud

Why people choose Coursera for their career

Felipe M.

Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."

Jennifer J.

Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."

Larry W.

Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."

Chaitanya A.

"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."
Coursera Plus

Open new doors with Coursera Plus

Unlimited access to 10,000+ world-class courses, hands-on projects, and job-ready certificate programs - all included in your subscription

Advance your career with an online degree

Earn a degree from world-class universities - 100% online

Join over 3,400 global companies that choose Coursera for Business

Upskill your employees to excel in the digital economy

Frequently asked questions