Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Open-Source Search and Analytics Sovereignty
- Elastic's licensing changes and the resulting forks.
- Feature parity between OpenSearch and Elasticsearch in 2025-2026.
- Key use cases: enterprise search, log analytics, SIEM, and observability.
Cluster Architecture
- Node roles: master, data, coordinating, and ingest nodes.
- Security plugin configuration: TLS internode communication, certificates, and PKI.
- Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum_master_nodes.
Data Ingestion
- REST API indexing, bulk loading operations, and mapping definitions.
- Pipelines utilizing Beats, Fluent Bit, and Logstash.
- Utilizing the OpenTelemetry Collector for traces and metrics collection.
Search and Dashboards
- Query DSL features: match, term, range queries, aggregations, and nested fields.
- OpenSearch Dashboards: creating visualizations and dashboard layouts.
- SIEM applications: setting up alert rules and anomaly detection mechanisms.
Index Management
- ILM (Index Lifecycle Management): rollover, shrinking, and deletion strategies.
- Implementing hot-warm-cold architecture.
- Optimizing mappings and text analysis processes.
Security and Access Control
- RBAC implementation involving users, roles, and tenants.
- Authentication via SAML and OpenID Connect.
- Document-level security and field masking techniques.
Backup and Recovery
- Setting up snapshot repositories with MinIO, S3, or NFS.
- Automating snapshots using Curator or ISM (Index State Management).
- Restoring specific indices and ensuring cluster-wide disaster recovery capabilities.
Requirements
- Foundational understanding of search engines and inverted indexes.
- Practical experience working with REST APIs and JSON.
- Basic Linux administration skills: proficiency with systemd, log management, and package handling.
Audience
- Engineers specializing in search and log analytics.
- Teams looking to replace managed Elasticsearch or Splunk solutions.
- Security analysts developing sovereign SIEM backends.
14 Hours
Testimonials (1)
the trainer was very good and made the training perfect for my needs