Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Introduction
- General overview of the Elastic Stack (ELK)
ELK Stack Architecture and Current Environment Review
- Review of the Altor CB current architecture
- Core ELK components: Elasticsearch, Logstash, Kibana, and Beats
- Comparison between Ingest nodes and Logstash
- Scalability and performance factors in on-premise deployments
- Best practices for administration
Beats – Distributed Monitoring
- Setup and utilization of Filebeat, Auditbeat, Winlogbeat, and Packetbeat
- Securing data transport via SSL
- Difference between preconfigured modules and custom inputs
- Integration strategies with Logstash and Ingest Pipelines
Parsing and Ingesting Logs from Apps and Databases
- Capturing custom application logs
- Leveraging Logstash for data transformation and parsing
- Applying filters such as grok, dissect, kv, mutate, and date
- Establishing database connections (Oracle, PostgreSQL, SQL Server) via the JDBC input plugin
- Practical examples: error logs, audit trails, traces, and slow queries
Advanced Search and Regular Expressions
- Advanced search syntax techniques in Kibana
- Application of regular expressions (regex)
- Combining filters using OR/AND logic
- Handling nested fields and arrays
- Storing reusable queries and filter definitions
Custom Dashboards and Visualizations in Kibana
- Visualization formats: bar charts, line graphs, maps, and tables
- Working with aggregations and metrics
- Implementing dynamic filters, controls, and drill-down capabilities
- Methods for sharing dashboards
- Hands-on exercises: building dashboards from database and system logs
Alerts and Email Notifications
- Overview of Watcher and alternatives like ElastAlert and Kibana Alerts
- Defining custom conditions and triggers
- Setting up email output configurations
- Exercise: Configuring alerts for critical events in Windows or database logs
User and Permission Management
- Introduction to X-Pack and available free options
- Creating user accounts and defining roles
- Controlling access at the index, dashboard, and query level
- Exercise: Establishing roles for audit and operations teams
Elasticsearch REST API
- Basics of the Elasticsearch RESTful API
- Executing GET and POST queries
- Managing manual and automated indexing
- Utilizing tools such as curl and Postman
- Exercises: Performing search, insert, delete, and update operations on documents
Requirements
- A solid grasp of fundamental ELK Stack architecture and core components
- Practical experience in log ingestion and visualization via Kibana and Logstash
- Proficiency with the Linux command line and basic scripting tasks
Target Audience
- System administrators
- Infrastructure engineers
- Technical teams looking to advance their log centralization capabilities
Testimonials (2)
The content is very helpful, and the trainer makes it more easier to understand
Ibrahim Al mayahi - Vastech SA
Course - Advanced Elasticsearch and Kibana Administration
the profesionalism of the trainer; the way he tried to respond to all the questions; the review questions we had to ask: engaging us in conversations