Get in Touch

Course Outline

Open-Source Search and Analytics Sovereignty

  • Elastic's licensing changes and the resulting forks.
  • Feature parity between OpenSearch and Elasticsearch in 2025-2026.
  • Key use cases: enterprise search, log analytics, SIEM, and observability.

Cluster Architecture

  • Node roles: master, data, coordinating, and ingest nodes.
  • Security plugin configuration: TLS internode communication, certificates, and PKI.
  • Preventing split-brain scenarios: configuring discovery.seed_hosts and minimum_master_nodes.

Data Ingestion

  • REST API indexing, bulk loading operations, and mapping definitions.
  • Pipelines utilizing Beats, Fluent Bit, and Logstash.
  • Utilizing the OpenTelemetry Collector for traces and metrics collection.

Search and Dashboards

  • Query DSL features: match, term, range queries, aggregations, and nested fields.
  • OpenSearch Dashboards: creating visualizations and dashboard layouts.
  • SIEM applications: setting up alert rules and anomaly detection mechanisms.

Index Management

  • ILM (Index Lifecycle Management): rollover, shrinking, and deletion strategies.
  • Implementing hot-warm-cold architecture.
  • Optimizing mappings and text analysis processes.

Security and Access Control

  • RBAC implementation involving users, roles, and tenants.
  • Authentication via SAML and OpenID Connect.
  • Document-level security and field masking techniques.

Backup and Recovery

  • Setting up snapshot repositories with MinIO, S3, or NFS.
  • Automating snapshots using Curator or ISM (Index State Management).
  • Restoring specific indices and ensuring cluster-wide disaster recovery capabilities.

Requirements

  • Foundational understanding of search engines and inverted indexes.
  • Practical experience working with REST APIs and JSON.
  • Basic Linux administration skills: proficiency with systemd, log management, and package handling.

Audience

  • Engineers specializing in search and log analytics.
  • Teams looking to replace managed Elasticsearch or Splunk solutions.
  • Security analysts developing sovereign SIEM backends.
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories