How to Securely Export Filtered Logs to an On-Prem SIEM?

Logging & Security Architecture
Answer Correct answer: C — Create a log sink for the relevant logs, send them to Pub/Sub, and use Dataflow to securely push the filtered stream to the on-premises SIEM.

A team at your organization collects logs in an on-premises security information and event management system (SIEM). You must provide a subset of Google Cloud logs for the SIEM, and minimize the risk of data exposure in your cloud environment. What should you do?

  1. Create a new BigQuery dataset. Stream all logs to this dataset. Provide the on-premises SIEM system access to the data in BigQuery by using workload identity federation and let the SIEM team filter for the relevant log data.
  2. Define a log view for the relevant logs. Provide access to the log view to a principal from your on-premises identity provider by using workforce identity federation.
  3. Create a log sink for the relevant logs. Send the logs to Pub/Sub. Retrieve the logs from Pub/Sub and push the logs to the SIEM by using Dataflow. Correct Answer
  4. Filter for the relevant logs. Store the logs in a Cloud Storage bucket. Grant the service account access to the bucket. Provide the service account key to the SIEM team.

Community Votes

C
57%
B
43%

57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests secure log export architecture; the common trap is selecting log views or storage buckets instead of a filtered sink with a managed streaming pipeline.

Learn how to securely export a filtered subset of Google Cloud logs to an on-premises SIEM using log sinks, Pub/Sub, and Dataflow. This page establishes why this streaming architecture is the correct PCSE exam answer.

Candidates often select log views (B) assuming they handle external delivery, but log views only control IAM access within GCP and cannot stream data to on-premises systems.

Community Discussion (7 comments)

Popa 👍 1 Selected: B
Option C, does involve setting up multiple components (Pub/Sub, Dataflow, log sinks) and ensuring they are properly configured. This might add to the complexity of the setup. That being said, option B is still a strong choice because it provides a more straightforward approach to controlling and accessing the logs using log views and identity federation
KLei 👍 1 Selected: C
B: Defining a log view provides access control but does not facilitate exporting logs to an external SIEM effectively.
BPzen 👍 2 Selected: C
Why C is Correct: Log Sink for Filtering: A log sink allows you to filter and export only the relevant logs, ensuring unnecessary data is not sent, which reduces the risk of data exposure. Pub/Sub for Delivery: Exporting logs to Pub/Sub enables real-time streaming of filtered logs to external systems. This ensures the SIEM receives logs promptly and securely. Dataflow for Transformation and Transfer: Use Dataflow to process and transform logs as needed before pushing them to the on-premises SIEM.
MoAk 👍 1 Selected: C
Answer C.
kalbd2212 👍 2
going with C..
irene062 👍 1 Selected: B
Log views let you grant a user access to only a subset of the logs stored in a log bucket. https://cloud.google.com/logging/docs/logs-views
abdelrahman89 👍 1 Selected: B
Answer B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Log sinks enable precise filtering at the collection layer, ensuring only relevant logs leave the environment and directly addressing the requirement to minimize data exposure. Publishing those filtered logs to Pub/Sub provides a secure, scalable, and real-time messaging layer that decouples collection from consumption. Dataflow then processes and reliably forwards the stream to the on-premises SIEM without requiring long-lived credentials or bulk archival storage.

Why the Other Options Are Wrong

Option A streams all logs to BigQuery first, violating the subset requirement and introducing unnecessary query costs and potential exposure before filtering occurs. Option B relies on log views, which only manage IAM permissions for viewing logs within GCP and lack native export capabilities to external systems. Option D recommends storing logs in Cloud Storage and distributing service account keys, which creates a high-severity credential leak risk and lacks real-time streaming.

Community Comment Notes

Several candidates debated between B and C, noting that log views simplify access control but fail to address the actual export mechanism. As BPzen highlighted, the sink filtering combined with Pub/Sub and Dataflow ensures only necessary data travels externally. Other voters acknowledged that while B feels simpler, it does not solve the external SIEM integration requirement.

Official Reference

Exam Strategy

Always map the requirement to the data flow first: filter at the source (sink), transport securely (Pub/Sub), and process/deliver reliably (Dataflow). Avoid options that recommend hardcoding credentials or over-collecting data before filtering.

Frequently Asked Questions

Why can't I use a log view to export logs to my SIEM?

Log views only restrict IAM access to logs stored in GCP log buckets; they do not contain functionality to route or stream data to external on-premises systems.

Is Dataflow required to send logs to an external SIEM?

While not strictly mandatory for basic setups, Dataflow provides the secure transformation, retry logic, and scaling needed to reliably deliver filtered logs to enterprise SIEMs.

Related Analysis

← Back to PCSE Study Guide