This course provides a comprehensive, end-to-end exploration of Google SecOps SIEM, guiding learners from foundational concepts to advanced investigation and detection engineering. Participants will gain hands-on experience with data ingestion, normalization, RBAC configuration, searching, and dashboarding using both legacy and native capabilities. Through structured modules, demos, and curated examples, the course emphasizes real-world investigation workflows, UDM-based analytics, and YARA-L rule development. By the end of the course, learners will be equipped to operationalize SIEM effectively within their environment and build scalable processes for detection, investigation, and reporting.
What you'll learn
understanding foundational security concepts
gaining hands-on experience with data ingestion and normalization
configuring role-based access control (RBAC)
developing YARA-L rules
creating dashboards for security operations
Course objectives
equip learners with the skills to implement Google SecOps SIEM
enable participants to design scalable detection and reporting processes