Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Sovereignty in Open-Source Search and Analytics
- Elasticsearch license changes and the emergence of forks.
- Feature parity between OpenSearch and Elasticsearch in the 2025-2026 landscape.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest.
- Security plugin configuration: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum master nodes.
Data Ingestion
- REST API indexing, bulk loading strategies, and mapping definitions.
- Pipelines using Beats, Fluent Bit, and Logstash.
- Integration of OpenTelemetry Collector for traces and metrics.
Search and Dashboards
- Query DSL components: match, term, range, aggregations, and nested fields.
- Creating visualizations and dashboards in OpenSearch Dashboards.
- SIEM applications: configuring alert rules and anomaly detection.
Index Management
- Index Lifecycle Management (ILM): rollover, shrinking, and deletion.
- Implementing hot-warm-cold architecture.
- Mapping optimization and text analysis techniques.
Security and Access Control
- RBAC implementation using users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Document-level security and field masking.
Backup and Recovery
- Configuring snapshot repositories to MinIO, S3, or NFS.
- Automating snapshots with Curator or ISM.
- Restoring specific indices and executing cluster-wide disaster recovery.
Requirements
- Familiarity with search engines and inverted indexes.
- Practical experience with REST APIs and JSON.
- Foundational Linux administration skills, including systemd, logging, and package management.
Audience
- Engineers specializing in search and log analytics.
- Teams aiming to replace managed Elasticsearch or Splunk deployments.
- Security analysts constructing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs