Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Sovereignty
- Impact of Elastic license changes and the emergence of forks.
- Feature comparison between OpenSearch and Elasticsearch for 2025-2026.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security plugin configuration: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios using discovery.seed_hosts and minimum master node settings.
Data Ingestion
- Indexing via REST API, bulk loading techniques, and mapping definitions.
- Utilizing Beats, Fluent Bit, and Logstash for data pipelines.
- Collecting traces and metrics with the OpenTelemetry Collector.
Search and Dashboards
- Query DSL fundamentals: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: defining alert rules and performing anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion strategies.
- Designing Hot-Warm-Cold architectures.
- Optimizing mappings and enhancing text analysis.
Security and Access Control
- Implementing RBAC through users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Applying document-level security and field masking.
Backup and Recovery
- Configuring snapshot repositories for MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery.
Requirements
- Familiarity with search engine concepts and inverted indexes.
- Practical experience working with REST APIs and JSON structures.
- Basic Linux administration skills, including systemd, log management, and package handling.
Target Audience
- Engineers specializing in search and log analytics.
- Teams seeking to replace managed Elasticsearch or Splunk instances.
- Security analysts developing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs