How to Securely Export Filtered Logs to an On-Prem SIEM?
A team at your organization collects logs in an on-premises security information and event management system (SIEM). You must provide a subset of Google Cloud logs for the SIEM, and minimize the risk of data exposure in your cloud environment. What should you do?
Community Votes
57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests secure log export architecture; the common trap is selecting log views or storage buckets instead of a filtered sink with a managed streaming pipeline.
Learn how to securely export a filtered subset of Google Cloud logs to an on-premises SIEM using log sinks, Pub/Sub, and Dataflow. This page establishes why this streaming architecture is the correct PCSE exam answer.
Candidates often select log views (B) assuming they handle external delivery, but log views only control IAM access within GCP and cannot stream data to on-premises systems.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Log sinks enable precise filtering at the collection layer, ensuring only relevant logs leave the environment and directly addressing the requirement to minimize data exposure. Publishing those filtered logs to Pub/Sub provides a secure, scalable, and real-time messaging layer that decouples collection from consumption. Dataflow then processes and reliably forwards the stream to the on-premises SIEM without requiring long-lived credentials or bulk archival storage.Why the Other Options Are Wrong
Option A streams all logs to BigQuery first, violating the subset requirement and introducing unnecessary query costs and potential exposure before filtering occurs. Option B relies on log views, which only manage IAM permissions for viewing logs within GCP and lack native export capabilities to external systems. Option D recommends storing logs in Cloud Storage and distributing service account keys, which creates a high-severity credential leak risk and lacks real-time streaming.Community Comment Notes
Several candidates debated between B and C, noting that log views simplify access control but fail to address the actual export mechanism. As BPzen highlighted, the sink filtering combined with Pub/Sub and Dataflow ensures only necessary data travels externally. Other voters acknowledged that while B feels simpler, it does not solve the external SIEM integration requirement.Official Reference
Exam Strategy
Always map the requirement to the data flow first: filter at the source (sink), transport securely (Pub/Sub), and process/deliver reliably (Dataflow). Avoid options that recommend hardcoding credentials or over-collecting data before filtering.
Frequently Asked Questions
Why can't I use a log view to export logs to my SIEM?
Log views only restrict IAM access to logs stored in GCP log buckets; they do not contain functionality to route or stream data to external on-premises systems.
Is Dataflow required to send logs to an external SIEM?
While not strictly mandatory for basic setups, Dataflow provides the secure transformation, retry logic, and scaling needed to reliably deliver filtered logs to enterprise SIEMs.