이 문서에서는 기존 Google Security Operations 파서에서 처리하지 않는 로그 데이터를 처리하는 데 도움이 되는 옵션을 설명합니다. 이러한 경우 Google SecOps는 파싱 및 수집을 지원하는 로그 유형 생성을 지원합니다.
다음 유형 중에서 선택할 수 있습니다.
사전 빌드된 로그 유형: Google SecOps에 사전 빌드된 로그 유형을 만들고 관리하도록 요청할 수 있습니다. 이는 사전 빌드되고 사전 구성된 파서와 함께 작동합니다. 요청 후 2~3주가 지나면 이러한 사전 빌드된 로그 유형이 모든 Google SecOps 고객에게 제공됩니다.
커스텀 로그 유형: 조직에서 만들고 관리합니다. 커스텀 로그 유형과 파서는 생성 후 10분 후에 내부적으로 (조직에만) 사용할 수 있으므로 내부에서 해당 커스텀 파서를 구성해야 합니다.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2025-09-04(UTC)"],[],[],null,["# Request prebuilt and create custom log types\n============================================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n| **Note:** This feature is covered by [Pre-GA Offerings Terms](https://chronicle.security/legal/service-terms/) of the Google Security Operations Service Specific Terms. Pre-GA features might have limited support, and changes to pre-GA features might not be compatible with other pre-GA versions. For more information, see the [Google SecOps Technical Support Service guidelines](https://chronicle.security/legal/technical-support-services-guidelines/) and the [Google SecOps Service Specific Terms](https://chronicle.security/legal/service-terms/).\n\nThis document describes options to help you process log data that isn't\nprocessed by existing Google Security Operations parsers. In such cases,\nGoogle SecOps supports the creation of log types to enable\nparsing and ingestion.\n\nYou can choose between the following types:\n\n- *Prebuilt log types*: You can request Google SecOps to create\n and manage prebuilt log types. These work in conjunction with prebuilt and\n preconfigured parsers. 2--3 weeks after your request, these prebuilt log\n types are made available to all Google SecOps customers.\n\n- *Custom log types*: Created and managed by your organization. You need to\n configure corresponding custom parsers in-house, where the custom log types\n and parsers become internally (only to your organization) available 10\n minutes after creation.\n\nFor information about corresponding **prebuilt parsers** and\n**custom parsers** , see\n[Manage prebuilt and custom parsers](/chronicle/docs/event-processing/manage-parser-updates).\n\nCreate a custom log type\n------------------------\n\nTo create a custom log type, do the following:\n\n1. Go to **SIEM settings \\\u003e Available Log Types** . You can view\n available log types using the **Search** feature.\n\n2. Click **Request a Log Type**.\n\n3. Under the **Create a custom log type on your own**, enter details for your log type.\n\n For example, to create a custom log type for *Azure Key Vault logging*,\n complete the following:\n - In the **Vendor/Product** field, enter\n `Azure Key Vault logging`.\n\n - In the **Log Type** field, enter `AZURE_KEYVAULT_LOGGING`.\n\n4. Click **Create Log Type**.\n\n5. Wait 10 minutes to ensure that the new log type is available in all\n components before creating feeds with it.\n\nThe custom log type limitations are:\n\n- Total: 400\n\n- Daily: 25\n\n- Hourly: 8\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]